Lead Architect
Job Description
Own the target architecture for the enterprise Policy‑as‑Code platform, including:
OPA Control Plane (OCP) / Enterprise OPA (EOPA)
Policy lifecycle management, versioning, distribution, and auditability
CI/CD and Terraform Cloud Run Task integrations
Define and govern architecture standards, patterns, and principles for PaC on Google Cloud Platform.
Lead architectural decision‑making and maintain Architecture Decision Records (ADRs) with full traceability.
Ensure designs are scalable, modular, cloud‑agnostic , and aligned with enterprise governance constraints.
Governance & Compliance Enablement
Design and implement the PaC governance model , including:
Policy ownership and domain boundaries (Security, IAM, Network, Organizational)
Contribution, review, approval, and escalation workflows
Enforcement modes (advisory vs hard) and promotion lifecycle
Ensure alignment with financial services regulatory requirements and internal controls (e.g., auditability, traceability, segregation of duties).
Support architecture and security governance forums (eARB, Security Advisory, TRA), including preparation of required artefacts.
Platform & Framework Design
Architect a modular PaC framework , including:
Reusable Rego libraries and shared data contracts
Cloud abstraction layers (provider‑agnostic vs provider‑specific policies)
Standardized repository and bundle structures
Define policy authoring, testing, enforcement, and release pipelines , including:
Rego unit and regression testing (opa test)
CI/CD‑integrated validation and enforcement
Terraform Cloud Run Task governance
Impact analysis and decision‑log‑based backtesting
Ensure policy enforcement is deterministic, auditable, and production‑faithful .
Integration & Automation
Architect CI/CD and automation patterns using GitHub Actions, including reusable workflows and onboarding automation.
Define integration approaches for:
Terraform Cloud
Kubernetes admission control (OPA Gatekeeper)
Centralized decision logging and observability (e.g., Cloud Logging, BigQuery)
External enterprise systems via secure data‑bridge patterns
Ensure strong separation between policy logic and enterprise system integrations .
Migration & Enablement
Define migration strategies to transition legacy Terraform Cloud / OPA policies into the new PaC framework with functional equivalence.
Oversee controlled rollouts and enforcement promotion strategies to minimize operational risk.
Lead knowledge transfer, documentation strategy, and operational readiness to enable client teams to independently operate the platform.
Leadership & Collaboration
Provide technical leadership to platform engineers, policy engineers, and DevSecOps specialists.
Act as the primary technical escalation point for complex design or enforcement issues.
Translate business and compliance requirements into clear, actionable technical designs .
Foster strong collaboration between architecture, security, platform, and delivery teams.
Your Future at Kyndryl
As an IT/Cloud Consultant at Kyndryl you will join the Kyndryl Consultant Profession, working with other Kyndryl Consultants, Architects, Project Managers, and cross-functional Technical Subject Matter Experts – presenting unlimited opportunities with unmatched support through our investment in your learning, training, and career growth.
Who You Are
Who you are
You’re good at what you do and possess the required experience to prove it. However, equally
as important – you have a growth mindset; keen to drive your own personal and professional
development. You are customer-focused – someone who prioritizes customer success in their
work. And finally, you’re open and borderless – naturally inclusive in how you work with others.
Core Technical Expertise
Policy‑as‑Code & OPA
5+ years of experience with Open Policy Agent (OPA) and Rego
Hands‑on knowledge of Enterprise OPA (EOPA) capabilities (impact analysis, decision logging, bundle lifecycle)
Infrastructure as Code
5+ years of experience with Terraform and Terraform Cloud
Terraform Cloud Run Tasks (design, enforcement, governance)
CI/CD & Automation
5+ years of experience with GitHub Actions (advanced workflows, reusable workflows, automation patterns)
Pipeline‑integrated validation and policy enforcement
Cloud Platforms
5+ years of experience with GCP in regulated environments
Kubernetes policy enforcement (OPA Gatekeeper)
Observability & Auditability
5+ years of experience policy decision logging, ingestion, analytics, and reporting
5+ years of experience Designing immutable, auditor‑friendly evidence pipelines
Architecture & Governance
Proven experience leading enterprise architecture designs in regulated industries
Strong understanding of:
Governance models
Segregation of duties
Audit and compliance requirements
Experience producing architecture artefacts:
C4 diagrams, data flows, process flows
ADRs and architecture review submissions
Domain & Industry Experience
Experience delivering cloud platforms for financial services or regulated enterprises
Familiarity with:
Banking security posture expectations
Compliance‑driven SDLC controls
Risk and control validation processes
Leadership & Soft Skills
