VMware VDI to AWS Workspaces Core Migration Architect
Location : Remote
Please note, this role is not able to offer visa transfer or sponsorship now or in the future.
Engagement Overview
This document defines the roles and responsibilities for personnel required to execute a migration from VMware Horizon (Omnissa) to Amazon WorkSpaces Core.
Team Structure: One (1) Senior VDI Migration Architect serving as technical lead, supported by two (2) VDI Migration Engineers responsible for hands-on execution.
Scope: End-to-end migration delivery including infrastructure design, identity integration, application packaging, image lifecycle automation, data migration, patching workflows, and operational handover.
Senior VDI Migration Architect (Lead)
Purpose and Scope
Serves as the technical lead and primary point of accountability for the migration engagement. Owns architecture decisions, customer-facing communication, delivery oversight, and quality of all technical outputs.
Key Responsibilities
Design the target-state AWS WorkSpaces Core architecture including directory integration, networking, bundle strategy, and running-mode selection
Define the Terraform module structure for WorkSpaces provisioning, FSx configuration, VPC/subnet layout, and IAM policies
Architect CI/CD pipelines for golden image build, test, and deployment lifecycle
Lead customer discovery sessions and translate business requirements into technical scope
Establish the migration wave plan, cutover sequencing, and rollback procedures
Review all automation code (Python, PowerShell) produced by the engineering team
Own the patching strategy decision (image-rebuild vs. live-patch) and associated automation design
Define monitoring, alerting, and observability standards (CloudWatch, Splunk, Datadog as applicable)
Produce architecture documentation, runbooks, and knowledge-transfer materials
Serve as escalation point for technical blockers and cross-team dependencies
Required Technical Skills
AWS WorkSpaces Core: provisioning, bundle management, directory integration (AWS Managed AD, AD Connector), WorkSpaces APIs
Terraform: module development, state management, workspace strategy, CI/CD integration
CI/CD: GitHub Actions, GitLab CI, or AWS CodePipeline for infrastructure and image pipelines
Python: automation scripting for provisioning, onboarding workflows, and validation
PowerShell: Windows image configuration, application silent-install scripting, Group Policy automation
AWS platform services: VPC, IAM, Directory Service, FSx for Windows File Server, S3, CloudWatch, KMS, AWS Backup, Systems Manager
Networking: Direct Connect, VPN, Transit Gateway, security groups, NACLs, hybrid DNS
Identity: Active Directory OU design, Group Policy, service account delegation
Required Soft Skills
Clear, factual communication with customer stakeholders at technical and executive levels
Ability to lead discovery workshops, whiteboard sessions, and architecture reviews
Structured documentation and runbook authoring
Mentorship of junior and mid-level engineers
Decision-making under ambiguity; ability to define path forward when requirements are incomplete
Preferred Qualifications and Certifications
8+ years infrastructure/cloud engineering experience
3+ years in VDI/EUC environments (VMware Horizon, Citrix, or AWS WorkSpaces)
AWS Certified Solutions Architect (Associate or Professional)
HashiCorp Certified: Terraform Associate
VMware Certified Professional (VCP-DCV) or equivalent demonstrable experience
Experience with compliance frameworks (HIPAA, PCI, SOX, FedRAMP, StateRAMP, CJIS)
VDI Migration Engineer
Purpose and Scope
Two engineers in this role support the Senior Architect with hands-on execution of migration tasks. They build and maintain automation, package applications, execute migration waves, and produce operational documentation under the direction of the lead.
Key Responsibilities
Develop and maintain Terraform configurations for WorkSpaces provisioning, networking, and supporting infrastructure
Build and operate CI/CD pipelines for golden image creation, patching, and deployment
Write Python and PowerShell scripts for user provisioning, application installation, validation testing, and operational automation
Package applications with silent-install commands (MSI, EXE switches, Chocolatey, PowerShell)
Research and resolve legacy/EOL application installation challenges
Execute migration waves: provision WorkSpaces, validate application stacks, confirm user access
Configure enterprise agents on images (EDR, proxy/zero-trust, endpoint management, log/telemetry)
Implement FSx for Windows File Server configuration, ACL preservation, and backup plans
Configure monitoring dashboards and alerting rules per the architecture defined by the lead
Produce operational runbooks, troubleshooting guides, and KT session content
Execute patching workflows (WSUS, SCCM, Ivanti, or image-rebuild model as directed)
Required Technical Skills
AWS WorkSpaces: provisioning, bundle configuration, directory integration basics
Terraform: ability to write and modify modules, execute plans, manage state under guidance
CI/CD: experience building or maintaining pipelines (GitHub Actions, GitLab CI, Jenkins, or AWS CodePipeline)
Python: scripting for automation tasks, API interactions, and data validation
PowerShell: Windows administration, application packaging, registry manipulation, scheduled tasks
AWS services: EC2, S3, IAM, CloudWatch, Systems Manager, FSx, AWS Backup
Windows Server: Active Directory, Group Policy, WSUS, SCCM fundamentals
Application packaging: silent-install creation, enterprise agent deployment, post-install configuration
Required Soft Skills
Clear written communication for runbooks, status updates, and issue documentation
Ability to work directly with customer IT staff during migration execution
Attention to detail in configuration and validation tasks
Willingness to troubleshoot unfamiliar application installation failures
Ability to follow established procedures and escalate when encountering blockers
Preferred Qualifications and Certifications
4+ years infrastructure or cloud engineering experience
1+ years working with VDI/EUC platforms
AWS Certified Solutions Architect - Associate or AWS Certified SysOps Administrator
HashiCorp Certified: Terraform Associate
Experience with configuration management tools (Ansible, SCCM, Intune)
Familiarity with compliance requirements in regulated environments
Technology Stack Summary
Technology
Senior Architect
Migration Engineer
VMware Horizon / Omnissa
Preferred
Preferred
AWS WorkSpaces Core
Required (deep)
Required (working)
Terraform
Required (design + review)
Required (develop + execute)
CI/CD (GitHub Actions, GitLab CI, CodePipeline)
Required (design)
Required (build + maintain)
Python
Required (review + author)
Required (primary author)
PowerShell
Required (review + author)
Required (primary author)
AWS (VPC, IAM, FSx, CloudWatch, KMS)
Required (architecture)
Required (implementation)
Active Directory / Group Policy
Required
Required
Networking (DX, VPN, TGW)
Required
Preferred
Application Packaging (MSI, Chocolatey)
Preferred
Required
Compliance (HIPAA, PCI, FedRAMP)
Required (awareness)
Preferred
Team Interaction Model
The following describes how the three roles collaborate during engagement delivery:
Activity
Senior Architect
Migration Engineer
Architecture Design
Owns; produces designs
Provides input; implements
Customer Communication
Primary point of contact
Supports during technical sessions
Terraform / IaC
Defines module structure; reviews PRs
Writes and tests modules
CI/CD Pipelines
Defines pipeline architect