The narrow corner that pays a Cloud Architect most
$224,930top of the range in California · middle $134,050 / yr
AI augments this role
Cloud Architects in the United States earn a median of $134,050 a year. Pay starts near $79,900. Pay reaches $224,930 at the top of the range in California, the best-paying state for this work among those with at least 500 people in the job.
Source: U.S. Bureau of Labor Statistics, Occupational Employment and Wage Statistics, May 2025 (Computer Network Architects, SOC 15-1241). Last checked 9 September 2026.
Entry level
$79,900
Top of the range · California
$224,930
Education
Bachelor's in CS/IT; master's valued
Wages — U.S. Bureau of Labor Statistics, Occupational Employment and Wage Statistics, May 2025 (Computer Network Architects). Top of the range is the highest state-level figure among states with at least 500 people in the job. AI-impact rating is PayCrunch's editorial assessment. Updated September 2026.
🆕 New & Trending AI Tools for Cloud ArchitectReviewed September 2026
We track new AI-tool launches every week and refresh this list — here’s what’s gaining traction for Cloud Architect work right now.
Claude CodeNEWFree / usage-based
Terminal coding agent that reads your repo, runs tests, and ships multi-file changes.
How a Cloud Architect uses it: describe a feature and let it implement and test it across the codebase
OpenAI CodexNEWIncl. w/ ChatGPT plans
Agent that runs longer, deterministic multi-step coding jobs on its own.
How a Cloud Architect uses it: delegate a well-defined build or migration and review the finished result
WindsurfNEWFree / $15 mo
Agentic IDE that keeps context across a whole project.
How a Cloud Architect uses it: make large, coordinated changes without losing track of the codebase
AWS KiroNEWPreview / see site
Spec-driven coding agent that turns written specs into working code.
How a Cloud Architect uses it: write the spec first and let it build to that spec
NotebookLMNEWFree / $7.99 mo
Google tool that answers questions grounded only in the documents you give it — with citations.
How a Cloud Architect uses it: load your own manuals, policies, or PDFs and ask questions that stay accurate to the source
CursorFree / $20 mo
AI-native code editor that edits across an entire project.
How a Cloud Architect uses it: describe a change in plain English and let it rewrite and refactor whole files
GitHub Copilot (Agent Mode)$10–19 mo
AI pair-programmer built into VS Code and GitHub that now completes multi-step tasks.
How a Cloud Architect uses it: hand off a task and have it plan, edit multiple files, and open a pull request
ChatGPTFree / $20 mo
The most-used AI assistant — writing, analysis, research, and images from a plain-language chat.
How a Cloud Architect uses it: draft emails and documents, summarize long files, and get instant answers to on-the-job questions
ClaudeFree / $20 mo
AI assistant known for careful writing, long-document analysis, and coding.
How a Cloud Architect uses it: analyze big reports or spreadsheets and turn messy notes into clean, finished writing
The design I am actually buying
I hire a cloud architect when the company has outgrown a pile of accounts and needs someone who can draw the next few years of the system before anyone clicks create. The person in that seat decides how the company's systems sit in a cloud: which accounts exist, how the networks between them are shaped, what still runs when a region fails, and what the design will cost once real traffic arrives. I am buying judgment about structure. A slide full of vendor logos is easy to produce. A design another team can build, secure, and pay for is the job.
Day to day, the architect sits with application leads, the security group, finance, and the engineers who will have to live in the result. A product team wants a new environment by the end of the month. Finance wants the bill to stop surprising them. Security wants a clear story about who can reach production data. The architect turns those pressures into a picture: a small set of account patterns, a network that keeps private systems private, a way to recover, and a rule for which services are allowed to run. Much of the week is review. Someone brings a diagram. The architect asks what happens when that region is unavailable, who administers the account, and which team pays.
The work is written as well as drawn. Design notes, decision records, and reference patterns are how the choice survives after the meeting ends. I look for someone who can say, in plain language, why one pattern was chosen and which alternative was set aside. The audience is mixed. A vice president needs the cost and the risk. An engineer needs enough detail to build the account without inventing a second design in the ticket. If the note only makes sense to the person who wrote it, the design will be rebuilt badly the first time that person is away.
I also watch how the architect behaves when the design meets a deadline. Real companies have legacy systems, a contract already signed, and a team that learned a different cloud last year. The useful architect narrows the choice, names the risk that remains, and leaves a path the operators can run. A design that assumes a blank company and a blank calendar is a classroom exercise. I am hiring for the company we already have.
