Cloud Architect

EPAM Systems

Turkey

On-site

TRY 5,834,000 - 8,751,000

Full time

23 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Private health insurance
Learning platforms access
English language courses
Competitive USD salary
Mentoring programs

Job summary

EPAM Systems is seeking a Cloud Architect to design and govern our Azure platform architecture, driving automation, security, and scalability across compute, identity, networking, and Kubernetes environments. You will partner with security, network, and platform teams to build a robust self-service cloud foundation.

Responsibilities include IaC modules for Azure services, identity and access design, AKS platform architecture, and integration with network and observability layers.

Qualifications

  • 5+ years of proven Azure solution/enterprise architecture experience.
  • Deep expertise in Terraform/OpenTofu, Azure DevOps, and CI/CD-driven deployment pipelines for Azure infrastructure automation.
  • Working knowledge of Azure networking constructs (VNets, private endpoints, NSGs).
  • Hands-on experience architecting Azure Kubernetes Service (AKS) at production scale.
  • Experience with Azure identity and access architecture (Entra ID, Active Directory, managed identities, RBAC).
  • Experience with Configuration as Code (Ansible) for VM post-provisioning and golden-image pipelines.
  • English proficiency at B2 level or higher.

Responsibilities

  • Architect Infrastructure as Code modules for Azure services and AVS private cloud.
  • Define Azure identity architecture with security teams and manage secrets in Key Vault.
  • Architect AKS platform, including clusters, add-ons, and tenant onboarding.
  • Collaborate on core connectivity, DNS, IPAM, and ExpressRoute integration.
  • Define image factory architecture for VM and container baselines and CIS hardening.
  • Establish IaC engine standards consumed by all automation modules.
  • Expose Azure provisioning capabilities via Backstage templates with other architects.
  • Provide governance during implementation and support module lifecycle ownership.

Skills

Azure architecture
Terraform/OpenTofu
Azure DevOps
CI/CD pipelines
Kubernetes AKS
Ansible
English proficiency

Tools

Terraform/OpenTofu
Azure DevOps
CI/CD pipelines
AKS
Ansible
Azure Key Vault

Job description

We are seeking a Cloud Architect to design and govern our Azure platform architecture, driving the automation, security, and scalability of infrastructure across compute, identity, networking, and Kubernetes environments. This role partners closely with security, network, and platform engineering teams to deliver a robust, self-service cloud foundation.

Responsibilities
  • Architect Infrastructure as Code modules (Terraform/OpenTofu) for Azure App Services, Container Apps, Function Apps, Azure SQL, Azure Cosmos DB, Azure Postgres, and the Azure VMware Solution (AVS) private cloud module, including managed-identity wiring, private endpoints, and diagnostic settings to Log Analytics
  • Define the Azure identity architecture in partnership with the security team, including Entra ID, Active Directory, Group Policy Objects, M365 groups, SPN/app registrations, and managed identities, to ensure secrets land in OpenBao/Key Vault per platform standards
  • Architect the Azure Kubernetes Service (AKS) platform, including cluster and node-pool design, baseline add-on stack (ingress, cert-manager, external-dns, monitoring, policy), namespace/tenant onboarding, and an operations dashboard for cluster management
  • Collaborate with the Network Architect on core connectivity (VNets, Application Gateway, WAF, Azure Firewall, NSGs), DNS, NetBox IPAM, and ExpressRoute connectivity, to ensure Azure compute, database, and AKS modules integrate cleanly with the network foundation
  • Define the Image Factory architecture for VM and container golden images (Linux and Windows/cloudbase-init baselines, CIS hardening, agent injection, image scanning, Shared Image Gallery publishing/versioning)
  • Establish the foundational Infrastructure as Code Engine standards (remote state/backend, locking, RBAC, module registry, testing framework, drift detection, policy hooks, secrets injection) consumed by all other automation modules
  • Collaborate with the Backstage Architect to expose Azure provisioning capabilities as Backstage golden-path templates, and with the Integration Architects on observability, ITSM/CMDB, and security integrations touching Azure resources
  • Provide architectural governance during Implementation, validate production deployments, and support module lifecycle ownership during Adoption
Requirements
  • 5+ years of proven Azure solution/enterprise architecture experience, ideally validated through Microsoft Azure partner-level engagements or equivalent certification
  • Deep expertise in Terraform/OpenTofu, Azure DevOps, and CI/CD-driven deployment pipelines for Azure infrastructure automation, including module design and state management
  • Working knowledge of Azure networking constructs (VNets, private endpoints, NSGs) sufficient to integrate compute and data modules with the network foundation owned by the Network Architect
  • Hands-on experience architecting Azure Kubernetes Service (AKS) at production scale, including networking, policy, and multi-tenant namespace design
  • Experience with Azure identity and access architecture (Entra ID, Active Directory, managed identities, RBAC) and secrets integration (Azure Key Vault, dynamic secrets)
  • Experience with Configuration as Code (Ansible) for VM post-provisioning and golden-image pipelines
  • English proficiency at B2 level or higher
Nice to have
  • Experience with Azure VMware Solution (AVS) private cloud provisioning
  • Familiarity with certificate lifecycle management platforms (e.g., Venafi) and their integration with Azure Key Vault
  • Experience integrating Azure infrastructure automation with a Backstage-based (or comparable) developer portal
  • Knowledge of policy-as-code engines (OPA/Conftest, Azure Policy) for automated compliance enforcement
  • Prior experience in large-scale, multi-region Azure landing-zone or platform engineering
We offer
  • CONTINUOUS UPSKILLING, LEARNING & DEVELOPMENT
    • Diversity of tasks and projects
    • Assessment center for objective review of competency level
    • Personal development plan
    • Mentoring programs and leadership development
    • Certification and professional development support
    • Access to learning platforms including more than 2,500 internal courses
    • English courses taught by certified teachers
  • CORPORATE BENEFITS
    • Extra leave days
    • Referral bonuses
  • COMPENSATION PACKAGE
    • Competitive compensation paid in USD
    • Regular salary and performance reviews
  • MEDICAL & HEALTHCARE
    • Private health insurance
    • Well-being events
  • WORKING ENVIRONMENT
    • Recreation areas and kitchens
    • Tea, coffee and snacks
    • Sports equipment and game consoles
    • IT Equipment
    • Microsoft’s Software Assurance Home Use Program (HUP)

