JD 9 - Migrations | Senior Consultant

Sumeru Solutions
  • Dallas, TX
  • Quick Apply
1 day ago

Job Description

JD 9 - Migrations | Senior Consultant

The Depository Trust & Clearing Corporation | DTCC_ProServs_Portfolio Assessment_FICC-Project | Source Row 71 | RR(s): RR-0705072

Client Name (Column AD)

The Depository Trust & Clearing Corporation

Job Description (Column W)

Included below under Role Scope & Key Responsibilities

Role Specialization (Column G)

Migrations

Role Experience (Column F)

Senior Consultant - L6, 8+ years relevant experience

Role Summary

Lead cloud infrastructure architecture design for DTCC A3P landing zone migration supporting FICC (Fixed Income, Currency, and Commodities) workloads. Design multi-region AWS infrastructure including VPC architecture, self-managed OpenShift on EC2, Aurora Global Database, DynamoDB Global Tables, and IBM MQ RDQM clustering. Architect disaster recovery topology with F5 GTM integration, cross-region data replication, and hybrid connectivity (DirectConnect/VPN) for on-premises integration. Define Terraform IaC modules for enterprise-scale, multi-account deployments with cost governance and Tier 1 resiliency requirements.

Role Scope & Key Responsibilities (from Column W)

Primary Responsibilities:

  • Landing Zone Architecture: Design and validate DTCC A3P landing zone configuration for FICC workloads with AWS Organizations, SCPs, and multi-account governance
  • Network Design: Define VPC architecture with public/private subnets, VPC endpoints, security groups per SYS ID; configure multi-region topology (us-east-1 primary, us-east-2 standby)
  • Disaster Recovery: Design F5 GTM integration for DR failover and operational traffic rotation; architect cross-region data replication (SRDF-A equivalent, Aurora Global DB, DynamoDB Global Tables)
  • Infrastructure as Code: Define Terraform module structure for FICC infrastructure (OCP on EC2, Aurora, DynamoDB, IBM MQ, GlobalScape, Autosys)
  • Compute Architecture: Design EC2 instance sizing and placement for OCP worker nodes, Autosys server, GlobalScape SFTP, IBM MQ RDQM with HA configurations
  • Observability: Configure Dynatrace OneAgent deployment on OCP and Splunk log forwarding
  • Hybrid Connectivity: Define on-premises connectivity architecture (DirectConnect/VPN for Ping Federate, CRS, CDTS MQ, Venafi)
  • Cost Governance: Design tagging strategy (per SYS ID, per environment, per wave) and validate A3P platform service readiness

Key Deliverables:

  • A3P Landing Zone Design (FICC-specific)
  • VPC and Network Architecture (multi-region)
  • Terraform Module Catalog (OCP, Aurora, DynamoDB, MQ, GlobalScape, Autosys)
  • Multi-Region DR Infrastructure Design
  • On-Premises Connectivity Architecture

EC2 Sizing Recommendations

AWS Skills & Services (added)

Governance & Multi-Account:

  • AWS Organizations: OU structure, SCPs, consolidated billing, cross-account strategies
  • AWS Control Tower: Landing zone automation, guardrails, Account Factory
  • AWS Service Catalog: Standardized resource provisioning

Networking:

  • Amazon VPC: Advanced design (public/private subnets, VPC endpoints, security groups, NACLs, route tables)
  • AWS Transit Gateway: Hub-and-spoke architecture, multi-region peering
  • AWS Direct Connect: Hybrid connectivity, VIFs, LAG configurations
  • AWS VPN: Site-to-Site VPN for on-premises integration
  • Elastic Load Balancing: ALB/NLB for OCP ingress, F5 GTM integration patterns
  • Amazon Route 53: DNS management, health checks, failover routing

Compute & Containers:

  • Amazon EC2: Instance families (compute/memory/storage optimized), placement groups, Auto Scaling, self-managed infrastructure
  • OpenShift on EC2: Overlay networks, load balancers, ingress controllers, persistent storage (EBS/EFS)

Database & Storage:

  • Amazon Aurora: Global Database (cross-region replication), cluster endpoints, failover mechanisms
  • Amazon DynamoDB: Global Tables, on-demand/provisioned capacity, DAX caching
  • Amazon S3: Bucket policies, lifecycle policies, cross-region replication, versioning
  • Amazon EBS: Volume types, snapshots, encryption, cross-region copy
  • Amazon EFS: Shared file storage for OCP persistent volumes

Messaging & Integration:

  • IBM MQ RDQM on EC2: Clustering, HA configurations, mTLS, channel authentication
  • Amazon MQ: Managed message broker (if applicable for non-RDQM workloads)

Disaster Recovery:

  • AWS Backup: Centralized backup, cross-region/cross-account backup
  • AWS Elastic Disaster Recovery (DRS): Continuous replication, failover orchestration
  • F5 GTM Integration: DNS-based traffic management, health monitoring