Accounts, networks, resilience, and the bill
Account design is the first concrete decision. A company usually needs more than one cloud account, because mixing experiments with customer data is how accidents happen. The architect decides which accounts are for production, which are for testing, which hold shared services such as identity and logging, and how a new product team gets an account that already follows the pattern. Naming, ownership, and a break-glass path for emergencies belong in that picture. So does the question of which team is allowed to change the guardrails. I want that answer written down before the second team arrives and copies the first team's shortcuts.
The network in this job is a cloud network: how traffic moves among accounts, regions, and the company's own data centers, and what is reachable from the public internet. The architect chooses where private connections land, how name lookup works, and which paths are intentionally closed. This is design for systems the company runs in a cloud provider, tied to the account model above. A campus wiring plan for an office building is a different craft. When I read a portfolio, I am looking for cloud accounts and the paths between them, with a reason for every path that faces the internet.
Resilience is the part leadership remembers after an outage. The architect decides whether a critical system runs in more than one region, what failover actually means, which data must be copied and how fresh that copy must be, and who has authority to declare the switch. Backups that have never been restored are a hope, not a design. I ask candidates to walk through a failure they planned for: what customers would have seen, which steps were automatic, and which steps still needed a person. Cost sits in the same conversation. A resilient design that the company will refuse to fund is unfinished. The architect should be able to show which pieces carry the bill and which cheaper pattern still meets the promise made to customers.
The tools vary by employer and by provider. Templates that create accounts the same way every time, diagrams, policy guardrails, and the provider's own console all show up. Some architects spend more time in reviews than in a template language, and that can be right if the engineers trust the patterns. I still expect fluency with at least one provider's building blocks: compute, storage, databases, private networking, and identity. Multi-cloud fluency is valuable when the company truly runs more than one provider. Claiming three providers from a single tutorial is easy to spot in an interview, because the tradeoffs will not survive a follow-up.
Vendor credentials, and no license in this seat
There is no universal license for a cloud architect. No state board issues a card that says you may design accounts and networks in a cloud. Employers use other proof. The strongest proof is a system you shaped that other people are running, plus a clear story of the decisions in it. After that, vendor credentials help a hiring manager sort a stack of resumes.
What the vendor names signal
Amazon Web Services, Microsoft Azure, and Google Cloud each publish credentials aimed at people who design on that platform. Names you will see include the AWS Certified Solutions Architect credentials, Microsoft Certified: Azure Solutions Architect Expert, and Google Cloud Professional Cloud Architect. Each one is granted by that vendor. It shows you studied that provider's design patterns and could apply them under the vendor's own assessment. It does not replace a design you can defend in the room.
People prepare by building. A personal lab, an internal migration, or a reference architecture for a team you already support will teach more than reading alone. Pick the provider your target employers use, learn the account and network patterns that provider recommends, and practice explaining them to someone who will not let vague answers stand. If you already work beside cloud engineers, ask to own a design review before you chase a second vendor's credential. I would rather see one credential that matches our stack and a diagram from a real project than three badges and no system.
Credentials go stale because the platforms change. Treat renewal as part of staying employable, and keep the portfolio next to the badge. When a credential and a story disagree, I believe the story I can test. Bring the diagram. Be ready to say what you would change if the bill doubled or if a region went dark.
How a design seat gets filled
Most cloud architects I hire were already close to the work. They were senior engineers, platform leads, or infrastructure designers who kept getting pulled into the "how should this sit" conversation. A smaller number come from a consulting firm where they designed landing zones for clients and now want a single company. Direct jumps from a general programming job, with no time spent on accounts and networks, rarely survive the design exercise.
The application should show scope. Name the providers, the kind of systems, and whether you owned the account model, the network, the recovery plan, or all three. A link to a public write-up helps when the real system is confidential. In the interview I usually give a messy situation: two teams, one shared database, a finance cap, and a security worry. I am listening for the order of decisions, the risks you refuse to hide, and whether you leave the engineers a buildable path. Polished vocabulary with no sequence is a warning.
References matter in this role because design quality is partly social. I ask engineers whether your patterns were usable, and I ask a security partner whether you treated their concerns as part of the design or as a late stamp. If you are moving cities, say so early. Pay varies sharply by location, and a design offer in one market is a poor template for another. If you need sponsorship or a remote arrangement, put it in the first conversation so the scope of the seat stays honest.
