Job Summary
We are looking for a Cloud Solution Architect to design, implement, and support secure, scalable, highly available, and reliable cloud solutions on Microsoft Azure.
The role will be responsible for translating business and technical requirements into robust Azure solution architectures, defining cloud environments and deployment models, and ensuring effective integration between infrastructure, applications, DevOps, security, and operational teams.
The ideal candidate should have strong hands-on experience across Azure infrastructure and platform services, cloud networking, security, CI/CD, Infrastructure as Code, monitoring, disaster recovery, and modern application deployment patterns.
Key Responsibilities
1. Azure Solution Architecture & Design
- Design end-to-end cloud solutions using Microsoft Azure services based on business, application, security, performance, and scalability requirements.
- Define appropriate Azure architecture patterns for enterprise applications and cloud-native workloads.
- Design cloud environments across development, testing, staging, and production.
- Define environment topology, resource organization, subscriptions, resource groups, networking, security boundaries, and deployment models.
- Translate functional and non-functional requirements into scalable, secure, and cost-effective Azure architectures.
- Evaluate existing architectures and recommend improvements related to performance, availability, scalability, security, and operational efficiency.
- Define architectural standards, patterns, and best practices for Azure implementations.
- Provide technical guidance throughout solution implementation and deployment.
2. Azure Infrastructure & Platform Services
- Design and support Azure infrastructure components including:
- Azure Virtual Networks (VNet)
- Subnets and Network Security Groups
- Private Endpoints and Private DNS
- Azure App Service
- Azure Kubernetes Service (AKS)
- Azure Front Door
- Azure Web Application Firewall (WAF)
- Azure API Management
- Azure Key Vault
- Microsoft Entra ID
- Design secure connectivity between Azure services, applications, on-premises environments, and external systems.
- Define appropriate compute, networking, storage, and platform services based on workload requirements.
3. Networking, Edge & Application Delivery
- Design and implement secure application delivery architectures using Azure Front Door, CDN, WAF, and edge services.
- Define routing, load balancing, traffic management, SSL/TLS, and application protection strategies.
- Design VNet architectures and private connectivity patterns for secure communication between Azure resources.
- Work with networking and security teams to resolve connectivity, routing, firewall, and access-related issues.
- Define appropriate patterns for public and private application exposure.
- Evaluate and support edge deployment and CDN architectures, including Vercel/edge deployment patterns where applicable.
4. Kubernetes & Containerized Workloads
- Design and support containerized application architectures using Azure Kubernetes Service (AKS).
- Define AKS environments, networking, ingress, security, scaling, availability, and operational patterns.
- Collaborate with development and DevOps teams on container deployment strategies.
- Support troubleshooting of application, networking, scaling, and deployment issues within AKS environments.
- Define appropriate deployment patterns for microservices and cloud-native applications.
5. API Management & Integration
- Design and support API architectures using Azure API Management.
- Define API security, authentication, authorization, routing, policies, throttling, and lifecycle management.
- Work with development teams to ensure APIs are securely exposed and integrated with enterprise applications.
- Ensure API architectures meet availability, performance, security, and operational requirements.
6. Identity & Security
- Design secure identity and access management solutions using Microsoft Entra ID.
- Define authentication and authorization patterns for applications and Azure resources.
- Design secure access to cloud resources using appropriate identity, RBAC, managed identities, and least-privilege principles.
- Use Azure Key Vault to securely manage secrets, certificates, and encryption keys.
- Collaborate closely with security teams to ensure cloud solutions meet security and compliance requirements.
- Support security assessments, remediation activities, and implementation of required security controls.
- Ensure architectures follow cloud security best practices and organizational policies.
7. Monitoring, Observability & Operations
- Design comprehensive monitoring and observability solutions using:
- Azure Monitor
- Application Insights
- Log Analytics
- Define monitoring, logging, alerting, dashboarding, and operational visibility requirements.
- Establish appropriate application and infrastructure health monitoring.
- Support incident investigation and root-cause analysis using Azure monitoring and logging capabilities.
- Define operational KPIs, alerts, and reliability mechanisms.
