Demo

Azure Cloud Security Architect

SPA
Alexandria, VA Full Time
POSTED ON 4/15/2025
AVAILABLE BEFORE 5/7/2025

Qualifications

Required Qualifications :

Experience :

  • 8 years in cybersecurity roles, with 5 years focused on Azure cloud security.
  • Proven experience designing secure, multi-subscription Azure environments that integrate with external partners.

Technical Skills :

  • Expertise in Azure services : Azure AD, Azure Firewall, Microsoft Defender for Cloud, Azure Sentinel, Key Vault, and Conditional Access Policies.
  • Strong knowledge of B2B interconnectivity, including Azure AD B2B, Guest Access, and identity federation.
  • Hands-on experience with hybrid connectivity using ExpressRoute, VPN Gateway, Private Link, and Azure Virtual WAN.
  • Proficiency with Infrastructure as Code (IaC) tools, including Terraform, ARM templates, or Bicep.
  • Compliance Knowledge :

  • Deep understanding of regulatory frameworks like NIST SP 800-53, CMMC, FedRAMP, ISO 27001, and DoD Impact Levels (IL2-IL6).
  • Familiarity with governance tools such as Azure Policy and Blueprints.
  • Certifications :

  • Microsoft Certified : Azure Security Engineer Associate (required).
  • Additional certifications such as Azure Solutions Architect Expert, CISSP, or CCSP are preferred.
  • Soft Skills :

  • Strong analytical and problem-solving skills.
  • Excellent communication and collaboration skills, with the ability to work with diverse stakeholders.
  • Leadership and mentoring capabilities to guide teams in adopting secure practices.
  • Desired Qualifications :

  • Experience with Mission Landing Zone (MLZ) design and deployment.
  • Knowledge of cross-domain solutions (CDS) and secure data transfer mechanisms.
  • Expertise in secure DevOps (DevSecOps) and CI / CD pipeline integration.
  • Experience with multi-cloud and inter-cloud security architectures.
  • Responsibilities

  • Security Architecture Design
  • Design secure cloud architectures incorporating zero trust, SCCA, and MLZ principles.
  • Develop hub-and-spoke network architectures using Azure Firewall, VPN Gateway, ExpressRoute, and Network Security Groups (NSGs).
  • Architect secure identity and access solutions using Azure AD, Privileged Identity Management (PIM), Key Vault, and Conditional Access Policies.
  • B2B and Enterprise Interconnectivity
  • Implement secure B2B collaboration solutions using Azure AD B2B, Guest Access, and Conditional Access Policies.
  • Architect identity federation across Azure AD tenants or with third-party identity providers to enable seamless partner integration.
  • Design and manage hybrid connectivity using ExpressRoute, VPN Gateway, Azure Private Link, and Virtual WAN.
  • Enable secure integration with third-party SaaS platforms and APIs using Azure API Management.
  • Regulatory Compliance
  • Ensure solutions meet frameworks like NIST SP 800-53, CMMC, FedRAMP, and ISO 27001.
  • Use Azure Policy and Blueprints to enforce compliance across subscriptions and workloads.
  • Provide technical support during audits, ensuring compliance evidence is well-documented.
  • Threat Management
  • Deploy and configure threat detection and response tools such as Azure Sentinel and Microsoft Defender for Cloud.
  • Conduct threat modeling, vulnerability assessments, and penetration testing.
  • Implement and optimize SIEM solutions and integrate them with monitoring tools like Log Analytics and Network Watcher.
  • Governance and Risk Management
  • Establish governance frameworks, including role-based access control (RBAC), resource tagging, and least privilege access.
  • Develop security baselines for Development, Production, and Sandbox environments.
  • Collaborate with stakeholders to identify risks and design mitigating controls for interconnectivity and workloads.
  • Automation and Integration
  • Build Infrastructure as Code (IaC) solutions using Terraform, ARM templates, or Bicep to automate compliance and security controls.
  • Integrate security into DevOps pipelines, enabling secure software delivery (DevSecOps).
  • Automate incident detection and remediation workflows to reduce response times.
  • Collaboration and Leadership
  • Partner with cloud architects, DevOps teams, and cybersecurity professionals to implement secure, scalable solutions.
  • Act as a technical leader, guiding teams to embed security best practices across the system development lifecycle (SDLC).
  • Mentor junior engineers and architects, fostering a security-focused culture.
  • If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
    Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

    What is the career path for a Azure Cloud Security Architect?

    Sign up to receive alerts about other jobs on the Azure Cloud Security Architect career path by checking the boxes next to the positions that interest you.
    Income Estimation: 
    $95,407 - $122,738
    Income Estimation: 
    $118,163 - $145,996
    Income Estimation: 
    $120,777 - $151,022
    Income Estimation: 
    $129,363 - $167,316
    Income Estimation: 
    $86,891 - $130,303
    Income Estimation: 
    $81,253 - $112,554
    Income Estimation: 
    $89,966 - $112,616
    Income Estimation: 
    $95,407 - $122,738
    Income Estimation: 
    $103,114 - $138,258
    Income Estimation: 
    $86,891 - $130,303
    Income Estimation: 
    $154,597 - $194,610
    Income Estimation: 
    $172,688 - $210,712
    Income Estimation: 
    $170,589 - $211,671
    Income Estimation: 
    $178,619 - $225,190
    Income Estimation: 
    $86,891 - $130,303
    Income Estimation: 
    $103,114 - $138,258
    Income Estimation: 
    $118,163 - $145,996
    Income Estimation: 
    $120,777 - $151,022
    Income Estimation: 
    $129,363 - $167,316
    Income Estimation: 
    $86,891 - $130,303
    Income Estimation: 
    $129,363 - $167,316
    Income Estimation: 
    $145,845 - $177,256
    Income Estimation: 
    $147,836 - $182,130
    Income Estimation: 
    $154,597 - $194,610
    Income Estimation: 
    $86,891 - $130,303
    View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

    Job openings at SPA

    SPA
    Hired Organization Address Washington, DC Full Time
    Qualifications Required Qualifications : Bachelor's degree in business administration (or other relevant field) - degree...
    SPA
    Hired Organization Address Alexandria, VA Full Time
    Qualifications Bachelor's degree in Accounting, Finance, Business Administration, or related field (preferred). At least...
    SPA
    Hired Organization Address Arlington, VA Full Time
    Qualifications Required : Active TS / SCI clearance Bachelor's degree with a desired focus area of National Security, Ec...
    SPA
    Hired Organization Address Fort Belvoir, VA Full Time
    Qualifications Required : 15 years of experience and a Bachelor's degree. Experience breifing high-level leaders to incl...

    Not the job you're looking for? Here are some other Azure Cloud Security Architect jobs in the Alexandria, VA area that may be a better fit.

    Azure Cloud & Endpoint Architect

    Orca Intelligence, Washington, DC

    AI Assistant is available now!

    Feel free to start your new journey!