Please note that our Talent Attraction Team reviews applications and CVs submitted in English. EPAM is global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and ambitious startups. With over thirty years of expertise in custom software, product and platform engineering, we empower our clients to become AI-Native enterprises, driving measurable value from innovation and digital investments.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Azure Cloud Engineer
Lead Azure Cloud Engineer

EPAM Systems • Turkey

On-site
TRY 400,000 - 800,000
Upskilling program
Private health insurance
Mentoring programs
+1
Senior AWS DevOps Engineer
Senior AWS DevOps Engineer

EPAM Systems • Turkey

Hybrid
TRY 300,000 - 540,000
Continuous upskilling
Private health insurance
English courses
+3
Principal, Technology Consulting - Microsoft Solutions
Principal, Technology Consulting - Microsoft Solutions

EPAM Systems • Turkey

On-site
TRY 7,289,000 - 9,232,000
Continuous upskilling
Private health insurance
English courses
+3
Senior Azure DevOps Engineer
Senior Azure DevOps Engineer

EPAM Systems, Inc. • Turkey

On-site
TRY 4,329,000 - 6,253,000
Private health insurance
Home Use Program (HUP)
Professional development support
Integration Architect
Integration Architect

EPAM Systems • Turkey

On-site
TRY 5,345,000 - 6,803,000
Continuous upskilling
Private health insurance
English courses
+1
Data Architect
Data Architect

EPAM Systems • Turkey

On-site
TRY 7,292,000 - 10,209,000
Continuous upskilling
Private health insurance
English courses
+3
Solution Architect – Microsoft Low-Code & Copilot Solutions
Solution Architect – Microsoft Low-Code & Copilot Solutions

EPAM Systems • Turkey

On-site
TRY 5,834,000 - 8,751,000
Extra leave days
Referral bonuses
Competitive USD compensation
+1
Data Solution Architect
Data Solution Architect

EPAM Systems • Turkey

On-site
TRY 5,834,000 - 8,751,000
Private health insurance
English courses
Mentoring programs
+2
Lead DevOps Engineer (Azure AI / GenAI Solutions)
Lead DevOps Engineer (Azure AI / GenAI Solutions)

EPAM Systems • Turkey

On-site
TRY 4,375,000 - 6,320,000
Continuous upskilling
Private health insurance
USD compensation
+2
Solution Architect for AI-Native Team
Solution Architect for AI-Native Team

EPAM Systems • Turkey

On-site
TRY 4,375,000 - 6,806,000
Continuous upskilling
Mentoring programs
Health insurance
+3