Senior Azure Cloud Architect (Hybrid)

Serigor Inc
Springfield, United States of America
2 days ago

Role details

Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior
Compensation
$ 237K

Job location

Springfield, United States of America

Tech stack

Microsoft Active Directory
Application Performance Management
Azure
Bash
Microsoft Online Services
Cloud Computing
Computer Security
System Configuration
Data Infrastructure
Database Queries
Software Design Patterns
DNS
Github
Identity and Access Management
Virtual Private Networks (VPN)
Python
PostgreSQL
Linux System Administration
Log Analysis
SQL Azure
Windows Server
Open Service Interface Definitions
PCI Data Security Standards
Powershell
Role-Based Access Control
Azure
Kusto Query Language
Zero Trust Network Access
Systems Integration
Virtual Machines
Virtualization Technology
Azure
Load Balancing
Microsoft Power Automate
Cloud Monitoring
Istio
Firewalls (Computer Science)
Data Layers
Event Driven Architecture
Microsoft Fabric
Data Lake
Kubernetes
Information Technology
Bicep
Microsoft Sentinel
Cosmos DB
Cloud Migration
Terraform
Code Restructuring
Azure
Api Management
Serverless Computing
Key Vault
VMware
Microservices

Job description

This position specifically requires both deep hands-on Azure engineering and architecture-level design in a single individual. The Architect will produce reference architectures, diagrams, and architecture decision records that engineering teams can implement directly; define infrastructure as code standards for the team; lead architecture review boards and design authority meetings; and drive enterprise-scale landing zone design and governance aligned to the Microsoft Cloud Adoption Framework and the Azure Well-Architected Framework. The Architect shall be adept at interpersonal communications, teamwork, goal setting, and business process improvement, and shall be comfortable translating business requirements into technical designs and presenting solution designs and tradeoffs to CIOs, CTOs, and senior leadership., * Work effectively with federal and contractor personnel to execute the project tasks;

  • Collaborate with client and other federal staff and contractors to refine and elaborate requirements.
  • Design enterprise-scale Azure solutions across compute services including Virtual Machines, VM Scale Sets, App Services, Azure Functions, Container Apps, AKS, and Azure Batch, selecting the right option for a given workload.
  • Architect advanced Azure networking spanning Virtual Networks, NSGs, UDRs, Private Endpoints, Load Balancer, Application Gateway, Azure Firewall, Front Door, Virtual WAN, ExpressRoute, and VPN Gateway, including hub and spoke topologies and enterprise DNS strategy.
  • Design identity architecture using Microsoft Entra ID, including Conditional Access, Privileged Identity Management, B2B and B2C scenarios, federation with on-premises Active Directory, managed identities, and RBAC.
  • Apply the Azure Well-Architected Framework across reliability, security, cost optimization, operational excellence, and performance efficiency.
  • Implement Cloud Adoption Framework practices, including enterprise scale landing zone design and governance blueprints.
  • Design multi region, highly available, and disaster resilient solutions with defined recovery time and recovery point objectives.
  • Produce reference architectures, diagrams, and architecture decision records that an engineering team can implement directly.
  • Lead workload assessments using Azure Migrate and map applications to the five Rs of rehost, refactor, rearchitect, rebuild, and replace.
  • Perform wave planning for large scale datacenter exits, including dependency mapping and cutover planning.
  • Define infrastructure as code standards and repository structure for the team, and review and validate Bicep or Terraform code written by others.
  • Build and maintain CI/CD pipelines in Azure DevOps or GitHub Actions, including artifact management, secret scanning, and pipeline security hardening.
  • Implement release strategies including blue and green, canary, and ring based deployments.
  • Operate production AKS clusters, including upgrades, node pool management, and networking through Azure CNI or Calico, with Helm chart authoring and GitOps workflows using Flux or ArgoCD.
  • Implement security, compliance, and governance using Microsoft Defender for Cloud, Microsoft Sentinel, and Key Vault with secret rotation, together with Azure Policy, Management Groups, and Blueprints, applying Zero Trust principles across identity, network, and data layers.
  • Configure Azure Monitor, Log Analytics, and Application Insights, and author KQL queries for diagnostics, alerting, and dashboards.
  • Provide incident command, including root cause analysis and capacity planning at scale;
  • Drive FinOps practices using Azure Cost Management, reserved instances, savings plans, and rightsizing, and build total cost of ownership and return on investment models for executive stakeholders.
  • Lead a team of engineers, including task assignment and design reviews with clear, constructive feedback.
  • Lead architecture review boards and design authority meetings, and facilitate discovery workshops with business and technical stakeholders.
  • Mentor engineers and architects on design patterns and troubleshooting technique.

