About the Role
HSO is seeking an Azure Cloud Architect to lead solution design and drive hands-on delivery of complex Microsoft Azure engagements for our clients. This role owns the architecture from discovery through implementation, spanning landing zones, migrations, identity & security, IaC, and cloud governance, while staying grounded in the platform and working directly alongside engineers and clients. A key part of the role is leading large-scale migrations and deployments, mentoring delivery teams, and building reusable assets.
Responsibilities
- Architect enterprise-scale Azure Landing Zones aligned to CAF and Well-Architected principles: management groups, subscriptions, Azure Policy, RBAC, and platform automation.
- Define compute and PaaS patterns: VM/VMSS sizing, AKS, App Service/Functions, and Container Registry as appropriate.
- Architect Azure Virtual Desktop solutions: host pool design, FSLogix profile strategy on Azure Files or Azure NetApp Files, Scaling Plans, and AVD Insights monitoring.
- Lead design sessions, produce Architecture Decision Records (ADRs), and validate approaches through hands-on proof-of-concept builds.
- Lead cloud migration programs across a range of scenarios: on-premises-to-Azure, cloud-to-cloud (e.g., AWS to Azure), and application modernization and refactoring efforts.
- Drive discovery and assessment: dependency mapping, workload inventory, rehost/replatform/refactor recommendations, and wave planning.
- Manage cutover execution and hypercare: tooling selection, replication monitoring, test migrations, rollback procedures, and stakeholder communication throughout.
- Architect Zero Trust models with Microsoft Entra ID: Conditional Access, PIM role patterns, hybrid identity (Entra Connect/Cloud Sync), and app registration governance.
- Define security blueprints: Azure Policy, Defender for Cloud, Microsoft Sentinel, Defender XDR integrations, and Key Vault design.
- Map controls to compliance frameworks (ISO 27001, SOC 2, HIPAA, PCI-DSS as applicable) and drive Secure Score improvements.
- Build modular IaC frameworks in Terraform and/or Bicep: reusable landing zone modules, policy-as-code, and coding standards for delivery teams.
- Design CI/CD pipelines in Azure DevOps and/or GitHub Actions: environment gates, drift detection, and pre-deployment compliance checks.
- Author automation in PowerShell, Azure CLI, and Python: bootstrap scripts, governance tooling, and operational runbooks.
- Design observability platforms: Log Analytics workspace architecture, Azure Monitor, Workbook/dashboard frameworks, and alerting.
- Architect BCDR solutions with Azure Backup, Site Recovery, and cross-region topologies; validate against RTO/RPO targets.
- Lead FinOps efforts: tagging standards, Cost Management reporting, reservation/Savings Plans strategy, and optimization roadmaps.
- Lead discovery workshops, design sessions, and Well-Architected Reviews; present architecture options with clear trade-offs to technical and business stakeholders.
- Stay hands-on throughout delivery: validate designs through working code and demonstrate patterns directly alongside client teams.
- Mentor delivery engineers through design reviews, pairing on complex problems, and code reviews.
- Design network topologies (hub-and-spoke or Virtual WAN): Azure Firewall, Application Gateway/WAF, Private Link, ExpressRoute/VPN, and DDoS Protection.
- Contribute to pre-sales: solution scoping, proposal authoring, SOW definition, and engagement estimates.
- Manage escalated technical issues while remaining calm, professional, and client-focused.
- Provide technical thought leadership in Modern Workplace, system integration, and automation.
- Communicate complex technical concepts clearly to non-technical stakeholders.
- Work independently while owning deliverables and collaborating effectively with team members.
- Promote the mission and shared values of the company.
Requirements
- 8+ years of hands-on experience architecting and delivering Azure solutions across networking, compute, storage, identity, and security.
- Proven experience leading Azure migration programs—on-premises, cloud-to-cloud, or application modernization—including assessment, wave planning, cutover, and stabilization.
- Proven delivery of enterprise Azure Landing Zones: management group design, Azure Policy, RBAC frameworks, and platform automation.
- Solid IaC experience in Terraform and/or Bicep with Azure DevOps or GitHub Actions CI/CD pipelines.
- Strong Azure networking fundamentals: hub-and-spoke or Virtual WAN, Azure Firewall, Application Gateway/WAF, Private Link, and ExpressRoute/VPN.
- Microsoft Entra ID experience: Conditional Access, PIM, hybrid identity, and Zero Trust concepts.
- Familiarity with Azure security services: Defender for Cloud, Microsoft Sentinel, Key Vault, and compliance frameworks.
- AVD experience: host pool design, FSLogix profiles, Scaling Plans, and monitoring.
- Proficiency in PowerShell and Azure CLI; Python is a plus.
- Strong analytical, problem-solving, and troubleshooting skills.
- Excellent written, verbal, and presentation skills.
