Azure Cloud Architect / Administration Specialist

Oz Solutions Group Inc.
New York, NY, United States
19 days ago

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Compensation
$90,000.0 - $150,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Azure Cloud Computing Security Continuous Integration Multi-Factor Authentication Github Identity and Access Management Network Security Windows PowerShell Role-Based Access Control Zero Trust Network Access Runbook SQL Databases
+11 more
Azure Powershell Firewalls (Computer Science) Bicep Azure AKS CIS Benchmarks Cloud Optimization Terraform Devsecops Azure Resource Manager Key Vault Vulnerability Analysis

Job description

You will extend, remediate, and harden an existing enterprise Azure tenant for a large-scale public sector organization - working within an established, already-defined subscription and management-group structure across Development, QA, UAT, Staging, and Production. This is a hands-on architecture role: you’ll provide architectural leadership and build in alignment with the Azure Well-Architected Framework, owning security, identity, networking, governance, and DevSecOps across cloud and on-premises integration. You’ll work within an established Azure DevOps and GitHub toolchain.

This is not a greenfield build. We’re looking for an architect who is just as strong remediating and extending a live enterprise tenant and landing zone as designing one - and who can whiteboard and defend an end-to-end Azure architecture on the spot.

WHAT YOU’LL DO

  • Extend, remediate, and harden an existing enterprise Azure landing zone; refine resource organization, naming conventions, and tagging standards within the established subscription and management-group structure
  • Design secure network topology (VNets, subnets, NSGs, hub-and-spoke, Azure Firewall/WAF, private endpoints) and produce architecture diagrams for stakeholder approval, aligned to the Azure Well-Architected Framework
  • Provision and configure core Azure resources (App Services, VMs, SQL, Storage, Key Vault); provision and support Azure Kubernetes Service (AKS)
  • Implement identity and access management - Entra ID, RBAC, MFA, Conditional Access, and PIM; manage Key Vault and secrets, and support data protection, classification, and DLP
  • Implement Azure Policy, governance controls, and security baselines; apply Zero Trust principles aligned to citywide Cyber GRC standards
  • Conduct threat modeling, risk and vulnerability assessments, audits, and remediation tracking; ensure compliance with ISO 27001, NIST, and related frameworks
  • Integrate security into CI/CD pipelines (DevSecOps) across Azure DevOps and GitHub; automate with Infrastructure as Code (Bicep, ARM, or Terraform), PowerShell, and Azure CLI
  • Develop runbooks, operational documentation, and architecture diagrams; conduct knowledge transfer to internal teams
  • Provide occasional off-hours or weekend support during production cutovers, upgrades, and deployments

Requirements

Extensive hands-on experience designing, implementing, AND remediating/extending enterprise Azure environments - able to whiteboard and defend an end-to-end architecture live

  • Deep knowledge of the Azure Well-Architected Framework and cloud best practices (security, scalability, resilience, governance, cost)
  • Hands-on Azure networking: VNets, subnets, NSGs, hub-and-spoke, Azure Firewall, WAF, private endpoints
  • Azure infrastructure provisioning: App Services, VMs, Storage, SQL, Key Vault (AKS a strong plus)
  • Strong Identity and Access Management expertise: Entra ID, RBAC, MFA, Conditional Access, PIM
  • Solid Zero Trust security architecture and implementation
  • Azure Policy, governance controls, and security baselines at scale
  • Cloud security, threat modeling, and risk assessment
  • DevSecOps / CI/CD security integration (Azure DevOps and GitHub) and Infrastructure as Code (Bicep, ARM, or Terraform)
  • Familiarity with regulatory and compliance frameworks (ISO 27001, NIST, etc.)
  • Strong documentation skills (architecture diagrams, runbooks, technical documentation) and stakeholder communication
  • Able to work on-site in Lower Manhattan 3 days per week (hybrid)

PREFERRED

  • Azure certifications: Azure Solutions Architect Expert (AZ-305), Azure Administrator Associate (AZ-104)
  • PowerShell and Azure CLI scripting; GitHub Actions
  • Azure cost management and optimization
  • Public sector / regulated-environment experience, * Will you be able to provide 2 references?
  • Do you have hands-on experience remediating or extending an existing enterprise Azure tenant / landing zone (Entra ID, RBAC, PIM, Zero Trust, hub-and-spoke networking, Azure Policy governance)?

About the company

OZ Solutions Group is a technology services company delivering IT and cybersecurity solutions to government and public sector clients across New York City. We are hiring one (1) Azure Cloud Architect (Administration Specialist) to support a large-scale public sector organization on a client engagement in Lower Manhattan.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

9:24 min

Azure well-architected framework cost optimization disciplines

Paweł Siwek Paweł Siwek · Europe 2026 Virtual

2:50 min

Introduction and the value of runbooks

Hila Fish · WWC 2023

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · WWC 2023

2:56 min

Provisioning a secure container infrastructure with Bicep

Matthias Falkenberg +1 · WWC 2022

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

1:32 min

Structuring automated incident workflows between runbooks and raw models

Aram Hakobyan Aram Hakobyan +1 · WWC Europe 2026

Videos

See all

Related articles

See all