Azure Cloud Architect

AVIVA PLC
New York, NY, United States
25 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$197,600.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Azure Cloud Computing Security Continuous Integration Multi-Factor Authentication Github Network Topologies Identity and Access Management Subnetting Windows PowerShell Role-Based Access Control Zero Trust Network Access Runbook
+8 more
SQL Databases Azure Powershell Firewalls (Computer Science) CIS Benchmarks Cloud Optimization Devsecops Key Vault Vulnerability Analysis

Job description

We’re seeking an Azure Cloud Security Architect to design and implement secure, scalable Azure architecture across all environments. This includes subscription structure, network topology, and Well-Architected Framework alignment; provisioning core Azure infrastructure (VNets, App Services, VMs, SQL, Storage, Key Vault, AKS); implementing IAM and Zero Trust controls (RBAC, Entra ID, MFA, Conditional Access, PIM); and enforcing governance and compliance (Azure Policy, ISO 27001, NIST). The role also covers risk/vulnerability assessments, DevSecOps integration, and producing runbooks and architecture documentation for knowledge transfer.

Requirements

  • Extensive experience designing and implementing Azure cloud architecture in enterprise environments
  • Strong knowledge of Azure Well-Architected Framework and cloud best practices (security, scalability, resilience, governance)
  • Hands-on Azure networking experience (VNets, subnets, NSGs, Azure Firewall, WAF, private endpoints)
  • Azure infrastructure provisioning experience (App Services, VMs, Storage, SQL, Key Vault)
  • Strong IAM expertise (Entra ID, RBAC, MFA, Conditional Access, PIM)
  • Solid understanding of Zero Trust security architecture
  • Experience implementing Azure Policy, governance controls, and security baselines
  • Knowledge of cloud security, threat modeling, and risk assessment
  • Familiarity with ISO 27001, NIST, and related compliance frameworks
  • DevSecOps experience with CI/CD security integration
  • Strong documentation skills (architecture diagrams, runbooks, technical docs)
  • Excellent communication and stakeholder engagement skills

Desirable Skills/Experience:

  • PowerShell and Azure CLI scripting
  • GitHub Actions and Azure cost management
  • Azure Administrator Associate certification
  • Azure Solutions Architect Expert certification, * Azure architecture: 6 years (Preferred)
  • Azure provisioning: 5 years (Preferred)
  • Azure IAM: 4 years (Preferred)
  • Azure networking: 4 years (Preferred)
  • Azure governance: 4 years (Preferred)
  • Well-Architected: 4 years (Preferred)
  • Risk assessment: 4 years (Preferred)
  • Zero Trust : 3 years (Preferred)
  • ISO 27001/NIST: 3 years (Preferred)
  • DevSecOps: 3 years (Preferred)
  • PowerShell/CLI: 2 years (Preferred)
  • Azure cost mgmt: 2 years (Preferred)

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:55 min

Centralizing credentials management using Azure Key Vault resource integration

Marcel Lupo · LIVE

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · WWC 2023

2:50 min

Introduction and the value of runbooks

Hila Fish · WWC 2023

9:24 min

Azure well-architected framework cost optimization disciplines

Paweł Siwek Paweł Siwek · Europe 2026 Virtual

3:03 min

Implementing secured configuration vaults via Azure

Markus Möller · WWC 2021

1:24 min

Evaluating formal AWS certifications versus raw practical engineering experience

Jan Giacomelli · LIVE

Videos

See all

Related articles

See all