Requirements

  • Degree in Computer Science or related field.
  • Between 9 and 15 years of total IT experience, including at least 5 to 7 years of hands-on Azure engineering and at least 2 to 4 years operating at an architecture or technical leadership level.
  • A career path that progressed from hands-on engineering into architecture, since this position specifically requires both skill sets in one candidate.
  • Advanced, hands-on expertise across Azure compute services, including Virtual Machines, VM Scale Sets, App Services, Azure Functions, Container Apps, AKS, and Azure Batch.
  • Full lifecycle knowledge of Blob Storage, Azure Files, Managed Disks, and storage lifecycle management policies.
  • Advanced Azure networking experience at an enterprise level, including hub and spoke design and DNS strategy.
  • Identity expertise covering Microsoft Entra ID administration and architecture, including Conditional Access, Privileged Identity Management, B2B and B2C, federation, managed identities, and RBAC design.
  • Data platform experience across Azure SQL, Cosmos DB, PostgreSQL Flexible Server, Synapse Analytics, Microsoft Fabric, and Data Lake Storage, from both an administration and a solution design perspective.
  • Integration services knowledge including API Management, Service Bus, Event Grid, Event Hubs, and Logic Apps.
  • Deep mastery of the Azure Well-Architected Framework and fluency with the Cloud Adoption Framework.
  • Expert level, hands-on proficiency in Bicep or Terraform, including module design, state management, and reusable patterns.
  • Working knowledge of ARM templates for legacy or complex deployments.
  • Strong scripting ability in PowerShell, Bash, and Python for automation and validation.
  • Production experience operating AKS, including upgrades, node pool management, and networking through Azure CNI or Calico.
  • Hands-on experience with Microsoft Defender for Cloud, Microsoft Sentinel, and Key Vault, including secret rotation practices.
  • Governance design using Azure Policy, Management Groups, and Blueprints.
  • Advanced configuration of Azure Monitor, Log Analytics, and Application Insights, with strong KQL query writing.
  • Practical experience with Azure Cost Management, reserved instances, savings plans, and rightsizing.
  • Clear written and verbal communication, including polished design documentation, with strong stakeholder management, negotiation, and the ability to influence without direct authority., * Background in Windows Server, Linux administration, or virtualization platforms such as VMware, which is valuable for migration and hybrid scenarios.
  • Exposure to a regulated industry such as financial services, healthcare, or government.
  • Hybrid architecture experience using Azure Arc, Azure Stack HCI, and Azure Stack Edge.
  • Application modernization expertise, including microservices, event driven architectures, serverless patterns, and strangler fig migrations.
  • Familiarity with relevant frameworks such as the CIS Azure Benchmark, NIST 800-53, FedRAMP, HIPAA, or PCI DSS.
  • Working knowledge of service mesh concepts through Istio or Open Service Mesh.
  • Understanding of Enterprise Agreement, Microsoft Customer Agreement, and bring your own license structures.
  • Experience with Agile/Scrum development environments.
  • Experience working with cross-functional teams in a federal or regulated environment.
  • An ownership mentality and comfort operating with ambiguity., * Preferred: SC-100, Cybersecurity Architect Expert.
  • Preferred: CKA, Certified Kubernetes Administrator.

Apply for this position