Cloud Architect
Remote in Armenia, & 4 others
Systems Architecture& 2 others
Looking for something else?
Find a vacancy that works for you. Send us your CV to receive a personalized offer.
Find me a jobChoose an option
We are seeking an experienced Cloud Architect to join our team and contribute to the delivery of a Unified Automation Platform. This Internal Developer Platform (IDP) will standardize new-project delivery, centralize access to development resources, and enable software creation through templates and golden paths.
The role focuses on architecting Azure-based infrastructure, identity, and Kubernetes foundations that power self-service capabilities across hybrid environments spanning Azure and on-premises VMware.
Responsibilities
- Architect Infrastructure as Code modules (Terraform/OpenTofu) for Azure App Services, Container Apps, and Function Apps, as well as Azure SQL, Azure Cosmos DB, and Azure Postgres, including the Azure VMware Solution (AVS) private cloud module with managed-identity wiring, private endpoints, and diagnostic settings to Log Analytics
- Define the Azure identity architecture in partnership with the security team, covering Entra ID, Active Directory, and Group Policy Objects, along with M365 groups, SPN/app registrations, and managed identities, ensuring secrets land in OpenBao/Key Vault per platform standards
- Design the Azure Kubernetes Service (AKS) platform, including cluster and node-pool design, baseline add-on stack (ingress, cert-manager, external-dns, monitoring, policy), namespace/tenant onboarding, and an operations dashboard for cluster management
- Collaborate with the Network Architect on core connectivity (VNets, Application Gateway, WAF), Azure Firewall, NSGs, and DNS, NetBox IPAM, and ExpressRoute connectivity, ensuring Azure compute, database, and AKS modules integrate cleanly with the network foundation
- Define the Image Factory architecture for VM and container golden images, covering Linux and Windows/cloudbase-init baselines, CIS hardening, agent injection, and image scanning with Shared Image Gallery publishing/versioning
- Establish foundational Infrastructure as Code Engine standards (remote state/backend, locking, RBAC), including module registry, testing framework, drift detection, policy hooks, and secrets injection consumed by all other automation modules
- Partner with the Backstage Architect to expose Azure provisioning capabilities as Backstage golden-path templates, and with Integration Architects on observability, ITSM/CMDB, and security integrations touching Azure resources
- Provide architectural governance during Implementation, validate production deployments, and support module lifecycle ownership during Adoption
Requirements
- 10+ years of proven Azure solution/enterprise architecture experience, ideally validated through Microsoft Azure partner-level engagements or equivalent certifications
- Deep expertise in Terraform/OpenTofu for Azure infrastructure automation, including module design, state management, and CI/CD-driven deployment pipelines (Azure DevOps)
- Working knowledge of Azure networking constructs (VNets, private endpoints, NSGs) sufficient to integrate compute and data modules with the network foundation owned by the Network Architect
- Hands-on experience architecting Azure Kubernetes Service (AKS) at production scale, including networking, policy, and multi-tenant namespace design
- Background in Azure identity and access architecture (Entra ID, Active Directory, managed identities, RBAC) and secrets integration (Azure Key Vault, dynamic secrets)
- Proficiency in Configuration as Code (Ansible) for VM post-provisioning and golden-image pipelines
- Excellent command of English (B2+ level), both written and spoken, with a strong emphasis on technical communication skills
Nice to have
- Experience with Azure VMware Solution (AVS) private cloud provisioning
- Familiarity with certificate lifecycle management platforms (e.g., Venafi) and their integration with Azure Key Vault
- Skills in integrating Azure infrastructure automation with a Backstage-based (or comparable) developer portal
- Knowledge of policy-as-code engines (OPA/Conftest, Azure Policy) for automated compliance enforcement
- Prior experience in large-scale, multi-region Azure landing-zone or platform engineering
