Role: Azure Cloud Architect
Location: Brussels, Belgium
Deadline for submitting CV's: 18/04/2025 17:36
Client: Elia
Description:
We are seeking an experienced Azure Cloud Architect with security expertise to join our Engineering chapter team. In this hybrid role, you will be responsible for designing, implementing and securing cloud infrastructure solutions with a strong focus on integrating security throughout the development, deployment, and operations lifecycle in the Consumer Centricity organization. You will work closely with cross-functional teams to deliver secure, scalable, and highly available cloud native solutions, while ensuring that security is a primary consideration throughout the software development lifecycle.
Requirements:
Key Responsibilities:
Identity & Access Management (IAM): Implement and manage secure authentication and authorization policies using Azure Entra ID, Privileged Identity Management (PIM), role-based access control (RBAC), and conditional access to ensure least-privilege access for users, applications, and services.
Encryption & Data Protection: Ensure that all data stored and transmitted in Azure environments is protected using encryption techniques. Architect solutions that use Azure Key Vault for secure key management and Azure Disk Encryption for data protection.
Automation & Security Tools: Utilize automation tools (e.g. ArgoCD) and DevSecOps principles to implement security into the CI/CD pipeline, ensuring that security testing, vulnerability scanning, and security checks are integrated into the entire software development lifecycle . Leverage Infrastructure as Code (IaC) tools such as Terraform, Bicep, or Azure Resource Manager (ARM) templates to automate secure resource provisioning and configuration.
Security Monitoring & Incident Response: Automate security tasks including vulnerability scanning, compliance checks, threat detection, and security monitoring using tools like Azure Sentinel, Azure Monitor, and Azure Defender. Develop and execute incident response plans for handling security breaches, including data exfiltration, DDoS attacks, or insider threats.
Cost Management & Optimization: Monitor cloud usage and costs, recommend optimization strategies, and help implement cost-effective cloud solutions while ensuring security and performance.
Collaboration & Leadership: Collaborate with cross-functional teams (DevOps, operations, development, and security) to integrate security best practices into the design and deployment of cloud-based solutions. Provide guidance on secure cloud design, and mentor team members in security architecture and best practices.
Cloud Architecture Documentation : Create and maintain comprehensive documentation on security architecture, security controls, cloud security policies, and risk management strategies.
Qualifications:
Strong understanding of cloud networking, hybrid cloud, and virtual networking concepts (e.g., VPNs, subnets, NSGs, load balancing, hub-spoke).
Expertise in designing and implementing cloud security architectures on Azure, with strong knowledge of Azure Defender, Azure Sentinel, Azure Key Vault, Azure EntraID, Azure Firewall, and other Azure security services.
Strong understanding of security frameworks and compliance standards (e.g. ISO 27001, GDPR, NIS2), and the ability to implement and manage them in the Azure cloud.
Experience with Identity and Access Management (IAM), including Azure Entra ID, Privileged Identity Management (PIM), role-based access control (RBAC), multi-factor authentication (MFA), and Conditional Access Policies.
Proficient in implementing Encryption strategies, such as Azure Disk Encryption, Azure Information Protection, and SSL/TLS for securing data in transit and at rest.
Experience with containerization and container security using Docker, Azure Kubernetes Service (AKS), and related tools to secure containerized environments.
Expertise in Infrastructure as Code (IaC) tools such as Terraform, ARM templates, or Bicep to automate secure provisioning and configuration of Azure resources.
Experience in Azure governance and cost management using Azure Cost Management, Azure Policies, and management groups.
· Experience with monitoring and logging tools such as Azure Monitor, Application Insights, or Log Analytics and third-party solutions like Splunk or Elastic Stack.
Experience in risk management, vulnerability assessment, and penetration testing, along with a strong understanding of incident response and remediation strategies in the cloud.
Hands-on experience with CI/CD tools (e.g., Azure DevOps, ArgoCD) and integration of security tools (e.g. SonarQube) within the pipeline.
Proficiency in scripting languages (e.g., PowerShell, Azure CLI, Python) to automate security tasks and infrastructure provisioning.
· Excellent problem-solving and troubleshooting skills in cloud environments.
Strong communication skills with the ability to explain complex security concepts to non-technical stakeholders and to collaborate across teams.
· Languages: English (C1).
Not a must, but advantageous:
Microsoft Azure certifications, such as Azure Solutions Architect Expert, Azure Security Engineer Associate, or Microsoft Certified: Azure DevOps Engineer Expert.
Security certifications such as CISSP, CCSP, Certified Cloud Security Professional (CCSP), or Certified Information Security Manager (CISM).
· Experience with following technologies: Kong, Event Hubs, Dapr
· Open to participate in a duty roll (24*7).
· Extra Languages: French (B1), Dutch (B1).
-
Additional information:
· Location: Primary location is Brussels and Berlin occasionally
Telework is possible but due to the nature of our environment (secure networks), onsite presence will be required at least partially.
Important: for non-EU candidates, please present candidates who comply with the following criteria:
System Manager-Architect (TSM) in Cloud
Ericsson, Brussels,
Cloud Operations Architect, ES - EMEA
AWS EMEA SARL (Belgium Branch), Brussels,