What are the responsibilities and job description for the Cloud Architect position at PayCloud Innovations?
To apply for this role send CV to techhr@paycloudinnovations.com
Cloud Architect
Payment Platform — Multi-Tenant SaaS, Security & Compliance
Location: Austin, TX (hybrid) — remote considered for exceptional candidates
Department: Engineering
Reports to: Chief Technology Officer
Employment type: Full-time
Travel: Occasional (up to 10%)
About the role
PayCloud Innovations runs the platform behind mobile wallets, digital card issuance, tokenization, and Trusted Service Manager (TSM) services on COREdotME. Our customers are issuers, processors, wallet providers, and healthcare payment partners — organizations that expect scheme-grade availability, auditable security, and predictable performance from everything we operate.
We are hiring a Cloud Architect to own the target architecture of that platform in the cloud: multi-tenancy and isolation, cryptographic services and HSM integration, PCI DSS and PHI-aware segmentation, resilience and disaster recovery, deployment and release engineering, observability, and cost. This is an architecture role with hands-on depth — you will write reference implementations, not only diagrams.
You will work closely with the TSM and tokenization architects, security and compliance, and delivery teams in Austin, LATAM, and Europe.
What you will do
- Own the cloud reference architecture for the payment platform: environment topology, network segmentation, identity, service boundaries, and data residency across regions.
- Design the multi-tenancy model — isolation, tenant onboarding, noisy-neighbour controls, and per-tenant configuration — so new issuers and partners can be onboarded without bespoke infrastructure.
- Architect the security perimeter around sensitive data: cardholder data and token vault environments, cryptographic services and cloud or on-premise HSM integration, key and secrets management, and encryption in transit and at rest.
- Define the segmentation and control design that keeps PCI DSS scope contained, and extend the same discipline to PHI and PII where our healthcare payment partners are involved.
- Set the infrastructure-as-code, CI/CD, and release standards: module design, environment promotion, GitOps workflows, change control, and evidence generation for audit.
- Design for resilience: availability targets, multi-region and failover strategy, backup and restore, and regular disaster recovery exercises with measured RTO and RPO.
- Own observability and operational readiness — logging, metrics, tracing, alerting, and the runbooks that make on-call sustainable across three time zones.
- Own cloud cost as an architectural concern: unit economics per tenant and per transaction, capacity planning, and a FinOps practice with real authority over spend decisions.
- Support certification and customer due diligence — QSA assessments, security questionnaires, penetration test remediation, and partner architecture reviews.
- Provide technical leadership to engineering teams through design reviews, reference implementations, and written architecture decision records.
What you bring
Core cloud architecture
- 8 years building and operating production cloud infrastructure, with 3 years in an architect or principal-level role.
- Deep, production-proven expertise in at least one major cloud (AWS, Azure, or GCP), and the judgement to reason about hybrid and multi-cloud estates as they actually exist rather than as drawn.
- Expert-level infrastructure as code — Terraform module design, state strategy, and setting IaC standards across teams.
- Production experience operating Kubernetes at scale: cluster lifecycle, multi-tenancy patterns, Helm governance, and GitOps delivery.
- Strong grounding in cloud security: IAM and least-privilege design, secrets management, network controls, and policy as code.
- Demonstrated ownership of resilience and disaster recovery, including cross-region failover design and live DR exercises.
- Clear architecture documentation and the ability to defend a design to engineers, auditors, and customers alike.
Payments, security and compliance context
- Regulated workloads: hands-on design against PCI DSS (v4.x), and familiarity with SOC 2 and HIPAA or PHI handling requirements.
- Cryptographic infrastructure: HSM-backed key management in cloud or hybrid deployments, key hierarchies, and key ceremony operational design.
- Tokenization platforms: understanding of vaulted and vaultless token architectures, token vault scaling, and the PCI scope reduction each model delivers.
- Transaction workloads: low-latency, high-availability authorization and provisioning paths, with realistic throughput and tail-latency targets.
- Ecosystem integration: secure connectivity to card schemes, processors, issuer hosts, and acquiring-side partners such as P2PE and healthcare gateway providers.
Preferred
- Experience at a payments platform, issuer processor, tokenization or data security vendor, or another PCI-regulated SaaS business.
- Experience taking a platform through QSA assessment or a comparable certification under a shared-responsibility model with a certified facility or provider.
- Familiarity with .NET and PostgreSQL service estates, and with event-driven or message-based integration patterns.
- Experience building an internal platform or paved road that engineering teams actually adopt.
- Experience working with distributed engineering teams across time zones.
Technical environment
Cloud-deployed multi-tenant services, containers and Kubernetes, Terraform-managed infrastructure, CI/CD and GitOps delivery, HSM-backed key management, token vault and tokenization services, .NET and PostgreSQL services, and API-based integration with schemes, token service providers, issuer hosts, and partner platforms.
What success looks like
- First 90 days: a documented current-state view of the platform estate — segmentation, isolation, secrets, resilience gaps, and cost drivers — with prioritized risks.
- First 6 months: target cloud architecture agreed with the CTO; IaC, deployment, and environment standards in place and adopted by at least one delivery team.
- First 12 months: tenant onboarding is repeatable without bespoke infrastructure, DR is exercised rather than assumed, audit evidence is generated from the pipeline, and per-tenant unit cost is measured and trending down.
Why PayCloud
We work at the point where wallets, secure elements, and tokenization meet real issuer and merchant economics. The platform carries regulated, high-consequence workloads for sophisticated customers — the architecture decisions made here are visible in production, in audits, and in the market.
Equal Opportunity & Accessibility
PayCloud Innovations is an Equal Opportunity Employer. We do not discriminate based on race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other legally protected characteristic. All qualified applicants will receive consideration for employment without regard to these factors.
We are committed to providing reasonable accommodations to qualified individuals with disabilities in our application process. If you need assistance or accommodation due to a disability, please contact us.
Background checks may be conducted after conditional offer of employment.