Overview
True Zero Technologies, a veteran-owned small business, was founded on the principle that the purposeful enablement of people and technology in an organization directly ties to the
Full job description
True Zero Technologies, a veteran-owned small business, was founded on the principle that the purposeful enablement of people and technology in an organization directly ties to the quality of its outcomes. True Zero recognizes that those outcomes begin and end with our people, and that is what we have built a community of like-minded, driven, and passionate individuals and innovators who are aligned in a common goal of delivering top-tier services to our customers. Our culture and commitment have been recognized through numerous accolades, including being named one of the Best Places to Work in 2023 in two categories (“Prosperous and Thriving” ($5MM–$50MM in gross revenue) and “Mid-Atlantic Region” (DC, DE, MD, NC, VA, WV)), and again in 2025 as a Best Places to Work honoree. In addition, True Zero earned coveted spots on the Inc. 5000 list of fastest-growing companies in America in 2022, 2023, and 2025, a testament to our sustained growth driven by our people-first approach and unwavering dedication to excellence.
True Zero Technologies is seeking an experienced AWS WorkSpaces Architect to design, implement, secure, automate, and manage a large-scale Amazon WorkSpaces environment supporting approximately 5,000 users. The architect will be responsible for the overall technical architecture and operational strategy for the virtual desktop environment, ensuring that it is secure, highly available, scalable, cost-effective, and capable of meeting enterprise performance and user-experience requirements. The ideal candidate will have extensive experience with Amazon WorkSpaces, AWS infrastructure, Active Directory, enterprise networking, endpoint management, automation, security, and large-scale virtual desktop environments. This individual will serve as the technical lead for the platform from initial architecture and deployment through Day 2 operations, optimization, troubleshooting, and continuous improvement.
Architecture and Design
Design and maintain the architecture for an Amazon WorkSpaces environment supporting approximately 5,000 concurrent and assigned users.
Develop highly available and scalable WorkSpaces architectures across multiple Availability Zones.
Design appropriate VPCs, subnets, routing, security groups, DNS, DHCP, NAT, internet access, and connectivity to enterprise networks.
Develop WorkSpaces deployment patterns based on user personas, workloads, performance requirements, security requirements, and application needs.
Determine appropriate WorkSpaces bundles, compute configurations, storage allocations, protocols, and operating system configurations.
Design the environment to support business continuity, disaster recovery, and service resiliency requirements.
Produce architecture diagrams, design documentation, configuration standards, runbooks, and operational procedures.
Amazon WorkSpaces Implementation
Lead the deployment and configuration of Amazon WorkSpaces at enterprise scale.
Configure WorkSpaces directories, bundles, images, user volumes, compute types, access policies, and network connectivity.
Develop standardized desktop images and application configurations for different user personas.
Establish image lifecycle, patching, testing, release, rollback, and version-control processes.
Implement automated WorkSpaces provisioning and deprovisioning processes.
Develop repeatable deployment processes using Infrastructure as Code and automation.
Support pilot deployments, user acceptance testing, production rollout, and migration of users to Amazon WorkSpaces.
Identity and Access Management
Design and manage integration between Amazon WorkSpaces and Microsoft Active Directory/AWS Directory Service.
Implement authentication and authorization architectures using AWS IAM and enterprise identity providers.
Support SAML-based federation, MFA, conditional access, and other enterprise authentication requirements where applicable.
Implement role-based access controls and least-privilege administrative models.
Design user onboarding, role changes, offboarding, and automated WorkSpaces lifecycle processes.
Networking
Design network connectivity between Amazon WorkSpaces and enterprise/on-premises environments using technologies such as AWS Direct Connect, Site-to-Site VPN, Transit Gateway, and VPC networking.
Design DNS, routing, proxy, firewall, NAT, and internet-access architectures supporting WorkSpaces users.
Troubleshoot latency, packet loss, bandwidth constraints, DNS issues, authentication issues, and other network-related performance problems.
Monitor network capacity and ensure sufficient bandwidth and connectivity for a 5,000-user environment.
Security and Compliance
Develop and enforce security standards for the WorkSpaces environment.
Implement network segmentation, encryption, endpoint restrictions, logging, monitoring, and least-privilege access.
Ensure WorkSpaces data is appropriately protected both at rest and in transit.
Integrate the platform with enterprise SIEM, vulnerability management, endpoint security, and security monitoring solutions.
Support implementation of applicable security frameworks such as NIST 800-53, CIS Benchmarks, FedRAMP, and organizational security policies.
