Sr. Cloud Platform Architect
KLA is a global leader in diversified electronics for the semiconductor manufacturing ecosystem. Virtually every electronic device in the world is produced using our technologies. We invent systems and solutions for the manufacturing of wafers and reticles, integrated circuits, packaging, printed circuit boards, and flat panel displays. Our focus on innovation drives us to invest 15% of sales back into R&D. Our expert teams of physicists, engineers, data scientists, and problem-solvers collaborate with leading technology providers to accelerate the delivery of tomorrow’s electronic devices.
About the Group/Division
The Information Technology (IT) group at KLA is involved in every aspect of the global business. IT’s mission is to enable business growth and productivity by connecting people, process, and technology. It focuses on enhancing the technology that enables our business to thrive and on empowering employees through technology. This integrated approach drives employee productivity, business analytics, and process excellence.
Responsibilities
- Design and architect scalable, highly available, resilient, and secure cloud solutions leveraging IaaS and PaaS services across AWS, Azure, and Google Cloud Platform (GCP).
- Lead cloud migration initiatives, including re-hosting, re-platforming, refactoring, and re-architecting legacy and on-premises workloads with a strong emphasis on security posture improvement and risk reduction.
- Drive application and infrastructure modernization programs to improve scalability, performance, security, and operational efficiency.
- Partner with engineering, platform, and security teams to define cloud-native reference architectures, security guardrails, and modernization roadmaps.
- Optimize cloud infrastructure for performance, availability, reliability, security hardening, and cost efficiency.
- Establish and manage cloud security architectures and governance frameworks, aligned with industry standards and internal security policies.
- Design and enforce identity-first security, including IAM strategies, least-privilege access controls, role-based access, identity federation, and secrets management.
- Design and implement secure cloud networking architectures, including VPN, Direct Connect, ExpressRoute, and Cloud Interconnect.
- Configure and enforce network segmentation, micro-segmentation, zero-trust architectures, and advanced network security controls.
- Secure containers, Kubernetes, serverless, and microservices environments, including image scanning, runtime protection, and policy enforcement.
- Implement Infrastructure as Code (IaC) using Terraform, AWS CloudFormation, and Azure ARM/Bicep templates with built-in security, policy, and compliance controls.
- Design and evolve DevSecOps CI/CD pipelines, integrating security scanning, policy enforcement, and automated compliance validation.
- Define and implement cloud security observability, including logging, monitoring, alerting, and incident response integration.
- Evaluate emerging cloud and security technologies, driving continuous improvement of platform security and resilience.
- Develop, document, and present architecture diagrams, security models, threat assessments, technical documentation, roadmaps, and executive-level presentations.
- Define and operate cloud operating models, including security governance, FinOps, tagging standards, resource governance, and operational excellence frameworks.
Requirements
- Bachelor’s level degree in Computer Science, Computer Engineering, or related field with eight (8) years of related experience.
- Seven (7) years of hands-on cloud architecture or engineering experience, including ownership of secure production environments.
- Proficient in at least one major cloud platform such as Microsoft Azure, AWS, or GCP, with strong cross-cloud security fundamentals.
- In-depth understanding of cloud networking, cloud security, containers, Kubernetes, serverless technologies, and microservices.
- Confirmed experience with cloud security controls, including IAM, encryption, key management, network security, and zero-trust principles.
- Extensive knowledge of cloud governance, monitoring, observability, FinOps, and cost management.
- Strong understanding of compliance and regulatory frameworks (e.g., NIST, ISO, SOC, CIS, PCI, or similar).
- Experience embedding security into architecture design, IaC, and CI/CD pipelines (DevSecOps).
- Exceptional communication, leadership, and customer-management skills, with the ability to influence engineering, security, and executive stakeholders.
Pay
Base pay range: $137,800.00 - $234,300.00 annually.
Benefits
- Medical, dental, vision, life, and other voluntary benefits.
- 401(K) with company matching.
- Employee stock purchase program (ESPP).
- Student debt assistance and tuition reimbursement program.
- Development and career growth opportunities and programs.
- Financial planning benefits.
- Wellness benefits including an employee assistance program (EAP).
- Paid time off and paid company holidays.
- Family care and bonding leave.
Interns are eligible for some of the benefits listed.