More jobs:
Azure Cloud Architect
Job in
Southlake, Tarrant County, Texas, 76092, USA
Listed on 2026-09-16
Listing for:
VeriDex Solutions
Full Time
position Listed on 2026-09-16
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Azure, Cloud Computing: Infrastructure & Operations
Job Description & How to Apply Below
You will serve as the lead Azure Cloud Architect responsible for designing and implementing a Zero Trust–aligned security architecture across a multi‑subscription Azure enterprise environment. This role focuses on securing AI Foundry
, Azure Kubernetes Service (AKS),
Microsoft Fabric
, and the broader Azure tenant using industry frameworks including NIST 800‑53
, NIST CSF
, ISO 27001
, SOC 2, and Insurance Regulator (NAIC Model 668 / NYDFS 500) requirements.
You will define the security blueprint, enforce governance, design identity boundaries, implement policy‑driven controls, and ensure all AI and cloud workloads meet enterprise and regulatory standards.
Key Responsibilities 1. Azure Tenant & Zero Trust Architecture- Architect and implement a Zero Trust security model across identity, network, data, and workload layers.
- Design Azure management group hierarchy
, subscription strategy, and landing zones aligned to NIST/ISO controls. - Implement Conditional Access
, PIM
, Identity Governance
, and segmented identity boundaries for developers, admins, and workloads. - Lead the rollout of Azure Policy
, policy initiatives
, RBAC
, and custom role definitions for least‑privilege enforcement. - Establish secure-by-default patterns for all cloud services.
- Architect secure environments for AI Foundry
, including: - Model training and serving isolation, Data access governance, Key Vault integration
- Private endpoints and network isolation
- Implement AI safety, lineage, and audit controls aligned with regulatory expectations.
- Define secure patterns for prompt flows, agents, vector stores, and model endpoints
.
- Design hardened AKS clusters with:
- Azure CNI
, network policies
, pod identity
, OPA/Gatekeeper
, secretless workloads - Workload identity with Entra
- Implement Zero Trust for microservices
, including: mTLS, API gateway patterns,Service mesh (Istio/Linkerd) optional - Define secure CI/CD patterns using OIDC
, Git Hub Actions, and policy‑driven deployments.
- Architect secure Fabric work spaces, pipelines, and lake houses.
- Implement:
- Managed VNETs, Private endpoints
- Ensure Fabric aligns with data residency
, retention
, and insurance regulatory requirements.
- Implement enterprise‑wide Key Vault
, Managed HSM
, and secret rotation patterns. - Data at rest, Data in transit, Model artifacts, AKS secrets and Fabric data
- Build automated detection and response patterns for:
- ISO 27001, SOC 2
- Produce architecture documentation, control evidence, and audit‑ready artifacts.
- Partner with risk, compliance, and internal audit teams.
- 15+ years in cloud architecture with deep expertise in Azure
. - Proven experience implementing Zero Trust in enterprise environments.
- Hands‑on experience with:
- AKS (production-grade)
- Microsoft Fabric
- AI Foundry or Azure ML
- Strong understanding of network segmentation
, identity governance
, and data protection
. - Experience with Bicep
, Terraform
, or ARM templates. - Strong knowledge of NIST/ISO frameworks and regulatory controls.
- SC‑100 (Cybersecurity Architect)
- Experience in insurance
, financial services
, or other regulated industries. - Experience with Git Hub OIDC
, Dev Sec Ops , and policy‑as‑code.
- Azure tenant fully aligned to Zero Trust principles.
- AI Foundry, AKS, and Fabric workloads fully secured and compliant.
- Automated governance and policy enforcement across all environments.
- Audit‑ready documentation and evidence for regulators.
- Secure, scalable patterns adopted across engineering teams.
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×