Work with cybersecurity teams to identify vulnerabilities, remediate findings, and maintain the security posture of desktop images and supporting AWS infrastructure.
Automation and Infrastructure as Code
Automate provisioning, configuration, patching, image management, user onboarding, monitoring, and administrative tasks.
Develop Infrastructure as Code using technologies such as Terraform, AWS CloudFormation, and AWS CDK.
Develop automation using Python, PowerShell, AWS CLI, AWS Systems Manager, Lambda, and AWS APIs/SDKs.
Integrate WorkSpaces deployment and configuration processes with CI/CD pipelines.
Reduce manual administration through policy-driven and event-driven automation.
Operations and Platform Management
Provide technical leadership for Day 2 operation of the WorkSpaces environment.
Establish operational procedures for provisioning, deprovisioning, patching, image management, application deployment, monitoring, incident response, and problem management.
Develop platform health dashboards and operational KPIs.
Monitor WorkSpaces availability, connection success rates, authentication failures, resource utilization, latency, and user-experience metrics.
Establish capacity-management processes for approximately 5,000 users.
Lead troubleshooting of complex WorkSpaces, Active Directory, networking, application, performance, and authentication issues.
Conduct root-cause analysis and implement permanent corrective actions.
Performance and Cost Optimization
Continuously evaluate WorkSpaces utilization and performance.
Right-size WorkSpaces based on CPU, memory, storage, and user workload requirements.
Evaluate appropriate WorkSpaces running modes and configurations based on user usage patterns.
Identify unused, underutilized, and oversized WorkSpaces.
Develop cost-management and FinOps processes for the WorkSpaces platform.
Establish chargeback/showback and reporting capabilities where required.
Balance user experience, availability, security, and cost when making architecture decisions.
Required Technical Skills
The successful candidate should have strong hands-on experience with:
Amazon WorkSpaces
AWS Directory Service
Microsoft Active Directory and Group Policy
AWS IAM
Amazon VPC
AWS Transit Gateway
AWS Direct Connect and Site-to-Site VPN
Route 53 and enterprise DNS
AWS Systems Manager
Amazon CloudWatch and CloudTrail
AWS KMS
Amazon S3
AWS Lambda
AWS Security Hub and GuardDuty
Terraform and/or AWS CloudFormation
PowerShell and Python
Windows desktop and Windows Server administration
Desktop image creation and lifecycle management
Application packaging and deployment
Enterprise patch and vulnerability management
Endpoint security technologies
SIEM and centralized logging
Infrastructure as Code and CI/CD practices
Required Experience
8+ years of experience designing, implementing, or managing enterprise infrastructure and cloud environments.
5+ years of hands-on AWS architecture and engineering experience.
Significant hands-on experience designing and operating Amazon WorkSpaces or comparable enterprise VDI/DaaS platforms.
Experience designing virtual desktop environments supporting thousands of users.
Strong experience with Microsoft Active Directory, Group Policy, DNS, authentication, and enterprise identity management.
Demonstrated experience designing AWS networking for large enterprise environments.
Experience implementing highly available and resilient AWS architectures.
Experience automating AWS infrastructure and operational processes.
Experience troubleshooting complex desktop, network, authentication, application, and performance issues.
Preferred Experience
Experience supporting Amazon WorkSpaces environments of 2,500–5,000+ users.
Experience migrating users from traditional physical desktops or legacy VDI platforms to Amazon WorkSpaces.
Experience with VMware Horizon, Citrix Virtual Apps and Desktops, Azure Virtual Desktop, or similar technologies.
Experience integrating WorkSpaces with enterprise endpoint management, application delivery, SIEM, ITSM, and security platforms.
Experience working in Federal Government or other highly regulated environments.
Familiarity with NIST 800-53, FedRAMP, CIS Benchmarks, and Zero Trust architectures.
Experience implementing automated desktop provisioning and application-delivery pipelines.
Preferred Certifications
AWS Certified Solutions Architect – Professional
AWS Certified Advanced Networking – Specialty
AWS Certified Security – Specialty
Security Clearance.
This position requires a Top Secret Clearance.
Tips for this job
Practical Job and Scholarship guidance. These tips do not replace official rules or create new eligibility requirements.
- Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
- Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
- Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
- Apply through the original employer or official recruitment destination shown on this page.
Verification notes
laptop-ats-crawler v2
Job and Scholarship is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.
Truezerotech (lever) ↗Browse current Job and Scholarship listings from Truezerotech (lever) →