- Strong client-facing skills, empathy, and the ability to guide clients through complex technical challenges.
- Ability to work independently, take ownership, and translate goals into actionable outcomes.
- Experience with tenant-to-tenant Microsoft 365 migrations: Exchange Online, SharePoint/OneDrive, Teams, and Entra ID coexistence and cutover.
- Microsoft 365 platform: Intune, Exchange Online, SharePoint/OneDrive, Teams, and Purview.
- Copilot readiness/governance, Copilot Studio development, and Microsoft Foundry experience.
- AKS/Kubernetes and cloud data platform experience (SQL MI, Cosmos DB, Synapse Analytics, or Fabric).
- Pre-sales and consulting delivery: scoping workshops, SOW authoring, and client relationship management.
Skills
- Azure
- Cloud Architecture
- Microsoft Azure
- Landing Zones
- Migrations
- Identity & Security
- Infrastructure as Code (IaC)
- Cloud Governance
- CAF
- Well-Architected Principles
- Management Groups
- Subscriptions
- Azure Policy
- RBAC
- Platform Automation
- Compute Patterns
- PaaS Patterns
- VM/VMSS Sizing
- AKS
- App Service
- Functions
- Container Registry
- Azure Virtual Desktop (AVD)
- Host Pool Design
- FSLogix
- Azure Files
- Azure NetApp Files
- Scaling Plans
- AVD Insights
- Architecture Decision Records (ADRs)
- Proof-of-Concept
- Cloud Migration Programs
- On-premises to Azure Migration
- Cloud-to-Cloud Migration
- Application Modernization
- Refactoring
- Discovery and Assessment
- Dependency Mapping
- Workload Inventory
- Rehost
- Replatform
- Refactor
- Wave Planning
- Cutover Execution
- Hypercare
- Tooling Selection
- Replication Monitoring
- Test Migrations
- Rollback Procedures
- Stakeholder Communication
- Zero Trust
- Microsoft Entra ID
- Conditional Access
- Privileged Identity Management (PIM)
- Hybrid Identity
- Entra Connect
- Cloud Sync
- App Registration Governance
- Security Blueprints
- Defender for Cloud
- Microsoft Sentinel
- Defender XDR
- Key Vault
- Compliance Frameworks
- ISO 27001
- SOC 2
- HIPAA
- PCI-DSS
- Secure Score
- Terraform
- Bicep
- CI/CD
- Azure DevOps
- GitHub Actions
- Environment Gates
- Drift Detection
- Pre-deployment Compliance Checks
- PowerShell
- Azure CLI
- Python
- Bootstrap Scripts
- Governance Tooling
- Operational Runbooks
- Observability Platforms
- Log Analytics
- Azure Monitor
- Workbooks
- Dashboards
- Alerting
- Business Continuity and Disaster Recovery (BCDR)
- Azure Backup
- Azure Site Recovery
- Cross-region Topologies
- RTO/RPO
- FinOps
- Cost Management
- Reservations
- Savings Plans
- Optimization Roadmaps
- Discovery Workshops
- Design Sessions
- Well-Architected Reviews
- Network Topologies
- Hub-and-Spoke
- Virtual WAN
- Azure Firewall
- Application Gateway
- Web Application Firewall (WAF)
- Private Link
- ExpressRoute
- VPN
- DDoS Protection
- Pre-sales
- Solution Scoping
- Proposal Authoring
- Statement of Work (SOW)
- Engagement Estimates
- Intune
- Modern Workplace
- System Integration
- Technical Thought Leadership
- Client Engagement
- Tenant-to-Tenant Microsoft 365 Migrations
- Exchange Online
- SharePoint/OneDrive
- Teams
- Purview
- Copilot
- Copilot Studio
- Microsoft Foundry
- Kubernetes
- AKS
- Cloud Data Platform
- SQL Managed Instance (SQL MI)
- Cosmos DB
- Synapse Analytics
- Fabric
- Client Relationship Management
- Microsoft Certified: Azure Solutions Architect Expert (AZ-305)
- Microsoft Certified: Azure Administrator Associate (AZ-104)
- Microsoft Certified: Azure Security Engineer Associate (AZ-500)
- Microsoft Certified: Cybersecurity Architect Expert (SC-100)
- Microsoft Certified: DevOps Engineer Expert (AZ-400)
- Microsoft Certified: Azure Network Engineer Associate (AZ-700)
- Microsoft 365 Certified: Enterprise Administrator Expert
Experience Level
- 8+ years of hands-on experience
Benefits
- Competitive pay
- Comprehensive benefits package
- Generous paid time off
- Medical coverage
- Dental coverage
- Vision coverage
- Flexible spending accounts
- Health reimbursement account
- 401(k) plan with company match
About the Company
- HSO is an Equal Opportunity Employer.
Equal Opportunity
- HSO is an Equal Opportunity Employer.
