Cloud Platform Architect

Mizuho

New York (NY)

Hybrid

USD 112,000 - 205,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Hybrid work program
Discretionary bonus

Job summary

Mizuho is seeking a Cloud Platform Architect with a focus on Microsoft Entra identity to own cloud identity as a platform capability within the Cloud Platform team. You will manage the Entra estate, hybrid identity, and security-first patterns across the Azure estate.

The role requires deep experience in enterprise-grade identity, regulation-aware governance, and hands-on automation to enable secure, auditable identity services. Hybrid work is available within a financial-regulated landscape.

Qualifications

  • 7+ years in identity or infrastructure engineering with hands-on Microsoft Entra ID experience at enterprise scale
  • Experience in regulated financial services or comparably regulated environment
  • Strong command of Conditional Access design, Privileged Identity Management, hybrid identity, and workload identity patterns
  • Experience owning an established identity estate and maturing its configuration, documentation, and controls
  • Working knowledge of authentication standards (OIDC, OAuth 2.0, SAML) and modern authentication policy (MFA)
  • Solid working knowledge of the broader Azure platform: RBAC, Azure Policy, Key Vault, and how identity integrates with core infrastructure services
  • Familiarity with regulatory expectations for identity and access management
  • Scripting and automation proficiency (PowerShell, Microsoft Graph API); IaC experience preferred

Responsibilities

  • Design and operate secure, compliant identity for our Azure estate using Microsoft Entra ID, aligned to regulatory and internal audit requirements, including access control and MFA provisions
  • Design, implement, and iterate Conditional Access policies, Privileged Identity Management, and entitlement management across the tenant
  • Publish identity standards as both clear documentation and consumable patterns: reference designs, reusable Terraform modules, and paved-road configurations that make the standard the easiest path to follow
  • Enforce identity guardrails through Azure Policy and automation rather than manual approval
  • Own hybrid identity and the technical interface with the directory services team: Entra Connect scope, what synchronizes, what stays cloud-only, and how the boundary is controlled
  • Design workload identity patterns for Azure services and pipelines: managed identities, workload identity federation, and service principal lifecycle
  • Partner with Security, Risk, and Compliance to integrate regulatory controls and evidence collection into identity designs
  • Represent cloud identity in audit and regulatory conversations

Skills

Identity engineering
Hybrid identity
Conditional Access
Privileged Identity Management
Workload identity
PowerShell
Microsoft Graph API
Terraform / IaC

Tools

Microsoft Entra ID
Azure
Azure Policy
RBAC
Key Vault

Job description

Join Mizuho as a Cloud Platform Architect, Entra!
About the role

We are hiring a Cloud Platform Architect specializing in identity to own cloud identity as a platform capability within our Cloud Platform team.

You will take ownership of our Microsoft Entra estate and everything from the synchronization boundary up: authentication design, access policy, hybrid identity, and the identity patterns the rest of the platform builds on. The platform operates on an enablement model: guardrails enforced in code and self-serve patterns as the default path. Your job is to make secure identity the easiest option, not a queue.

This is a role for someone who wants a domain of their own: full technical ownership of cloud identity in a regulated financial environment, a direct line into platform and architecture decisions, and a roadmap that includes building our external identity capability from the ground up.

What you will own
  • The Microsoft Entra estate: tenant configuration, Conditional Access, Privileged Identity Management, entitlement management
  • Hybrid identity design: synchronization scope, attribute flow, authentication method, and cloud-only account policy
  • Identity patterns for platform services: workload identities, service account lifecycle, and non-human identity governance
  • Break-glass access design and its integration with the bank’s privileged access management platform
  • External and business-partner identity architecture (Entra External ID) per the cloud roadmap
  • Identity blueprints, runbooks, and the documentation that makes the estate operable beyond one person
Responsibilities
  • Design and operate secure, compliant identity for our Azure estate using Microsoft Entra ID, aligned to regulatory and internal audit requirements, including access control and MFA provisions
  • Design, implement, and iterate Conditional Access policies, Privileged Identity Management, and entitlement management across the tenant
  • Publish identity standards as both clear documentation and consumable patterns: reference designs, reusable Terraform modules, and paved-road configurations that make the standard the easiest path to follow
  • Enforce identity guardrails through Azure Policy and automation rather than manual approval
  • Own hybrid identity and the technical interface with the directory services team: Entra Connect scope, what synchronizes, what stays cloud-only, and how the boundary is controlled
  • Design workload identity patterns for Azure services and pipelines: managed identities, workload identity federation, and service principal lifecycle
  • Partner with Security, Risk, and Compliance to integrate regulatory controls and evidence collection into identity designs
  • Represent cloud identity in audit and regulatory conversations
Qualifications
  • 7+ years in identity or infrastructure engineering, including deep hands-on Microsoft Entra ID experience at enterprise scale
  • Proven experience in regulated financial services (banking, capital markets, or insurance) or a comparably regulated environment
  • Strong command of Conditional Access design, Privileged Identity Management, hybrid identity (Entra Connect / cloud sync), and workload identity patterns
  • Experience taking ownership of an established identity estate and maturing its configuration, documentation, and controls
  • Working knowledge of authentication standards (OIDC, OAuth 2.0, SAML) and modern authentication policy (phishing-resistant MFA, token protection)
  • Solid working knowledge of the broader Azure platform: RBAC, Azure Policy, Key Vault, and how identity integrates with core infrastructure services
  • Familiarity with control frameworks and regulatory expectations for identity and access management
  • Scripting and automation proficiency (PowerShell, Microsoft Graph API); Infrastructure-as-Code experience preferred
What distinguishes a strong candidate
  • You build a defensible picture of an environment before changing anything in it
  • You know what you chose not to enforce, and why: policy design for you is about blast radius and rollout, not checklists
  • You have made an identity control easier to follow instead of easier to bypass
  • Your last hands-on work was recent, and you intend to keep it that way

The expected base salary ranges from $112k-$205k. Salary offers are based on a wide range of factors including relevant skills, training, experience, education, and, where applicable, certifications and licenses obtained. Market and organizational factors are also considered. In addition to salary and a generous employee benefits package, successful candidates are eligible to receive a discretionary bonus.

#LI-Hybrid

Other requirements

Mizuho has in place a hybrid working program, with varying opportunities for remote work depending on the nature of the role, needs of your department, as well as local laws and regulatory obligations. Roles in some of our departments have greater in-office requirements that will be communicated to you as part of the recruitment process.

Company Overview

Mizuho Financial Group, Inc. is the 15th largest bank in the world as measured by total assets of ~$2 trillion. Mizuho’s 60,000 employees worldwide offer comprehensive financial services to clients in 35 countries and 800 offices throughout the Americas, EMEA and Asia. Mizuho Americas is a leading provider of corporate and investment banking services to clients in the US, Canada, and Latin America. Through its acquisition of Greenhill, Mizuho provides M&A, restructuring and private capital advisory capabilities across Americas, Europe and Asia. