True Zero Technologies is seeking an experienced AWS WorkSpaces Architect to design, implement, secure, automate, and manage a large-scale Amazon WorkSpaces environment supporting approximately 5,000 users. The architect will be responsible for the overall technical architecture and operational strategy for the virtual desktop environment, ensuring that it is secure, highly available, scalable, cost-effective, and capable of meeting enterprise performance and user-experience requirements.
The ideal candidate will have extensive experience with Amazon WorkSpaces, AWS infrastructure, Active Directory, enterprise networking, endpoint management, automation, security, and large-scale virtual desktop environments. This individual will serve as the technical lead for the platform from initial architecture and deployment through Day 2 operations, optimization, troubleshooting, and continuous improvement.
Job Responsibilities
Architecture and Design
- Design and maintain the architecture for an Amazon WorkSpaces environment supporting approximately 5,000 concurrent and assigned users.
- Develop highly available and scalable WorkSpaces architectures across multiple Availability Zones.
- Design appropriate VPCs, subnets, routing, security groups, DNS, DHCP, NAT, internet access, and connectivity to enterprise networks.
- Develop WorkSpaces deployment patterns based on user personas, workloads, performance requirements, security requirements, and application needs.
- Determine appropriate WorkSpaces bundles, compute configurations, storage allocations, protocols, and operating system configurations.
- Design the environment to support business continuity, disaster recovery, and service resiliency requirements.
- Produce architecture diagrams, design documentation, configuration standards, runbooks, and operational procedures.
- Lead the deployment and configuration of Amazon WorkSpaces at enterprise scale.
- Configure WorkSpaces directories, bundles, images, user volumes, compute types, access policies, and network connectivity.
- Develop standardized desktop images and application configurations for different user personas.
- Establish image lifecycle, patching, testing, release, rollback, and version-control processes.
- Implement automated WorkSpaces provisioning and deprovisioning processes.
- Develop repeatable deployment processes using Infrastructure as Code and automation.
- Support pilot deployments, user acceptance testing, production rollout, and migration of users to Amazon WorkSpaces.
- Design and manage integration between Amazon WorkSpaces and Microsoft Active Directory/AWS Directory Service.
- Implement authentication and authorization architectures using AWS IAM and enterprise identity providers.
- Support SAML-based federation, MFA, conditional access, and other enterprise authentication requirements where applicable.
- Implement role-based access controls and least-privilege administrative models.
- Design user onboarding, role changes, offboarding, and automated WorkSpaces lifecycle processes.
- Design network connectivity between Amazon WorkSpaces and enterprise/on-premises environments using technologies such as AWS Direct Connect, Site-to-Site VPN, Transit Gateway, and VPC networking.
- Design DNS, routing, proxy, firewall, NAT, and internet-access architectures supporting WorkSpaces users.
- Troubleshoot latency, packet loss, bandwidth constraints, DNS issues, authentication issues, and other network-related performance problems.
- Monitor network capacity and ensure sufficient bandwidth and connectivity for a 5,000-user environment.
- Develop and enforce security standards for the WorkSpaces environment.
- Implement network segmentation, encryption, endpoint restrictions, logging, monitoring, and least-privilege access.
- Ensure WorkSpaces data is appropriately protected both at rest and in transit.
- Integrate the platform with enterprise SIEM, vulnerability management, endpoint security, and security monitoring solutions.
- Support implementation of applicable security frameworks such as NIST 800-53, CIS Benchmarks, FedRAMP, and organizational security policies.
- Work with cybersecurity teams to identify vulnerabilities, remediate findings, and maintain the security posture of desktop images and supporting AWS infrastructure.
- Automate provisioning, configuration, patching, image management, user onboarding, monitoring, and administrative tasks.
- Develop Infrastructure as Code using technologies such as Terraform, AWS CloudFormation, and AWS CDK.
- Develop automation using Python, PowerShell, AWS CLI, AWS Systems Manager, Lambda, and AWS APIs/SDKs.
- Integrate WorkSpaces deployment and configuration processes with CI/CD pipelines.
- Reduce manual administration through policy-driven and event-driven automation.
- Provide technical leadership for Day 2 operation of the WorkSpaces environment.
- Establish operational procedures for provisioning, deprovisioning, patching, image management, application deployment, monitoring, incident response, and problem management.
