Azure Cloud Architect at HSO Group B.V. | New York, United States | Rezi

Azure Cloud Architect at HSO Group B.V.

Azure Cloud Architect

HSO Group B.V. · New York, United States

Today

Azure Cloud Architect

HSO Group B.V. · New York, United States

2 hours ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

HSO is seeking an Azure Cloud Architect to lead solution design and drive hands-on delivery of complex Microsoft Azure engagements for our clients. This role owns the architecture from discovery through implementation, spanning landing zones, migrations, identity & security, IaC, and cloud governance, while staying grounded in the platform and working directly alongside engineers and clients. A key part of the role is leading large-scale migrations and deployments, mentoring delivery teams, and building reusable assets.

Responsibilities

  • Architect enterprise-scale Azure Landing Zones aligned to CAF and Well-Architected principles: management groups, subscriptions, Azure Policy, RBAC, and platform automation.
  • Define compute and PaaS patterns: VM/VMSS sizing, AKS, App Service/Functions, and Container Registry as appropriate.
  • Architect Azure Virtual Desktop solutions: host pool design, FSLogix profile strategy on Azure Files or Azure NetApp Files, Scaling Plans, and AVD Insights monitoring.
  • Lead design sessions, produce Architecture Decision Records (ADRs), and validate approaches through hands-on proof-of-concept builds.
  • Lead cloud migration programs across a range of scenarios: on-premises-to-Azure, cloud-to-cloud (e.g., AWS to Azure), and application modernization and refactoring efforts.
  • Drive discovery and assessment: dependency mapping, workload inventory, rehost/replatform/refactor recommendations, and wave planning.
  • Manage cutover execution and hypercare: tooling selection, replication monitoring, test migrations, rollback procedures, and stakeholder communication throughout.
  • Architect Zero Trust models with Microsoft Entra ID: Conditional Access, PIM role patterns, hybrid identity (Entra Connect/Cloud Sync), and app registration governance.
  • Define security blueprints: Azure Policy, Defender for Cloud, Microsoft Sentinel, Defender XDR integrations, and Key Vault design.
  • Map controls to compliance frameworks (ISO 27001, SOC 2, HIPAA, PCI-DSS as applicable) and drive Secure Score improvements.
  • Build modular IaC frameworks in Terraform and/or Bicep: reusable landing zone modules, policy-as-code, and coding standards for delivery teams.
  • Design CI/CD pipelines in Azure DevOps and/or GitHub Actions: environment gates, drift detection, and pre-deployment compliance checks.
  • Author automation in PowerShell, Azure CLI, and Python: bootstrap scripts, governance tooling, and operational runbooks.
  • Design observability platforms: Log Analytics workspace architecture, Azure Monitor, Workbook/dashboard frameworks, and alerting.
  • Architect BCDR solutions with Azure Backup, Site Recovery, and cross-region topologies; validate against RTO/RPO targets.
  • Lead FinOps efforts: tagging standards, Cost Management reporting, reservation/Savings Plans strategy, and optimization roadmaps.
  • Lead discovery workshops, design sessions, and Well-Architected Reviews; present architecture options with clear trade-offs to technical and business stakeholders.
  • Stay hands-on throughout delivery: validate designs through working code and demonstrate patterns directly alongside client teams.
  • Mentor delivery engineers through design reviews, pairing on complex problems, and code reviews.
  • Design network topologies (hub-and-spoke or Virtual WAN): Azure Firewall, Application Gateway/WAF, Private Link, ExpressRoute/VPN, and DDoS Protection.
  • Contribute to pre-sales: solution scoping, proposal authoring, SOW definition, and engagement estimates.
  • Manage escalated technical issues while remaining calm, professional, and client-focused.
  • Provide technical thought leadership in Modern Workplace, system integration, and automation.
  • Communicate complex technical concepts clearly to non-technical stakeholders.
  • Work independently while owning deliverables and collaborating effectively with team members.
  • Promote the mission and shared values of the company.

Requirements

  • 8+ years of hands-on experience architecting and delivering Azure solutions across networking, compute, storage, identity, and security.
  • Proven experience leading Azure migration programs—on-premises, cloud-to-cloud, or application modernization—including assessment, wave planning, cutover, and stabilization.
  • Proven delivery of enterprise Azure Landing Zones: management group design, Azure Policy, RBAC frameworks, and platform automation.
  • Solid IaC experience in Terraform and/or Bicep with Azure DevOps or GitHub Actions CI/CD pipelines.
  • Strong Azure networking fundamentals: hub-and-spoke or Virtual WAN, Azure Firewall, Application Gateway/WAF, Private Link, and ExpressRoute/VPN.
  • Microsoft Entra ID experience: Conditional Access, PIM, hybrid identity, and Zero Trust concepts.
  • Familiarity with Azure security services: Defender for Cloud, Microsoft Sentinel, Key Vault, and compliance frameworks.
  • AVD experience: host pool design, FSLogix profiles, Scaling Plans, and monitoring.
  • Proficiency in PowerShell and Azure CLI; Python is a plus.
  • Strong analytical, problem-solving, and troubleshooting skills.
  • Excellent written, verbal, and presentation skills.
  • Strong client-facing skills, empathy, and the ability to guide clients through complex technical challenges.
  • Ability to work independently, take ownership, and translate goals into actionable outcomes.
  • Experience with tenant-to-tenant Microsoft 365 migrations: Exchange Online, SharePoint/OneDrive, Teams, and Entra ID coexistence and cutover.
  • Microsoft 365 platform: Intune, Exchange Online, SharePoint/OneDrive, Teams, and Purview.
  • Copilot readiness/governance, Copilot Studio development, and Microsoft Foundry experience.
  • AKS/Kubernetes and cloud data platform experience (SQL MI, Cosmos DB, Synapse Analytics, or Fabric).
  • Pre-sales and consulting delivery: scoping workshops, SOW authoring, and client relationship management.

