About Networkz IT
Networkz IT is a managed services provider purpose-built for regulated industries. We go deepest in life sciences, supporting biotech organizations from pre-seed through post-IPO and acquisition across FDA 21 CFR Part 11, GxP, SOX, HIPAA, and CMMC frameworks. We do not treat IT as commodity helpdesk. Every system decision passes through a stage-appropriate compliance and validation review before it goes near a client environment.
Our mission: deliver exceptional IT infrastructure and compliance solutions that enable our clients to operate with confidence, scale without fear, and advance work that matters.
Our four core values drive every client engagement and every internal decision.
- Empathy: we communicate with transparency, actively listen, and lead with understanding and respect in every interaction, with clients and with each other.
- Accountability: we operate with integrity, honesty, and ownership on all commitments we make to our clients, team, and ourselves.
- Growth Mindset: we prioritize the growth of our clients and team through continuous improvement, scalability, and personal development.
- Detail Oriented: we achieve operational excellence through high-quality, repeatable, and adaptable processes that drive scalability and consistent results.
Position Summary
The Cloud & Security Architect is NIT's senior technical authority. This role designs the technical solutions that solve client problems, and owns the architecture and design integrity of NIT's full managed services stack, with particular depth in Microsoft cloud and identity (Azure, Entra ID, Microsoft Defender), and holds ownership of the endpoint security, networking, and virtual desktop platforms NIT deploys across its client base.
This is a senior individual contributor role and NIT's Tier 3 escalation point for complex technical issues. The Cloud & Security Architect sets the architecture standard for client environments and holds design authority over them. Engineers and technicians execute within the standards this role defines.
Core Responsibilities
Cloud Architecture and Configuration Ownership. Own the architecture, configuration, and security posture of client Microsoft cloud environments: Azure infrastructure, Entra ID, and the Microsoft Defender / Microsoft Security suite. Define and maintain configuration baselines and security policy frameworks that engineering work is measured against. Make the final call on Azure and Microsoft Security architecture decisions. Ensure every client’s cloud environment is built to a documented, defensible standard, and that deviations are identified, reviewed, and resolved rather than worked around.
Security and Infrastructure Stack Ownership. Own the architectural standard and final decision authority for NIT's broader security and infrastructure toolstack across the client base: endpoint security and monitoring (ThreatLocker, Huntress, NinjaRMM), network and firewall infrastructure (Fortinet), and virtual desktop infrastructure (Nerdio). Set configuration baselines, hold the engineering team accountable to them, and build hands-on fluency across this stack over time.
Tier 3 Escalation and Incident Response. Serve as the final internal escalation point for complex technical issues across cloud, identity, endpoint, and network domains. Lead incident response for security events across the client portfolio. Own root cause analysis, remediation documentation, and post-incident review.
Technical Leadership and Process Improvement. Raise the technical bar for the engineering team, particularly Tier 2 staff developing toward Tier 3 readiness: catch technical problems as they surface, teach better approaches, and push the team toward more scalable ways of working. This leadership happens through project work, standards, and direct technical mentorship.
Technical Project Leadership. Lead complex client projects from design through delivery: owning the technical plan, sequencing workstreams, and pulling in the appropriate resources to execute. Participate in internal and joint client project meetings, make architecture decisions when they arise mid-project, and show up prepared when client calls require technical explanation.
Solution Design and Pre-Sales Partnership. Partner with the Account Manager and CEO on new business and expansion opportunities: listening to what a client needs and designing the technical solution, what should be done, how long it will take, and what it will cost in hours. Sanity-check feasibility and scope risk, and validate the technical accuracy of Statements of Work before they go to the client. Statement of Work authorship and client contracting remain owned by the Account Manager, built from the Cloud & Security Architect's technical plan.
Technical Quality Assurance. Review technical work product across the engineering team. Establish and maintain configuration standards, runbooks, and technical documentation across the stack this role owns. Identify gaps in team capability and recommend training or process changes.
Required Qualifications
Experience: 5+ years in IT infrastructure, cloud, identity, or security engineering. Proven Tier 3 escalation experience in a multi-client MSP or enterprise environment. Demonstrated experience setting architecture standards and holding a team accountable to them. Experience owning the technical plan on complex, multi-workstream projects. Comfortable mentoring less senior engineers without formal management authority.