- Develop platform health dashboards and operational KPIs.
- Monitor WorkSpaces availability, connection success rates, authentication failures, resource utilization, latency, and user-experience metrics.
- Establish capacity-management processes for approximately 5,000 users.
- Lead troubleshooting of complex WorkSpaces, Active Directory, networking, application, performance, and authentication issues.
- Conduct root-cause analysis and implement permanent corrective actions.
- Continuously evaluate WorkSpaces utilization and performance.
- Right-size WorkSpaces based on CPU, memory, storage, and user workload requirements.
- Evaluate appropriate WorkSpaces running modes and configurations based on user usage patterns.
- Identify unused, underutilized, and oversized WorkSpaces.
- Develop cost-management and FinOps processes for the WorkSpaces platform.
- Establish chargeback/showback and reporting capabilities where required.
- Balance user experience, availability, security, and cost when making architecture decisions.
Amazon WorkSpaces Implementation
Identity and Access Management
Networking
Security and Compliance
Automation and Infrastructure as Code
Operations and Platform Management
Performance and Cost Optimization
Job Qualifications
Required Technical Skills
The successful candidate should have strong hands-on experience with:
- Amazon WorkSpaces
- AWS Directory Service
- Microsoft Active Directory and Group Policy
- AWS IAM
- Amazon VPC
- AWS Transit Gateway
- AWS Direct Connect and Site-to-Site VPN
- Route 53 and enterprise DNS
- AWS Systems Manager
- Amazon CloudWatch and CloudTrail
- AWS KMS
- Amazon S3
- AWS Lambda
- AWS Security Hub and GuardDuty
- Terraform and/or AWS CloudFormation
- PowerShell and Python
- Windows desktop and Windows Server administration
- Desktop image creation and lifecycle management
- Application packaging and deployment
- Enterprise patch and vulnerability management
- Endpoint security technologies
- SIEM and centralized logging
- Infrastructure as Code and CI/CD practices
- 8+ years of experience designing, implementing, or managing enterprise infrastructure and cloud environments.
- 5+ years of hands-on AWS architecture and engineering experience.
- Significant hands-on experience designing and operating Amazon WorkSpaces or comparable enterprise VDI/DaaS platforms.
- Experience designing virtual desktop environments supporting thousands of users.
- Strong experience with Microsoft Active Directory, Group Policy, DNS, authentication, and enterprise identity management.
- Demonstrated experience designing AWS networking for large enterprise environments.
- Experience implementing highly available and resilient AWS architectures.
- Experience automating AWS infrastructure and operational processes.
- Experience troubleshooting complex desktop, network, authentication, application, and performance issues.
- Experience supporting Amazon WorkSpaces environments of 2,500–5,000+ users.
- Experience migrating users from traditional physical desktops or legacy VDI platforms to Amazon WorkSpaces.
- Experience with VMware Horizon, Citrix Virtual Apps and Desktops, Azure Virtual Desktop, or similar technologies.
- Experience integrating WorkSpaces with enterprise endpoint management, application delivery, SIEM, ITSM, and security platforms.
- Experience working in Federal Government or other highly regulated environments.
- Familiarity with NIST 800-53, FedRAMP, CIS Benchmarks, and Zero Trust architectures.
- Experience implementing automated desktop provisioning and application-delivery pipelines.
- AWS Certified Solutions Architect – Professional
- AWS Certified Advanced Networking – Specialty
- AWS Certified Security – Specialty
Required Experience
Preferred Experience
Preferred Certifications
Security Clearance.
This position requires a Top Secret Clearance.
Similar Jobs
What you need to know about the Chicago Tech Scene
Key Facts About Chicago Tech
- Number of Tech Workers: 245,800; 5.2% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: McDonald’s, John Deere, Boeing, Morningstar
- Key Industries: Artificial intelligence, biotechnology, fintech, software, logistics technology
- Funding Landscape: $2.5 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Pritzker Group Venture Capital, Arch Venture Partners, MATH Venture Partners, Jump Capital, Hyde Park Venture Partners
- Research Centers and Universities: Northwestern University, University of Chicago, University of Illinois Urbana-Champaign, Illinois Institute of Technology, Argonne National Laboratory, Fermi National Accelerator Laboratory


%20copy.jpg)