- Ensure solutions are designed for effective production support and operational handover.
8. Backup, Disaster Recovery & Business Continuity
- Design backup and disaster recovery strategies using Azure Backup and Azure Site Recovery.
- Define Recovery Time Objective (RTO) and Recovery Point Objective (RPO) requirements.
- Design high-availability and disaster recovery architectures for critical workloads.
- Support disaster recovery testing and validation.
- Identify single points of failure and recommend appropriate resilience improvements.
- Ensure production environments have appropriate backup, recovery, and business continuity mechanisms.
9. DevOps & CI/CD
- Work closely with DevOps teams to define and implement effective CI/CD architectures.
- Support Azure DevOps-based pipelines for application and infrastructure deployment.
- Define deployment strategies such as:
- Blue/Green deployment
- Canary deployment
- Rolling deployment
- Automated environment promotion
- Ensure deployments are repeatable, controlled, secure, and reliable.
- Collaborate with development teams to integrate application delivery with cloud infrastructure.
- Troubleshoot deployment and pipeline issues and provide architectural guidance.
10. Infrastructure as Code (IaC)
- Design and support Infrastructure as Code practices for Azure environments.
- Define reusable and maintainable infrastructure deployment patterns.
- Work with technologies such as Terraform, Bicep, ARM templates, or equivalent IaC tools.
- Ensure infrastructure changes are version-controlled, reviewable, and automated where possible.
- Support DevOps teams in integrating IaC with CI/CD pipelines.
- Promote consistent infrastructure configuration across environments.
11. Reliability & Cloud Operations
- Define operational patterns to ensure Azure solutions are reliable, scalable, maintainable, and supportable.
- Participate in technical troubleshooting and production issue resolution.
- Conduct root-cause analysis for complex cloud infrastructure and application issues.
- Identify opportunities to improve availability, performance, scalability, and operational efficiency.
- Support capacity planning and scalability assessments.
- Ensure solutions are designed with operational support and long-term maintainability in mind.
12. Documentation & Technical Governance
- Create and maintain technical architecture documentation, diagrams, design documents, deployment guides, and operational runbooks.
- Document environment architecture, dependencies, configurations, security controls, and deployment procedures.
- Define technical standards and reusable architecture patterns.
- Ensure technical documentation is maintained throughout the solution lifecycle.
- Provide clear technical handover documentation to DevOps, infrastructure, security, and support teams.
13. Stakeholder & Delivery Collaboration
- Work closely with:
- Solution Architects
- Application/Software Development teams
- DevOps teams
- Infrastructure teams
- Cybersecurity teams
- Network teams
- Project/Program Managers
- Operations and Support teams
- Participate in technical workshops and architecture discussions.
- Provide technical recommendations and explain complex cloud concepts to technical and non-technical stakeholders.
- Take ownership of assigned technical deliverables and ensure they are completed within agreed timelines.
- Proactively identify technical risks, dependencies, and implementation challenges.
Required Experience
- 7+ years of experience in cloud, infrastructure, solution architecture, DevOps, or a related technical field.
- Strong experience designing and implementing solutions on Microsoft Azure.
- Proven experience designing enterprise-grade cloud environments.
- Strong understanding of Azure networking, security, identity, and infrastructure services.
- Practical experience with CI/CD and Infrastructure as Code.
- Experience working with DevOps and cybersecurity teams.
- Experience with production environments and operational support.
- Experience designing high-availability, backup, and disaster recovery solutions.
- Experience working on complex projects involving multiple technical teams and stakeholders.
- Strong troubleshooting and problem-solving capabilities.
- Experience creating technical architecture and operational documentation.
Preferred Qualifications
- Microsoft Azure certifications such as:
- Azure Solutions Architect Expert
- Azure Administrator Associate
- Azure DevOps Engineer Expert
- Azure Security Engineer Associate
- Experience with Kubernetes and container platforms.
- Experience with Terraform.
- Experience with Vercel or other modern edge platforms.
- Experience with enterprise API management.
- Experience with cloud migration and modernization projects.
- Experience working in regulated or security-sensitive environments.
- Experience with Agile/DevOps delivery methodologies.