Technical Expertise: Deep hands-on expertise in Azure infrastructure and architecture, and Entra ID (identity architecture, conditional access, hybrid identity). Deep hands-on expertise in the Microsoft Defender / Microsoft Security suite: candidates should have configured and administered these tools directly, not simply used them as an end user or supported someone else's administration of them.
Demonstrated, ownership-level depth across the domains our security and infrastructure stack covers: endpoint protection and monitoring, RMM, network and firewall infrastructure, and virtual desktop infrastructure. Direct experience with our specific platforms (ThreatLocker, Huntress, NinjaRMM, Fortinet, Nerdio) is preferred; equivalent platforms in any of these categories (for example, CrowdStrike, Sophos, or SonicWall) are also acceptable, provided the depth is real ownership, not support or use.
Preferred Qualifications
Experience independently listening to a client's needs and designing the technical solution behind a proposal or Statement of Work, partnering with sales or account management to translate that design into client-facing scope. Deep technical ownership across our stack is the baseline for this role; demonstrated solution design experience is what moves a candidate toward the top of the posted salary range.
2+ years supporting life sciences, biotech, pharmaceutical, or other regulated industries.
Working knowledge of FDA 21 CFR Part 11 and GxP validation requirements as they apply to cloud environments. Familiarity with SOX IT General Controls (ITGC). Understanding of HIPAA Security Rule technical safeguards. Familiarity with GDPR data protection requirements for clients with EU data exposure. Awareness of CMMC/NIST 800-171 for defense-adjacent clients.
Microsoft Purview: data governance, information protection, and compliance. Microsoft 365 security configuration. Hands-on experience with ThreatLocker, Huntress, NinjaRMM, Fortinet, or Nerdio specifically. Scripting and automation, PowerShell preferred.
Certifications
- Microsoft Certified: Azure Solutions Architect Expert or equivalent.
- Microsoft Certified: Identity and Access Administrator Associate (SC-300) or equivalent.
- Microsoft Certified: Information Protection and Compliance Administrator Associate (SC-400) or equivalent.
- CISSP, CISM, or equivalent security certification.
What Good Looks Like
You know Azure and Entra ID because you built them, not because you watched someone else build them. When a client asks why a conditional access policy is configured a certain way, you have the answer, because you wrote the policy.
You set the architecture standard for the environments you own, cloud and beyond, and you enforce it through documentation and review. When the team builds something, it is built to your standard and there is a record of it.
You've held day-to-day ownership across security and infrastructure platforms before, and you pick up a new vendor's quirks fast because you've already done the harder part, setting a standard and defending it, more than once.
You listen to what a client needs and you already see the shape of the solution: feasible, valuable, and something we can deliver on time and on budget. You partner with the Account Manager to turn that vision into a proposal; they own the contract, you own the plan it's built on.
When a Tier 2 engineer is stuck, you help them work through it and you leave them more capable than you found them, not just the ticket closed.
NIT Culture Fit
We look for people who lead with empathy in every relationship, with clients and with each other, hold themselves accountable without being told to, grow alongside the people they serve, and sweat the details so our clients never have to.
Working Conditions
- San Diego metro area residence required. This is a hybrid role; most work is performed remotely, with occasional client site visits in the San Diego area for specific projects.
- Relocation assistance is not provided; candidates must already reside in the San Diego area, or be willing to relocate at their own expense prior to start.
- Regular participation in project meetings and internal team meetings.
- Occasional evening or weekend work for critical implementations or security incidents.
- Participation in compensated on-call rotation for Tier 3 escalations.
Benefits
- Medical insurance
- Dental and vision insurance
- Paid time off and paid holidays
- 401(k) with company matching
- Professional development budget and certification reimbursement
This job description is not designed to cover or contain a comprehensive listing of activities, duties, or responsibilities that are required of the employee. Duties, responsibilities, and activities may change, or new ones may be assigned at any time with or without notice.
Networkz IT is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, disability, marital status, veteran status, genetic information, or any other characteristic protected by applicable federal, state, or local law.
Pay: $140,000.00 - $175,000.00 per year
Benefits:
- 401(k)
- 401(k) matching
- Dental insurance
- Health insurance
- Paid time off
- Professional development assistance
- Retirement plan
- Vision insurance
Work Location: Hybrid remote in San Diego, CA 92121