Skip To Main Content
backBack to Search

Cloud Architect

Remote in Türkiye
Systems Architecture& 2 others
Looking for something else?

Find a vacancy that works for you. Send us your CV to receive a personalized offer.

Find me a job

We are seeking a Cloud Architect to design and govern our Azure platform architecture, driving the automation, security, and scalability of infrastructure across compute, identity, networking, and Kubernetes environments. This role partners closely with security, network, and platform engineering teams to deliver a robust, self-service cloud foundation.

Responsibilities
  • Architect Infrastructure as Code modules (Terraform/OpenTofu) for Azure App Services, Container Apps, Function Apps, Azure SQL, Azure Cosmos DB, Azure Postgres, and the Azure VMware Solution (AVS) private cloud module, including managed-identity wiring, private endpoints, and diagnostic settings to Log Analytics
  • Define the Azure identity architecture in partnership with the security team, including Entra ID, Active Directory, Group Policy Objects, M365 groups, SPN/app registrations, and managed identities, to ensure secrets land in OpenBao/Key Vault per platform standards
  • Architect the Azure Kubernetes Service (AKS) platform, including cluster and node-pool design, baseline add-on stack (ingress, cert-manager, external-dns, monitoring, policy), namespace/tenant onboarding, and an operations dashboard for cluster management
  • Collaborate with the Network Architect on core connectivity (VNets, Application Gateway, WAF, Azure Firewall, NSGs), DNS, NetBox IPAM, and ExpressRoute connectivity, to ensure Azure compute, database, and AKS modules integrate cleanly with the network foundation
  • Define the Image Factory architecture for VM and container golden images (Linux and Windows/cloudbase-init baselines, CIS hardening, agent injection, image scanning, Shared Image Gallery publishing/versioning)
  • Establish the foundational Infrastructure as Code Engine standards (remote state/backend, locking, RBAC, module registry, testing framework, drift detection, policy hooks, secrets injection) consumed by all other automation modules
  • Collaborate with the Backstage Architect to expose Azure provisioning capabilities as Backstage golden-path templates, and with the Integration Architects on observability, ITSM/CMDB, and security integrations touching Azure resources
  • Provide architectural governance during Implementation, validate production deployments, and support module lifecycle ownership during Adoption
Requirements
  • 5+ years of proven Azure solution/enterprise architecture experience, ideally validated through Microsoft Azure partner-level engagements or equivalent certification
  • Deep expertise in Terraform/OpenTofu, Azure DevOps, and CI/CD-driven deployment pipelines for Azure infrastructure automation, including module design and state management
  • Working knowledge of Azure networking constructs (VNets, private endpoints, NSGs) sufficient to integrate compute and data modules with the network foundation owned by the Network Architect
  • Hands-on experience architecting Azure Kubernetes Service (AKS) at production scale, including networking, policy, and multi-tenant namespace design
  • Experience with Azure identity and access architecture (Entra ID, Active Directory, managed identities, RBAC) and secrets integration (Azure Key Vault, dynamic secrets)
  • Experience with Configuration as Code (Ansible) for VM post-provisioning and golden-image pipelines
  • English proficiency at B2 level or higher
Nice to have
  • Experience with Azure VMware Solution (AVS) private cloud provisioning
  • Familiarity with certificate lifecycle management platforms (e.g., Venafi) and their integration with Azure Key Vault
  • Experience integrating Azure infrastructure automation with a Backstage-based (or comparable) developer portal
  • Knowledge of policy-as-code engines (OPA/Conftest, Azure Policy) for automated compliance enforcement
  • Prior experience in large-scale, multi-region Azure landing-zone or platform engineering