Senior Azure Cloud Architect

Boston, MA, US • Posted 12 hours ago • Updated 12 hours ago
Contract Independent
Contract W2
24 Months
No Travel Required
On-site
Depends on Experience
Fitment

Dice Job Match Score™

📋 Comparing job requirements...

Job Details

Skills

  • ARM
  • Access Control
  • Cloud Computing
  • Active Directory
  • Analytics
  • Command-line Interface
  • Border Gateway Protocol
  • Cloud Security
  • DirectShow
  • Computer Networking
  • DNS
  • Identity Management
  • FOCUS
  • DS
  • Data Link Layer
  • Dragon NaturallySpeaking
  • Firewall
  • Microsoft
  • Fortinet
  • High Availability
  • Multi-factor Authentication
  • Leadership
  • Management
  • Network Security
  • Microsoft Azure
  • Migration
  • Routing
  • Network
  • SAP SRM
  • OAuth
  • PIM
  • Supplier Relationship Management
  • Palo Alto
  • VMware Site Recovery Manager
  • RBAC
  • Virtualization
  • SAML
  • Storage
  • Terraform
  • WAN
  • VMware
  • Windows PowerShell

Summary

Role Overview

We are looking for a Senior Azure Architect to lead the strategy, design, and execution of our enterprise cloud foundation. In this role, you will be responsible for building secure, enterprise-grade Azure Landing Zones, configuring hybrid identity and access management (Active Directory / Microsoft Entra ID), and executing large-scale workload migrations—with a strong focus on Azure VMware Solution (AVS / VMC on Azure).

You will bridge the gap between legacy VMware data center architecture and modern native cloud capabilities while ensuring rigorous security postures and seamless network routing.


Responsibilities

1. Azure Landing Zone & Architecture

·         Architect and operationalize enterprise-grade Azure Landing Zones aligning with Microsoft’s Cloud Adoption Framework (CAF).

·         Establish management groups, subscription topologies, resource naming/tagging standards, and operational governance.

·         Implement Infrastructure as Code (IaC) using Terraform or Bicep/ARM to automate subscription vends and policy enforcement.

2. VMware Migration (AVS / VMC on Azure)

·         Lead end-to-end design, sizing, deployment, and migration of legacy on-premises VMware environments to Azure VMware Solution (AVS).

·         Plan and execute migration strategies using VMware HCX (bulk migration, RAV, cold/warm vMotion, and L2 network extensions).

·         Configure VMware NSX-T network virtualizations, vSAN storage profiles, vCenter integrations, and host lifecycle configurations within Azure.

3. Hybrid Networking & Security

·         Design secure, high-availability hybrid networks using ExpressRoute, Azure Virtual WAN (vWAN), Hub-and-Spoke topologies, and Azure Route Server.

·         Integrate Network Virtual Appliances (NVAs), Palo Alto / Fortinet firewalls, Azure Firewall, and Network Security Groups (NSGs).

·         Enforce Zero-Trust architecture across cloud environments, including micro-segmentation with NSX-T and Azure security boundaries.

4. Identity & Access Governance (AD / Entra ID)

·         Design and maintain hybrid identity solutions integrating on-premises Active Directory Domain Services (AD DS) with Microsoft Entra ID (formerly Azure AD).

·         Implement Role-Based Access Control (RBAC), Entra ID Privileged Identity Management (PIM), Conditional Access, Managed Identities, and Azure Key Vault.

·         Ensure proper DNS routing and resolution between on-premises AD, Azure Private Endpoints, and AVS SDDC infrastructure.



Required Qualifications & Technical Skills

·         Azure Expertise: 4+ years of hands-on design and architectural leadership in Microsoft Azure (Virtual Networks, Subscriptions, Management Groups, Policy, Log Analytics).

·         VMware / AVS Mastery: Direct experience designing or migrating to Azure VMware Solution (AVS) or equivalent hybrid VMware platforms (e.g., VMC).

·         Migration Tooling: Hands-on mastery of VMware HCX, Azure Migrate, or Site Recovery Manager (SRM).

·         Networking & Virtualization: Deep knowledge of VMware NSX-T (firewalling, segment creation, BGP routing) and Azure networking (ExpressRoute Global Reach, UDRs, vWAN).

·         Identity & Security: Strong Active Directory, Microsoft Entra ID (SAML, OAuth, Conditional Access, MFA, RBAC), and cloud security baseline management.

·         Automation: Proficiency in IaC with Terraform, Bicep, PowerShell, or Azure CLI.

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 91163556
  • Position Id: 9048308
  • Posted 12 hours ago
Contact the job poster
JK

John Kumar

Recruiter @ kjohn@samrusystems.com
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Remote or North Carolina

Today

Full-time

USD 140,000.00 - 170,000.00 per year

No location provided

Today

Full-time

USD 86,100.00 - 169,800.00 per year

Remote

3d ago

Easy Apply

Contract, Third Party

Depends on Experience

No location provided

Today

Easy Apply

Full-time, Part-time, Third Party, Contract

Search all similar jobs