After the first architecture title
The first architecture title usually still sits near a single platform or a single group of products. You own the patterns for that slice, you review the designs that touch it, and you spend part of the week unblocking engineers. The next step is often a senior or principal title with a wider map: several business lines, more than one provider, or the connection between cloud systems and older company platforms. Influence grows faster than headcount. You may still have no one reporting to you, and the job can still be larger.
Some people move toward a director of platform, a head of infrastructure, or a technology leadership seat. That path adds budgets, hiring, and vendor contracts to the design work. Others stay on an individual path and become the person the company calls for the hardest structural choices. Both are real. The mistake is drifting into meetings that no longer change the system. If your calendar is full and the account model is still a mess, the title has outrun the work.
Consulting and advisory practices hire architects who can repeat the craft across clients. The pay can be strong, and the context changes constantly. The trade is less ownership of what happens after the design is handed over. If you want to see a system mature, a single company's principal seat is usually the better fit. If you want variety and you can sell a design as well as draw it, a firm will use that. Either way, keep a record of decisions and outcomes. Promotions in this field are argued with stories of systems that held up, bills that stayed explainable, and outages that went the way the design said they would.
What a cloud design offer is worth
Read a cloud design offer against the May 2025 Occupational Employment and Wage Statistics series for computer network architects, the published set these design dollars come from. On that series, pay starts near $79,900, the median is $134,050, and the high end of the published range in California is $224,930, among places with enough people in the job for the Bureau to publish it. California's typical pay, the state median of $158,870, is a different figure from that high end. Use the high end as the top of the published range, and use the state median when you are talking about typical pay in a place.
The gap from the entry figure to the median is $54,150. If an offer lands near $79,900, that distance is the conversation. Ask which parts of the design seat are in the job: account model, network, resilience, cost, or only a slice of one of them. A narrow slice can justify a figure near the start. Ownership of the whole picture, especially if you are the person other teams must consult, belongs closer to the median and beyond. The gap from the median to the California high end is $90,880. That span is real for people whose designs cover large, costly systems in a high-paying market. It is a poor target to name on a first architecture title with a single product and no record yet.
State medians show how place changes typical pay. Washington's median is $168,070, which is $34,020 above the national median. New Jersey sits at $162,350, Maryland at $159,460, California at $158,870, and Massachusetts at $155,060. Kansas, at $100,610, is the low end among the published state medians. A Washington offer near the national median is a different conversation from a Kansas offer near $100,610. Name the state, and compare the offer with that state's typical pay rather than with a national figure alone. Moving for pay only works if the design work itself is the work you want. A higher median in a market where you will only draw slides is a weak trade.
When you negotiate, put the design scope next to the number. If they offer the median and the role includes multi-team authority, on-call design ownership during incidents, or more than one provider, say what similar scope pays in the state where you will sit. If they offer closer to $168,070 because the job is in Washington, check that the role matches the responsibility that figure implies, and remember that $224,930 is the California high end of the range, not Washington's typical paycheck. Bring a diagram of a system you would actually put into production, and let that diagram carry the salary talk.
The top of Cloud Architect pay — and how to get there with AI
$224,930what Cloud Architect pay reaches in California
Highest state-level top-of-range annual wage for Computer Network Architects, among states with at least 500 people in the job. U.S. Bureau of Labor Statistics, Occupational Employment and Wage Statistics, May 2025.
And the role it leads to — Computer Hardware Engineers — reaches $281,210 in California.
$79,900entry$134,050middle$224,930top end
Generalist design work is priced against a large supply of people who can draw a three-tier diagram; the top of the range belongs to the cloud architect who owns one hard seam — usually the place where real circuits, address space and regulated traffic meet a provider network — and is the only person who can sign off a change there.
The occupation's own task list gives the tell: relocating user connectivity equipment, preparing network diagrams with design software, ordering and tracking telecommunications equipment for customer premises and backbone networks, raising purchase requisitions for cabling and test gear. That is not an abstraction. Most designs are now assembled quickly — templates in Amazon Web Services AWS CloudFormation, configuration pushed with Ansible software, and a model such as Claude perfectly able to draft the first pass of either. What stays scarce is the person who can say what happens to a latency-sensitive workload when the primary circuit drops, whose address plan does not collide after the next acquisition, and who has actually stood in the facility. Narrow into that seam and the supply of substitutes gets very thin.
