Senior Azure Cloud Architect

Cutsforth, Inc.
United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$135,735.0 - $168,093.0
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Amazon Web Services Application Performance Management Microsoft Azure BigQuery Cloud Computing Cloud Engineering Continuous Integration DevOps Github Identity and Access Management Virtual Private Networks (VPN)
+28 more
Key Management Log Analysis Role-Based Access Control Azure Active Directory Azure DevOps Pipelines Kusto Query Language Azure Machine Learning Security Information and Event Management Wide Area Networks Google Cloud Cloud Monitoring Autoscaling Delivery Pipeline Large Language Models Multi-Agent Systems Multi-Cloud Firewalls (Computer Science) Infrastructure Automation Frameworks Information Technology Deployment Automation Bicep Microsoft Sentinel Azure AKS Machine Learning Operations Cloud Migration Terraform Network Server Key Vault

Job description

All Cutsforth employees are expected to perform their work in a manner that exhibits understanding and adherence to the Company Mission and Core Attributes of Cutsforth Employees. Employees in management roles must exhibit continual improvement along Cutsforth’s Leadership Traits. Further, each employee must read and adhere to corporate policies and safety protocols.

  • Learn more about Cutsforth here: Cutsforth.com/About
  • Read our Mission & Values here: Cutsforth.com/Values, * Design and maintain Azure Landing Zones using the Cloud Adoption Framework (CAF) Enterprise-Scale, including management group hierarchy, subscription vending, and policy-driven governance
  • Build and maintain Infrastructure as Code using Terraform (Azure Verified Modules) and/or Bicep, with reusable modules, managed state, and CI/CD-driven deployments
  • Architect hub-and-spoke and Virtual WAN network topologies using Azure Firewall Premium, Private Link/Private Endpoints, NSGs, UDRs, and hybrid connectivity (ExpressRoute, VPN Gateway)
  • Design and operate production Azure Kubernetes Service (AKS) clusters, including Azure CNI networking, workload identity, autoscaling, and GitOps delivery (Flux/ArgoCD)
  • Implement identity and access architecture with Microsoft Entra ID (Conditional Access, PIM, managed identities), Entra External ID for customer identity, and RBAC at scale
  • Establish security and compliance tooling using Microsoft Defender for Cloud, Microsoft Sentinel (SIEM/SOAR), Azure Policy, Key Vault, and Defender for Containers/Servers
  • Map cloud architecture to compliance frameworks such as SOC 2, ISO 27001, FedRAMP, and IEC 62443, and support audit and remediation efforts
  • Drive cost optimization and FinOps practices, including reservations, savings plans, tagging strategy, and chargeback/showback models
  • Build observability across the platform using Azure Monitor, Log Analytics, Application Insights, and author KQL queries for monitoring and troubleshooting
  • Lead Well-Architected Framework reviews and strengthen DevOps pipelines (GitHub Actions / Azure DevOps), branch strategy, secrets management, and supply-chain security (SBOM, signed artifacts)

Requirements

  • Bachelor’s degree in Computer Science, Engineering, or a related field, or equivalent professional experience
  • 8-12 years of cloud engineering experience, including 5+ years architecting production Azure environments at enterprise scale
  • Deep expertise with Azure Landing Zones and the Cloud Adoption Framework (CAF) Enterprise-Scale, including management group hierarchy, subscription vending, and policy-driven governance
  • Infrastructure as Code mastery with Terraform (Azure Verified Modules) and/or Bicep, including reusable module design, state management, and CI/CD-driven deployments
  • Strong Azure networking experience: hub-and-spoke and Virtual WAN topologies, Azure Firewall Premium, Private Link/Private Endpoints, NSGs, UDRs, and hybrid connectivity (ExpressRoute, VPN Gateway)
  • Production Azure Kubernetes Service (AKS) experience: cluster design, Azure CNI networking, workload identity, autoscaling, and GitOps (Flux/ArgoCD)
  • Microsoft Entra ID expertise (Conditional Access, PIM, managed identities), Entra External ID for B2C/customer identity, and RBAC at scale
  • Hands-on experience with Azure security and compliance tooling: Microsoft Defender for Cloud, Microsoft Sentinel (SIEM/SOAR), Azure Policy, Key Vault, and Defender for Containers/Servers
  • Cost optimization and FinOps experience (reservations, savings plans, tagging strategy, chargeback/showback)
  • Observability fluency with Azure Monitor, Log Analytics, Application Insights, and KQL
  • Ability to lead Azure Well-Architected Framework reviews across reliability, security, cost, operational excellence, and performance
  • Strong DevOps background with GitHub Actions / Azure DevOps Pipelines, branch strategy, secrets management, and supply-chain security (SBOM, signed artifacts), * Azure Solutions Architect Expert (AZ-305) and DevOps Engineer Expert (AZ-400) certifications
  • AWS Solutions Architect Professional, Google Cloud Professional Architect, or equivalent certification
  • Experience mapping architecture to compliance frameworks such as SOC 2, ISO 27001, FedRAMP, and industrial standards (IEC 62443)
  • Multi-cloud experience with AWS (Organizations, Control Tower, EKS, IAM) and cross-cloud landing zone parity
  • GCP experience with Vertex AI, BigQuery, Cloud SQL, and GKE
  • ML/AI engineering experience with Azure AI Foundry / Azure Machine Learning, including model deployment, endpoints, and MLOps pipelines
  • Familiarity with RAG architectures, vector databases, and LLM application patterns
  • Production GenAI experience including agent orchestration, prompt/eval pipelines, and responsible-AI governance
  • Experience with model serving, inference optimization, and GPU capacity planning

Other Qualifications:

  • Successfully pass background check for cybersecurity site access
  • Expert-level command of Microsoft Azure architecture at enterprise scale, with the ability to set platform standards others build against
  • Skilled at translating business and compliance requirements into governed, policy-driven cloud designs
  • Fluent in Infrastructure as Code practices and able to enforce repeatable, automated deployments across teams
  • Able to lead architecture and Well-Architected reviews, balancing reliability, security, cost, operational excellence, and performance
  • Strong communicator who can explain cloud architecture and trade-offs to both engineers and non-technical stakeholders
  • Capable of managing multiple concurrent initiatives and guiding the technical decisions of other engineers
  • Security-minded, with a working understanding of compliance frameworks relevant to industrial and customer-facing systems

Alignment with Corporate Values

Benefits & conditions

5.05.0 out of 5 stars Remote $135,735 - $168,093 a year - Full-time, * $135,735 - $168,093, depending on years of experience

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:46 min

Navigating a career in cloud transformation consulting

Piet Van Dongen · LIVE

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · WWC Europe 2026

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · WWC 2023

2:56 min

Provisioning a secure container infrastructure with Bicep

Matthias Falkenberg +1 · WWC 2022

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

2:40 min

Using GitHub primitives for internal documentation and corporate operations

Kyle Daigle · Coffee With Developers

Videos

See all

Related articles

See all