The Cloud Architect is accountable for establishing and evolving core cloud platform foundations on Microsoft Azure. This role focuses on building secure, scalable, and repeatable cloud capabilities – so product and data teams can move fast without breaking things. This is a hands-on architecture role with clear ownership of cloud landing zones, identity and access management, secure connectivity, observability, and shared data platform resources.
Main Duties and Responsibilities
Cloud Platform Foundations
- Design, implement, and maintain an Azure application landing zone, including subscription strategy, network topology, security baselines, policies, and cost controls.
- Define and operate cloud architecture guardrails and “golden paths” that enable team autonomy while maintaining platform consistency.
- Own and evolve reference architectures for cloud-native workloads and shared platform services.
Secure Connectivity & Networking
- Design and implement secure network connectivity patterns between Azure and external environments, including Mendix Cloud, private datacenters, and third-party service providers.
- Define standards for network segmentation, private connectivity, ingress/egress control, and traffic inspection.
- Ensure connectivity solutions are resilient, observable, and aligned with security and regulatory requirements.
- Partner with vendors and internal teams to establish clear ownership and operational models for cross-boundary connectivity.
Identity, Security, and Access
- Establish platform-level identity and access management as a shared service, including Azure Entra External ID and brokering with external identity providers.
- Define access models, role-based access control, and trust boundaries across internal and external workloads.
- Work closely with security and governance stakeholders to embed security controls into platform foundations.
Observability & Operational Excellence
- Define and implement platform-wide observability standards (logging, metrics, tracing, alerting) across internal and connected external services.
- Embed observability into CI/CD pipelines and engineering workflows to support incident response and operational learning.
- Collaborate with DevOps and platform teams to enable resilience, automated recovery, and operational readiness.
Data Platform Enablement
- Co-own the cloud foundations for the company’s data platform, including secure data services, access patterns, and operational guardrails.
- Support high-throughput, reliable, and secure data exchange between internal platforms and external systems.
Architecture Leadership
- Conduct architecture reviews focused on enabling delivery, managing risk, and making clear, timely decisions.
- Produce clear, pragmatic documentation that teams actually use.
- Mentor engineers through hands-on collaboration and by delivering concrete reference implementations.
- Stay current on cloud and platform technologies, evaluating new capabilities where they create real operational or business value.
Skills and Qualifications
- 5+ years’ experience in cloud architecture or senior cloud engineering roles.
- Deep, hands-on expertise with Microsoft Azure (networking, identity, security, IaaS, PaaS).
- Proven experience designing and implementing cloud landing zones and secure network architectures.
- Practical experience with hybrid and multi-environment connectivity (e.g. cloud-to-cloud, cloud-to-datacenter, third-party integrations).
- Strong experience with cloud identity and access management, including federation with external identity providers.
- Practical experience implementing platform-wide observability.
- Solid understanding of DevOps practices, CI/CD, and infrastructure as code.
- Experience with container platforms (e.g. Kubernetes / AKS) and cloud-native architecture patterns.
- Ability to balance architectural rigor with delivery pragmatism.
- Strong communication and stakeholder-management skills.