Skills

  • Azure
  • Cloud Architecture
  • Microsoft Azure
  • Landing Zones
  • Migrations
  • Identity & Security
  • Infrastructure as Code (IaC)
  • Cloud Governance
  • CAF
  • Well-Architected Principles
  • Management Groups
  • Subscriptions
  • Azure Policy
  • RBAC
  • Platform Automation
  • Compute Patterns
  • PaaS Patterns
  • VM/VMSS Sizing
  • AKS
  • App Service
  • Functions
  • Container Registry
  • Azure Virtual Desktop (AVD)
  • Host Pool Design
  • FSLogix
  • Azure Files
  • Azure NetApp Files
  • Scaling Plans
  • AVD Insights
  • Architecture Decision Records (ADRs)
  • Proof-of-Concept
  • Cloud Migration Programs
  • On-premises to Azure Migration
  • Cloud-to-Cloud Migration
  • Application Modernization
  • Refactoring
  • Discovery and Assessment
  • Dependency Mapping
  • Workload Inventory
  • Rehost
  • Replatform
  • Refactor
  • Wave Planning
  • Cutover Execution
  • Hypercare
  • Tooling Selection
  • Replication Monitoring
  • Test Migrations
  • Rollback Procedures
  • Stakeholder Communication
  • Zero Trust
  • Microsoft Entra ID
  • Conditional Access
  • Privileged Identity Management (PIM)
  • Hybrid Identity
  • Entra Connect
  • Cloud Sync
  • App Registration Governance
  • Security Blueprints
  • Defender for Cloud
  • Microsoft Sentinel
  • Defender XDR
  • Key Vault
  • Compliance Frameworks
  • ISO 27001
  • SOC 2
  • HIPAA
  • PCI-DSS
  • Secure Score
  • Terraform
  • Bicep
  • CI/CD
  • Azure DevOps
  • GitHub Actions
  • Environment Gates
  • Drift Detection
  • Pre-deployment Compliance Checks
  • PowerShell
  • Azure CLI
  • Python
  • Bootstrap Scripts
  • Governance Tooling
  • Operational Runbooks
  • Observability Platforms
  • Log Analytics
  • Azure Monitor
  • Workbooks
  • Dashboards
  • Alerting
  • Business Continuity and Disaster Recovery (BCDR)
  • Azure Backup
  • Azure Site Recovery
  • Cross-region Topologies
  • RTO/RPO
  • FinOps
  • Cost Management
  • Reservations
  • Savings Plans
  • Optimization Roadmaps
  • Discovery Workshops
  • Design Sessions
  • Well-Architected Reviews
  • Network Topologies
  • Hub-and-Spoke
  • Virtual WAN
  • Azure Firewall
  • Application Gateway
  • Web Application Firewall (WAF)
  • Private Link
  • ExpressRoute
  • VPN
  • DDoS Protection
  • Pre-sales
  • Solution Scoping
  • Proposal Authoring
  • Statement of Work (SOW)
  • Engagement Estimates
  • Intune
  • Modern Workplace
  • System Integration
  • Technical Thought Leadership
  • Client Engagement
  • Tenant-to-Tenant Microsoft 365 Migrations
  • Exchange Online
  • SharePoint/OneDrive
  • Teams
  • Purview
  • Copilot
  • Copilot Studio
  • Microsoft Foundry
  • Kubernetes
  • AKS
  • Cloud Data Platform
  • SQL Managed Instance (SQL MI)
  • Cosmos DB
  • Synapse Analytics
  • Fabric
  • Client Relationship Management
  • Microsoft Certified: Azure Solutions Architect Expert (AZ-305)
  • Microsoft Certified: Azure Administrator Associate (AZ-104)
  • Microsoft Certified: Azure Security Engineer Associate (AZ-500)
  • Microsoft Certified: Cybersecurity Architect Expert (SC-100)
  • Microsoft Certified: DevOps Engineer Expert (AZ-400)
  • Microsoft Certified: Azure Network Engineer Associate (AZ-700)
  • Microsoft 365 Certified: Enterprise Administrator Expert

Experience Level

  • 8+ years of hands-on experience

Benefits

  • Competitive pay
  • Comprehensive benefits package
  • Generous paid time off
  • Medical coverage
  • Dental coverage
  • Vision coverage
  • Flexible spending accounts
  • Health reimbursement account
  • 401(k) plan with company match

About the Company

  • HSO is an Equal Opportunity Employer.

Equal Opportunity

  • HSO is an Equal Opportunity Employer.