Your playbook, by where you are now
Just startingDraw the whole path, cage to workload
Diagram one production application end to end, from the physical handoff and the cabling through to the compute on Amazon Elastic Compute Cloud EC2, and get it corrected by someone who was there when it was built.
Learn the address plan your organisation actually uses, including the ranges nobody documented, and write it down.
Rebuild a hand-made environment as a template in Amazon Web Services AWS CloudFormation so the diagram and the reality cannot drift apart.
Read the equipment inventory and the circuit contracts, because both constrain every design you will be asked for.
Produce the system activity and performance report yourself for one quarter instead of skimming somebody else's.
What proves it: An end-to-end path diagram for a live application that the network team endorses without correction.
Realistic span: the opening two years
A few years inTake the workload nobody will touch
Pick the system that has not moved because it is latency-bound, licence-bound or regulated, and make it your problem.
Get deep on one interconnect model — private circuits, routing policy, failover behaviour — rather than broad on three providers.
Ask Claude to summarise a long device configuration in plain language, then verify every line against the running configuration before you trust a word of it.
Keep access and identity design in scope, because the segmentation argument and the connectivity argument are the same argument.
Sit on the change board for that seam and start refusing changes with reasons people can check.
What proves it: A migration or redesign of a workload others had written off, with its failover tested rather than asserted.
Realistic span: years three through seven
ExperiencedHold the seam and the spend that goes with it
Take ownership of the circuit and equipment purchase requisitions for your corner, so capacity planning and design sit with one person.
Review and rule on modification requests from engineers and managers rather than only responding to them.
Publish the standard other architects design against, and keep it short enough that they read it.
Teach the operations and support staff how the voice, video and data paths behave when things break, because your design is only as good as the people running it at midnight.
Be the named escalation for the seam, in writing, and price yourself accordingly at review.
What proves it: Named design authority over one interconnect domain, with budget responsibility attached.
Realistic span: from about year eight
The next 90 days
Choose the connection your organisation would suffer most from losing — usually a private circuit, a partner link or the path a regulated system depends on — and become the person who understands it completely within a quarter. Trace it physically: which rack, which port, which carrier, which contract, what the second path is and whether anyone has ever tested it. Draw it properly. Then run the failure on paper and write what would actually happen to each dependent workload, in enough detail that the operations team can argue with you. Almost nobody does this, which is precisely why it is worth doing. Finish it and you are no longer a cloud architect who produces designs on request; you are the person consulted before anyone changes that seam.
Wage figures: BLS OEWS, May 2025. The playbook is PayCrunch editorial guidance, not a guarantee of pay or placement.
Every figure is the national median from the U.S. Bureau of Labor Statistics (OEWS) shown on that role’s own page.
Never used AI before? Start here (2 minutes).
Turn on an AI assistant inside your IaC workflow this week. Enable GitHub Copilot, Amazon Q Developer, or Cursor in the editor where you write Terraform or Pulumi, and let it draft resource blocks, modules, and variables while you review every line before it merges. You will feel the speed-up on the first module.
For architecture, cost, and security reasoning, use Claude or ChatGPT (enterprise plans, no secrets or customer data) to structure designs, pressure-test trade-offs, and draft Well-Architected reviews. You bring the judgment and own every decision; AI removes the blank-page and boilerplate tax so you spend your time on the calls that matter.
The one rule, forever: Never let AI-generated infrastructure code reach production unreviewed — a bad Terraform plan can delete a database or open a security group to the internet. Always run it through plan review, policy-as-code checks, and a human approval before apply. Never paste live credentials, secrets, private IP ranges, or customer data into a consumer AI tool; use enterprise plans with data-retention controls and keep secrets in a vault.
The plays — exact steps, exact prompts
Do these in order. Each one is copy-paste ready. You do not need to know anything about AI going in.
1
Write and review Infrastructure-as-Code at double speed
Why this pays: Cloud architects are judged on how much reliable, secure infrastructure they can stand up and govern. AI that drafts your Terraform, Pulumi, or CloudFormation — while you review every line — lets you ship more environments and modules per sprint, which is the throughput that justifies a top-of-band architect.
TerraformAmazon Q DeveloperGitHub Copilot
1
Enable Amazon Q Developer or GitHub Copilot in your editor and let it scaffold Terraform modules, variables, and resource blocks while you review, name, and constrain everything it produces.
