Job Description :
We are looking for a senior architect to own the end-to-end technical architecture of a production-grade, multi-agent AI platform deployed in US regulated financial institutions. This is not an advisory or strategy role; it is a hands-on architecture role with accountability for system design decisions that affect security, regulatory compliance, scalability, and operational reliability.
The platform operates in some of the most demanding technical environments in enterprise software: BYOC deployments inside bank Azure and GCP tenants, confidential computing enclaves, offline cryptographic licensing, and HITL-governed agentic pipelines that must produce immutable audit trails defensible to federal regulators. Every architectural decision has regulatory implications.
Scope of Responsibility :
Platform Architecture :
- Own the overall technical architecture of a multi-agent AI platform defining component boundaries, data flows, integration patterns, and deployment topologies across cloud environments (Azure and GCP).
- Architect the Model Abstraction Layer decoupling agent orchestration logic from specific model providers and versions, enabling zero-downtime model upgrades and multi-cloud model serving flexibility.
- Define and maintain the Blue-Green deployment architecture parallel environment management, traffic shifting strategy, rollback procedures, and regression testing gates for model version changes.
- Design scalable Kubernetes-based deployment topology (AKS / GKE) node pool architecture, namespace isolation, pod security policies, Workload Identity Federation, resource quota management.
Security Architecture :
- Architect the BYOC (Bring Your Own Cloud) deployment model ensuring all platform components operate within the client institution's cloud tenant with zero data egress to Anaptyss infrastructure.
- Design the offline cryptographic licensing system RSA-4096 JWT-based license enforcement that operates without network dependency, supporting both air-gapped and hybrid deployment modes.
- Define encryption architecture : CMEK via Azure Key Vault / GCP Cloud KMS for at-rest encryption; TLS 1.3 for in-transit; confidential computing enclaves for in-processing.
- Architect network security posture : VPC Service Controls (GCP) / Azure Private Endpoints, Private Service Connect / Private Link for model serving, no public IP surfaces on core components.
- Define identity and access architecture : AAD/Entra ID or Google Cloud Identity SSO integration, Workload Identity Federation for service-to-service authentication, RBAC with principle of least privilege.
- Design audit logging architecture immutable audit trail system capturing every agent action, HITL decision, evidence retrieval, and output version in structured, tamper-evident form.
AI System Architecture :
- Architect the agentic pipeline framework multi-stage workflow orchestration, inter-agent communication protocols, state persistence across HITL gates, and graceful degradation on component failure.
- Define the RAG (Retrieval Augmented Generation) architecture embedding model selection, vector store integration, chunking and indexing strategy, retrieval precision and recall optimisation, context window management for large document corpora.
- Design deterministic tool architecture separation of AI reasoning layer from data retrieval layer, tool interface contracts, error handling, evidence validation logic, and auditability of every data access operation.
- Architect stateless agent execution ensuring no cross-session memory accumulation, no passive learning from runtime data, and full reproducibility of pipeline outputs given equivalent inputs.
Cloud & Infrastructure Architecture :
- Design multi-cloud deployment architecture supporting both Azure and GCP abstracting cloud-specific components behind common interfaces while leveraging cloud-native managed services appropriately on each platform.
- Architect data persistence layer: relational database (Azure SQL / Cloud SQL PostgreSQL) for structured outputs and audit trail; object storage (Azure Blob / GCS) for document and artefact storage with appropriate partitioning, indexing, retention, and CMEK encryption.
- Design observability architecture: telemetry strategy (Azure Monitor + App Insights / GCP Cloud Monitoring + Cloud Logging) that provides operational visibility while keeping all telemetry within the client's cloud tenant.
- Define container image supply chain security: image signing (Sigstore/Binary Authorization), registry architecture (Azure Container Registry / Google Artifact Registry), Kubernetes admission control for signature verification.
Integration Architecture :
- Design the enterprise system integration layer defining connectivity patterns for read-only evidence retrieval from ERP, identity/access management, GRC, and workflow systems across on-premises and cloud-hosted environments.
