Job Summary
We're seeking an Azure Cloud Security Architect to design and implement secure, scalable Azure architecture across all environments. This includes subscription structure, network topology, and Well-Architected Framework alignment; provisioning core Azure infrastructure (VNets, App Services, VMs, SQL, Storage, Key Vault, AKS); implementing IAM and Zero Trust controls (RBAC, Entra ID, MFA, Conditional Access, PIM); and enforcing governance and compliance (Azure Policy, ISO 27001, NIST). The role also covers risk/vulnerability assessments, DevSecOps integration, and producing runbooks and architecture documentation for knowledge transfer.
Mandatory Skills/Experience:
- Extensive experience designing and implementing Azure cloud architecture in enterprise environments
- Strong knowledge of Azure Well-Architected Framework and cloud best practices (security, scalability, resilience, governance)
- Hands-on Azure networking experience (VNets, subnets, NSGs, Azure Firewall, WAF, private endpoints)
- Azure infrastructure provisioning experience (App Services, VMs, Storage, SQL, Key Vault)
- Strong IAM expertise (Entra ID, RBAC, MFA, Conditional Access, PIM)
- Solid understanding of Zero Trust security architecture
- Experience implementing Azure Policy, governance controls, and security baselines
- Knowledge of cloud security, threat modeling, and risk assessment
- Familiarity with ISO 27001, NIST, and related compliance frameworks
- DevSecOps experience with CI/CD security integration
- Strong documentation skills (architecture diagrams, runbooks, technical docs)
- Excellent communication and stakeholder engagement skills
Desirable Skills/Experience:
- PowerShell and Azure CLI scripting
- GitHub Actions and Azure cost management
- Azure Administrator Associate certification
- Azure Solutions Architect Expert certification
Pay: From $95.00 per hour
Experience:
- Azure architecture: 6 years (Preferred)
- Azure provisioning: 5 years (Preferred)
- Azure IAM: 4 years (Preferred)
- Azure networking: 4 years (Preferred)
- Azure governance: 4 years (Preferred)
- Well-Architected: 4 years (Preferred)
- Risk assessment: 4 years (Preferred)
- Zero Trust : 3 years (Preferred)
- ISO 27001/NIST: 3 years (Preferred)
- DevSecOps: 3 years (Preferred)
- PowerShell/CLI: 2 years (Preferred)
- Azure cost mgmt: 2 years (Preferred)
Work Location: In person