2
Use AI to generate a first-draft module from a plain-English spec, then harden it yourself.
Copy-paste this prompt
Act as a senior cloud architect. Write a Terraform module for [a highly-available VPC on AWS with public and private subnets across 3 AZs, NAT gateways, and flow logs]. Use variables for CIDR ranges and region, tag every resource with [cost-center and environment], and add comments explaining each block. List the security and cost trade-offs I should review before applying.
Treat the output as a draft. Run terraform plan, review the diff, and never apply AI-written IaC to production without policy checks and human approval.
What you'll haveMore secure, well-tagged infrastructure shipped per sprint — the throughput that anchors a top-of-band cloud architect.
2
Cut the cloud bill with AI-assisted FinOps
Why this pays: Nothing makes a cloud architect visible to the CFO like a materially lower bill. Using AI to analyze usage, model right-sizing, and draft the savings plan turns you into the person who directly moves a six- or seven-figure line item — the clearest business case for top-of-band comp.
AWS Cost ExplorerInfracostClaude
1
Wire Infracost into pull requests so every IaC change shows its cost delta before merge, and pull spend and utilization data from AWS Cost Explorer (or Azure Cost Management / GCP Billing).
2
Export the cost report and have AI turn raw numbers into a prioritized savings plan.
Copy-paste this prompt
Act as a FinOps-minded cloud architect. Here is our monthly cloud cost breakdown by service and the top resources by spend: [paste anonymized cost export — no account IDs or customer data]. Identify the biggest savings opportunities (right-sizing, reserved/savings plans, idle resources, storage tiering, data-transfer), estimate the monthly saving for each, and rank them by saving-per-effort. Flag anything that could hurt reliability.
Strip account IDs and customer identifiers before pasting. Validate every recommendation against real workload patterns before you change anything.
What you'll haveA documented, prioritized reduction in the monthly cloud bill — the CFO-visible win that pushes an architect toward $224,930.
3
Accelerate architecture design and Well-Architected reviews
Why this pays: The architect's core deliverable is a sound, defensible design. Using AI to structure options, stress-test trade-offs, and run a Well-Architected-style review lets you produce better decisions faster and document them cleanly — the strategic output that separates an architect from a build engineer.
AWS Well-Architected ToolClaudeCloudcraft
1
Draft and diagram the design fast — use Cloudcraft (or Diagrams-as-code) for the architecture diagram and the AWS Well-Architected Tool for the formal review pillars.
2
Use AI as a devil's advocate to pressure-test the design before you commit to it.
Copy-paste this prompt
Act as a principal cloud architect and skeptic. We are designing [a multi-region, event-driven order-processing system on AWS] with [expected 5,000 requests/sec peak, strict data-residency in EU]. Evaluate my proposed design against the AWS Well-Architected pillars (operational excellence, security, reliability, performance, cost, sustainability). Here is the design: [paste high-level design]. For each pillar, list the top risks, the questions I have not answered, and a stronger alternative where one exists.
Use it to challenge your thinking and structure a review doc — the architecture decision and its consequences are yours.
What you'll haveFaster, better-reasoned, well-documented designs that survive review — the strategic work that defines a senior cloud architect.
4
Enforce security and compliance with policy-as-code
Why this pays: A single misconfigured bucket or open security group can cost a company millions and a breach headline. The architect who bakes security guardrails into the pipeline becomes the trusted owner of cloud risk — an indispensable role that commands premium comp and unlocks regulated workloads.
CheckovWizClaude
1
Add Checkov (or tfsec) scanning to CI so misconfigurations fail the build, and use a CNAPP like Wiz or Prisma Cloud to catch risks in the running environment.
2
Use AI to write and explain custom policy-as-code rules for your organization's standards.
Copy-paste this prompt
Act as a cloud security architect. Write a Checkov custom policy (and explain it line by line) that fails any Terraform plan where [an S3 bucket is public, lacks encryption, or has no versioning]. Then list the 10 highest-impact guardrails we should enforce in CI for a [healthcare SaaS on AWS handling PHI], mapped to the relevant control (e.g., HIPAA, SOC 2).
Have security and compliance review the control mapping. AI drafts the rule; a qualified human confirms it actually satisfies the regulation.