Monitoring & Observability:

  • Amazon CloudWatch: Metrics, logs, alarms, dashboards
  • AWS X-Ray: Distributed tracing
  • Dynatrace OneAgent: APM integration with OCP
  • Splunk: Log forwarding and SIEM integration

Security & Compliance:

  • AWS IAM: Advanced policies, cross-account roles, service accounts
  • AWS KMS: Customer Managed Keys, key policies, cross-region replication
  • AWS Secrets Manager: Credential rotation, cross-account access
  • AWS Security Hub: Centralized security findings
  • AWS Config: Configuration compliance, resource inventory

Infrastructure as Code:

  • Terraform: Enterprise-scale IaC (multi-account, multi-region), module development, state management, workspaces
  • AWS CloudFormation: StackSets for multi-account deployments

Cost Management:

  • AWS Cost Explorer: Cost analysis, tagging strategies
  • AWS Budgets: Cost alerts, anomaly detection
  • Tagging Strategy: Per SYS ID, per environment, per wave

Hybrid Connectivity:

  • AWS Direct Connect: Dedicated network connections, VIFs, LAG

AWS VPN: Site-to-Site VPN for Ping Federate, CRS, CDTS MQ, Venafi integration

Financial Services & Industry Skills (added)

  • Large regulated financial-services delivery with formal change-control, audit and risk governance
  • Operational resilience expectations including RTO/RPO, multi-region DR and evidence for audit review
  • Awareness of applicable controls and regulations such as DORA, NIST CSF 2.0, PCI DSS, SEC cyber rules, RegSCI and SIFMU/FMI expectations where relevant
  • Ability to create Tech Risk-ready documentation including ADRs, runbooks, design docs, threat models and validation evidence
  • Clear communication with client engineering, security, SRE, data and platform stakeholders as an embedded SME

Certifications / Qualifications

  • AWS Certified Solutions Architect - Associate / Professional
  • AWS Certified SysOps Administrator - Associate
  • AWS Certified DevOps Engineer - Professional preferred

General Requirements

  • 8+ years of relevant hands-on delivery experience at L6 scope
  • Prior delivery in a large regulated enterprise environment, preferably financial services
  • Ability to write architecture decision records, design documents, runbooks and test evidence for client Tech Risk review
  • Strong stakeholder communication across engineering, security, operations, SRE and delivery teams
  • Compliance with AWS ProServe and client onboarding, security, vetting and time-zone overlap requirements

Numbers & Facts

LocationDallas, TX

Skills

  • Adverse Eventsunmatched
  • Amazon Elastic Compute Cloud (EC2)unmatched
  • Amazon Simple Storage Service (S3)unmatched
  • Amazon Web Services (AWS)unmatched
  • Architectural Designunmatched
  • Authenticationunmatched
  • Automationunmatched
  • Autoscalingunmatched
  • Billingunmatched
  • Budgetingunmatched
  • CA Workload Automation AE (AutoSys Edition)unmatched
  • Cachingunmatched
  • Cloud Architectureunmatched
  • Communication Skillsunmatched
  • Computer Architectureunmatched
  • Consultingunmatched
  • Cost Analysisunmatched
  • Cost Controlunmatched
  • Cryptographyunmatched
  • DNS (Domain Name System)unmatched
  • Database Replicationunmatched
  • Design Documentunmatched
  • DevOpsunmatched
  • Disaster Recoveryunmatched
  • Documentationunmatched
  • Elastic Load Balancingunmatched
  • Embedded Systemsunmatched
  • Endpoint Securityunmatched
  • F5 Network Softwareunmatched
  • Failoverunmatched
  • Financial Servicesunmatched
  • Fixed Income Investmentsunmatched
  • IBM WebSphere MQ (Message Queue)unmatched
  • Load Balancingunmatched
  • Memory Hardwareunmatched
  • Message Brokerunmatched
  • Messaging Middlewareunmatched
  • Metricsunmatched
  • Model Validationunmatched
  • Network Architecture/Engineeringunmatched
  • Network Connectivityunmatched
  • Network Designunmatched
  • Network Routingunmatched
  • Onboardingunmatched
  • Portfolio Analysisunmatched
  • Radiographyunmatched
  • Ray Tracingunmatched
  • Registered Training Organisation (RTO)unmatched
  • Replication and Remote Mirroringunmatched
  • Reporting Dashboardsunmatched
  • Riskunmatched
  • Sales Strategyunmatched
  • Secure/SSH File Transfer Protocol (SFTP)unmatched
  • Security Information and Event Management (SIEM)unmatched
  • Service Deliveryunmatched
  • Splunkunmatched
  • Subnetunmatched
  • System Operationsunmatched
  • Testingunmatched
  • Threat Modelingunmatched
  • Topologyunmatched
  • VPN (Virtual Private Network)unmatched
  • Writing Skillsunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder