Azure Cloud Architect
India
Full Time
Experienced
Azure Cloud Architect
About Zappsec
Zappsec is a global digital engineering partner helping high-growth enterprises modernize their cloud, network, and security infrastructure. We combine deep technology expertise, automation-first methodologies, and AI-driven innovation to deliver secure, scalable, and intelligent modernization outcomes.
Role Overview
The Azure Cloud Architect is responsible for designing and implementing enterprise Azure networking, identity, and security architectures for Zappsec clients. You will design scalable hub-and-spoke and Virtual WAN networks, build secure identity foundations on Microsoft Entra ID, enforce governance guardrails, and integrate Azure-native security services across client environments.
Key Responsibilities
1. Azure Networking and Hybrid Connectivity
Required:
About Zappsec
Zappsec is a global digital engineering partner helping high-growth enterprises modernize their cloud, network, and security infrastructure. We combine deep technology expertise, automation-first methodologies, and AI-driven innovation to deliver secure, scalable, and intelligent modernization outcomes.
Role Overview
The Azure Cloud Architect is responsible for designing and implementing enterprise Azure networking, identity, and security architectures for Zappsec clients. You will design scalable hub-and-spoke and Virtual WAN networks, build secure identity foundations on Microsoft Entra ID, enforce governance guardrails, and integrate Azure-native security services across client environments.
Key Responsibilities
1. Azure Networking and Hybrid Connectivity
- Design and deploy enterprise network topologies across Azure, including:
- Virtual network design, multi-region layouts, subnet tiering, and outbound connectivity strategies.
- Hub-and-spoke architectures or Azure Virtual WAN for global connectivity.
- Hybrid connectivity through VPN Gateway and ExpressRoute.
- Azure Firewall, network security groups, user-defined routing, Private Link, private endpoints, and Azure DNS Private Resolver.
- Design Entra ID tenant architecture, including administrative units, role assignments, and separation of privileged access.
- Implement Conditional Access policies, multifactor authentication, and passwordless authentication strategies.
- Design hybrid identity using Entra Connect or Entra Cloud Sync, including synchronization and authentication method decisions.
- Configure Privileged Identity Management, access reviews, and entitlement management for identity governance.
- Integrate enterprise applications with single sign-on using SAML and OpenID Connect, and design B2B collaboration and external identity patterns.
- Apply managed identities and workload identity federation to remove stored credentials from workloads.
- Implement secure-by-default patterns, including:
- Least-privilege RBAC models and custom role design.
- Azure Key Vault, encryption at rest and in transit, and secrets management.
- Web Application Firewall on Azure Front Door or Application Gateway, and Azure DDoS Protection.
- Guardrails enforced through Azure Policy, such as allowed regions, blocked public network access, and required diagnostic settings.
- Integrate Defender for Cloud and Microsoft Sentinel for posture management and threat detection.
- Produce architecture diagrams, design decision records, deployment runbooks, and handover documentation.
- Build reusable artifacts for Zappsec's delivery and pre-sales teams.
- 10+ years of hands-on experience in cloud engineering, networking, and security, with a strong focus on Microsoft Azure.
- Strong understanding of Azure Policy, RBAC, Defender for Cloud, and centralized logging.
- Deep knowledge of Microsoft Entra ID, including Conditional Access, PIM, hybrid identity, identity governance, and application integration.
- Deep knowledge of Azure virtual networking, hub-and-spoke and Virtual WAN designs, Azure Firewall, VPN Gateway, ExpressRoute, private endpoints, and multi-region and hybrid cloud patterns.
- Strong grounding in Zero Trust, least privilege, and detective and preventive guardrails.
- Strong ownership mindset and ability to operate independently.
Required:
- Microsoft Certified: Azure Solutions Architect Expert (AZ-305)
- Microsoft Certified: Azure Security Engineer Associate (AZ-500)
- Microsoft Certified: Azure Network Engineer Associate (AZ-700)
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)
- Microsoft Certified: Cybersecurity Architect Expert (SC-100)
Apply for this position
Required*