What you'll haveAutomated security guardrails that let the org run regulated, high-value workloads safely — the trusted ownership that anchors premium comp.
5
De-risk large cloud migrations with AI
Why this pays: Migrations and modernizations are among the highest-budget cloud projects, and the architect who plans and de-risks them owns a large, visible line of work. Using AI to assess the estate, map dependencies, and draft the migration plan lets you lead bigger moves with confidence — exactly the scope that carries top-of-band pay.
AWS Migration HubClaudeTerraform
1
Inventory and group the estate with a discovery tool (e.g., AWS Migration Hub / Application Discovery Service, or Azure Migrate) before deciding what moves how.
2
Use AI to turn the inventory into a phased, risk-ranked migration plan.
Copy-paste this prompt
Act as a cloud migration architect. We are moving [an on-prem monolith plus 12 supporting services] to [AWS] over [6 months]. Given this application inventory and dependency list: [paste sanitized inventory], propose a wave-based migration plan using the 7 Rs (rehost, replatform, refactor, etc.) with a recommendation per app, the sequencing to minimize risk, the cutover and rollback strategy, and the top 5 risks with mitigations.
Sanitize hostnames and internal details. The plan is a starting framework to validate with app owners, not a schedule to execute blindly.
What you'll haveA phased, defensible migration you can lead end to end — the high-budget scope that carries a cloud architect to the top of the band.
6
Design the AI/ML platform your company runs on
Why this pays: As every company races to ship AI, the architect who can design the platform it runs on — secure model access, GPU/inference infrastructure, data pipelines, and cost controls — becomes the most valuable person in the room. This is the emerging, scarce skill that commands offers at and beyond the top of the band.
Amazon BedrockAmazon SageMakerClaude
1
Learn your cloud's managed AI stack hands-on — Amazon Bedrock for model access, SageMaker (or Vertex AI / Azure ML) for training and hosting — and prototype a small internal use case yourself.
2
Use AI to design a governed, cost-controlled reference architecture for company-wide AI.
Copy-paste this prompt
Act as an AI-platform architect. Design a reference architecture for a [mid-size enterprise] to run generative-AI features securely on [AWS]: model access via Bedrock, a retrieval layer over internal data, guardrails and prompt-injection defenses, per-team cost tracking and quotas, logging/observability, and data-privacy controls. Give me the component diagram in words, the top 5 risks, and a rollout plan from pilot to production.
This is a scarce, high-value skill — build real hands-on depth, not just diagrams. Validate cost and security assumptions before proposing it.
What you'll haveA secure, cost-governed AI platform you designed — the scarce, in-demand capability that earns offers at and beyond $224,930.
Your 12-month sequence to the top of the range
How the plays above stack into a path from median pay toward the $224,930 tier.
Month 1
Turn on an AI coding assistant in your IaC workflow and use it to draft and review Terraform/Pulumi modules — reviewing every line.
Months 2-3
Wire cost visibility (Infracost, Cost Explorer) into pull requests and ship your first AI-assisted FinOps savings plan.
Months 3-6
Use AI to structure architecture designs and Well-Architected reviews; add policy-as-code security guardrails to CI.
Months 6-9
Lead an AI-assisted migration or modernization: assess the estate, draft the wave plan, and de-risk the cutover.
Months 9-12
Go deep on your cloud's managed AI stack and prototype an internal generative-AI use case end to end.
Year 2
Design and own the company's AI/ML platform architecture — the scarce skill that carries comp toward $224,930.
Gear for this job
As an Amazon Associate, PayCrunch earns from qualifying purchases. Links to books and tools are for the job on this page; we only recommend what we’d use in the work.
Same live O’Reilly 3rd already on cloud-engineer / devops-engineer / devops-architect. This page’s first play is Write and review Infrastructure-as-Code and Month 1 is draft and review Terraform/Pulumi modules. Not Kubernetes Up and Running as the lead (that is site-reliability-engineer) and not CompTIA Security+ (that is software-engineer / infosec).
Next steps for a Cloud Architect
Some links below are affiliate or partner links. PayCrunch may earn a commission if you enroll or subscribe through them, at no extra cost to you. Wage figures on this page still come from the Bureau of Labor Statistics, not from these programs.
Cloud Architect work is specific enough that a stamped 'check out these courses' block would be noise. BLS files this work as Computer Network Architects (SOC 15-1241). O*NET Job Zone 4 is typical: a bachelor's degree, so the honest next credential is a professional certificate or bachelor's-level coursework — not a random catalog dump.
