> Markdown version of [/jobs/ext/3675755-cloud-security-architect](https://www.wearedevelopers.com/jobs/ext/3675755-cloud-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cloud Security Architect - **Company:** OpenKyber LLC - **Location:** New York, NY, United States - **Contract:** Permanent contract - **Skills:** User Authentication, Microsoft Azure, Cloud Computing Security, Configuration Management, Continuous Integration, Software Design Patterns, Identity and Access Management, Role-Based Access Control, Azure Active Directory, Systems Integration, Workflow Management Systems, Data Logging, Cloud Platform System - **Published:** October 10, 2026 - **Apply:** https://www.careerjet.com/jobad/us56e4be3e6077bbd64736ebca2d898fb4 ## About the Role * Advanced knowledge of Microsoft Entra ID (Azure AD ), Azure RBAC , security groups, privileged identity management (PIM ), and JIT access workflows . * Hands-on experience with Azure Policy and resource configurations, including enabling managed identities, provisioning Azure AD admin roles for services, and minimizing local service key usage. * Familiarity with Azure monitoring and logging capabilities , AAA (authentication, authorization, accounting) concepts, and integration with approval workflow tools. * Strong understanding of least-privilege access design and practical application of access control best practices in Azure. * Competence in baseline configuration management and maintaining accurate asset/data inventories., * Demonstrated experience implementing least-privilege design at scale and articulating the rationale for RBAC in Azure . * Ability to author and maintain IAM policies and procedures, perform access reviews, and support audit evidence and control test preparation. * Proven capability to implement and govern remote/elevated access, emergency access processes, and related incident handling. * Strong communication and documentation skills for technical writing and stakeholder coordination. * Ability to collaborate across engineering, security, and operations teams to drive consistent, compliant access practices. Nice-to-Have Experience * Integrating identity workflows with enterprise approval systems and ticketing/incident processes. * Exposure to application identity design patterns and CI/CD controls for secret management . * Background in supporting audit readiness for access controls in cloud environments . For applications and inquiries, contact:hirings@openkyber.com ## Description Role: Cloud Security-Azure IAM/RBAC Engineer Duration: 12+ months Location: New York, NY or Pittsburgh, PA(4 days onsite required weekly from day one) Interview: Video LOCAL Candidates ONLY !