Cloud Platform Architect
Listed on 2026-09-02
-
IT/Tech
Cybersecurity, Systems Engineer, Cloud Computing: Infrastructure & Operations, Azure
Join Mizuho as a Cloud Platform Architect, Entra! About the role
We are hiring a Cloud Platform Architect specializing in identity to own cloud identity as a platform capability within our Cloud Platform team.
You will take ownership of our Microsoft Entra estate and everything from the synchronization boundary up: authentication design, access policy, hybrid identity, and the identity patterns the rest of the platform builds on. The platform operates on an enablement model: guardrails enforced in code and self-serve patterns as the default path. Your job is to make secure identity the easiest option, not a queue.
This is a role for someone who wants a domain of their own: full technical ownership of cloud identity in a regulated financial environment, a direct line into platform and architecture decisions, and a roadmap that includes building our external identity capability from the ground up.
What you will own- The Microsoft Entra estate: tenant configuration, Conditional Access, Privileged Identity Management, entitlement management
- Hybrid identity design: synchronization scope, attribute flow, authentication method, and cloud-only account policy
- Identity patterns for platform services: workload identities, service account lifecycle, and non-human identity governance
- Break-glass access design and its integration with the bank's privileged access management platform
- External and business-partner identity architecture (Entra External ) per the cloud roadmap
- Identity blueprints, runbooks, and the documentation that makes the estate operable beyond one person
- Design and operate secure, compliant identity for our Azure estate using Microsoft Entra , aligned to regulatory and internal audit requirements, including access control and MFA provisions
- Design, implement, and iterate Conditional Access policies, Privileged Identity Management, and entitlement management across the tenant
- Publish identity standards as both clear documentation and consumable patterns: reference designs, reusable Terraform modules, and paved-road configurations that make the standard the easiest path to follow
- Enforce identity guardrails through Azure Policy and automation rather than manual approval
- Own hybrid identity and the technical interface with the directory services team:
Entra Connect scope, what synchronizes, what stays cloud-only, and how the boundary is controlled - Design workload identity patterns for Azure services and pipelines: managed identities, workload identity federation, and service principal lifecycle
- Partner with Security, Risk, and Compliance to integrate regulatory controls and evidence collection into identity designs
- Represent cloud identity in audit and regulatory conversations
- 7+ years in identity or infrastructure engineering, including deep hands-on Microsoft Entra at enterprise scale
- Proven experience in regulated financial services (banking, capital markets, or insurance) or a comparably regulated environment
- Strong command of Conditional Access design, Privileged Identity Management, hybrid identity (Entra Connect / cloud sync), and workload identity patterns
- Experience taking ownership of an established identity estate and maturing its configuration, documentation, and controls
- Working knowledge of authentication standards (OIDC, OAuth 2.0, SAML) and modern authentication policy (phishing-resistant MFA, token protection)
- Solid working knowledge of the broader Azure platform: RBAC, Azure Policy, Key Vault, and how identity integrates with core infrastructure services
- Familiarity with control frameworks and regulatory expectations for identity and access management
- Scripting and automation proficiency (Power Shell, Microsoft Graph API);
Infrastructure-as-Code experience preferred
- You build a defensible picture of an environment before changing anything in it
- You know what you chose not to enforce, and why: policy design for you is about blast radius and rollout, not checklists
- You have made an identity control easier to follow instead of easier to bypass
- Your last hands-on work was recent, and you intend to keep it that way
The expected base…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).