The occupation's listed knowledge areas include Telecommunications and Engineering and Technology; the links search those subjects, not a generic 'career courses' list.
Cloud Architects in this dataset list AJAX among the tools in use, so a program that names that stack is a better fit than a survey course.
Coursera search for architecture — a professional certificate or bachelor's-level coursework that lines up with computing, not a generic professional-development aisle.
FlexJobs screens remote, hybrid, freelance, and flexible listings so you are not wading through unverified ads. This is a job-board search for Cloud Architect work, not a claim that they list a counted SOC 15-1241 inventory.
Write a Cloud Architect resume, or one aimed at Computer Hardware Engineers, instead of a blank template. Resume Now is a resume builder; we are not claiming a counted template set for this SOC.
A Cloud Architect resume that names the actual tasks on this page, or the step-up title Computer Hardware Engineers, beats a blank template when you apply.
What Cloud Architects earn by state
These are the Bureau of Labor Statistics’ own figures for Computer Network Architects, state by state — not a cost-of-living adjustment applied to the national number. Only states employing at least 500 people in the occupation are shown, because a state median drawn from a handful of workers is noise rather than a signal.
Washington
$168,070
highest of them · +25% vs the national median
Kansas
$100,610
lowest of the 39 states and D.C. that qualify · -25% vs the national median
The same job pays $67,460 more a year at the median in Washington than in Kansas — 67% higher. That gap is what the Bureau measured, before any question of what it costs to live in either place. The top-of-range figure quoted at the head of this page, $224,930, is a different statistic in a different place: it is the 90th-percentile wage in California. The state that pays the typical worker most and the state where the best-paid go highest are not always the same one.
Source: U.S. Bureau of Labor Statistics, Occupational Employment and Wage Statistics, May 2025, SOC 15-1241. 39 states and D.C. clear the 500-employee reporting floor for this occupation; those below it are left out rather than shown with a wide error band.
Free data. Use any of it.
PayCrunch publishes verified, BLS-sourced salary + AI-playbook data on 1,000+ professions — free, no signup.
No — it changes what the job rewards. AI can draft Terraform, suggest right-sizing, and diagram a system, but it cannot own the trade-offs between cost, resilience, security, and business need, carry accountability for a design that must not fail, or navigate the politics of a migration. AI is augmentation: architects who use it govern far more surface area per person, while those who ignore it look slow and expensive by comparison.
Is it safe to let AI write my infrastructure code?
As a draft, yes — as an unreviewed apply, never. AI-generated IaC can open a security group to the world or destroy stateful resources on a bad plan. Always review the terraform plan diff, run policy-as-code checks (Checkov, tfsec), and require human approval before apply. The productivity is real; the discipline of review is non-negotiable and is part of the architect's job.
Which AI tool should a cloud architect start with?
Start with an assistant inside your IaC editor — Amazon Q Developer or GitHub Copilot — because it saves time on the boilerplate you write every day. Then add a reasoning model (Claude or ChatGPT, enterprise plan) for architecture, cost analysis, and review docs. Q Developer is especially handy on AWS because it understands the service catalog and can reference your account context.
How does using AI actually raise a cloud architect's pay?
By making your business impact bigger and more visible. AI lets you ship more infrastructure, cut a larger share of the cloud bill, pass audits faster, and lead bigger migrations — and increasingly, design the AI platform the whole company depends on. Comp at the top of the band tracks that scope and impact, not the volume of YAML you personally type.
Do I still need cloud certifications if AI can answer the questions?
Certifications (AWS/Azure/GCP Professional Architect) still help you get interviews and prove baseline breadth, and AI is a great study partner for them. But they are table stakes, not the differentiator. What moves you to the top of the band is demonstrated judgment — real designs that saved money, passed security review, and scaled — which AI helps you produce but cannot certify for you.
Methodology & sources
Salary (median, 10th, top of the range) — U.S. Bureau of Labor Statistics, OEWS.
By state — the Bureau of Labor Statistics’ own state medians, limited to states employing at least 500 people in the occupation. No cost-of-living arithmetic is applied to a wage anywhere on this page.
The plays — PayCrunch's own step-by-step guidance using publicly available AI tools. Tool names/URLs are real and current as of August 2026; prompts written to work as-is. Verify any professional output before relying on it.