- Architect GRC platform integration defining output delivery formats (JSON, PDF, CSV), API-based and file-based delivery patterns, and data mapping between ANA's output schema and client GRC platform import specifications.
- Define the client deployment package architecture Helm charts, Terraform modules, container image delivery via shared registry, cryptographic signature verification, and zero-Anaptyss-access deployment process.
Required Experience & Skills :
Architecture & Systems Design - Essential :
- 8+ years in enterprise software architecture, with at least 3 years in AI/ML platform architecture.
- Demonstrable experience designing production systems that were deployed in regulated environments financial services, healthcare, government, or equivalent where architectural decisions had compliance and regulatory implications.
- Deep expertise in cloud-native architecture on Azure and/or GCP proven ability to design production systems using managed services, Kubernetes, IAM, encryption, and networking on at least one platform; working familiarity with the other.
- Experience designing BYOC (Bring Your Own Cloud) or tenant-isolated deployment models where customer data must remain within the customer's cloud environment.
- Hands-on experience with confidential computing Azure Confidential Computing (DCv3/Intel SGX), GCP Confidential VMs (AMD SEV/Intel TDX), or equivalent at the architecture level.
AI Platform Architecture - Essential :
- Deep understanding of LLM inference architecture model serving patterns, API integration, token economics, latency optimisation, and failure mode handling at production scale.
- Hands-on experience architecting agentic AI systems multi-agent orchestration, tool use frameworks, ReAct patterns, state management across agent handoffs.
- RAG system architecture experience embedding model selection and deployment, vector database design (pgvector, Pinecone, Weaviate, Vertex AI Vector Search, or equivalent), retrieval pipeline optimisation.
- LLMOps / MLOps architecture model versioning strategy, Blue-Green model deployment, regression testing gates, monitoring for model drift and output quality degradation.
- Understanding of LLM security attack surfaces prompt injection, data exfiltration via model outputs, context window manipulation and architectural mitigations.
Security Architecture - Essential :
- Cryptographic systems design asymmetric key cryptography (RSA), JWT architecture, offline license enforcement, key management lifecycle.
- Cloud security architecture encryption at rest (CMEK), encryption in transit (TLS), encryption in processing (confidential computing), secrets management, network perimeter design.
- Identity and access architecture SSO integration (SAML/OIDC), Workload Identity Federation, RBAC design, principle of least privilege applied at cloud IAM level.
- Audit logging and compliance architecture immutable log design, audit trail completeness, log retention and tamper-evidence for regulated environments.
- Familiarity with bank technology risk frameworks OCC guidelines, Federal Reserve SR Letters, FFIEC guidance sufficient to understand what an examiner will look for in a system architecture review.
Engineering Credibility - Essential :
- Ability to produce architecture artefacts that engineering teams can build from not high-level slides but component diagrams, data flow specifications, interface contracts, security boundary definitions, and deployment topology documentation.
- Experience producing technical documentation for external review by enterprise architecture teams, information security teams, model risk management functions, and regulatory examiners.
- Proficiency in Python and/or TypeScript sufficient to review code, prototype architectural concepts, and engage credibly with engineering teams on implementation decisions.
Strong Advantages :
- Experience engaging directly with bank technology risk, information security, or enterprise architecture teams as a vendor having your architecture reviewed, questioned, and approved through institutional governance processes.
- Multi-cloud architecture experience having designed and deployed the same logical system on both Azure and GCP with appropriate cloud-native service mapping.
- Experience with confidential computing at implementation depth enclave programming, attestation, sealed storage.
- Background in designing licensing and IP protection systems for software deployed in customer environments.
- SOC 2 Type II audit preparation having worked with auditors to document and evidence security controls.
What We Offer :
- A technically demanding problem space that very few architect roles offer governed agentic AI in federally regulated environments, combining confidential computing, multi-cloud security, and LLM architecture.
- Exposure to the most technically sophisticated buyers in enterprise software bank CDOs, Chief AI Officers, and Enterprise Architects who will probe every architectural decision.
AI Architect • Gurgaon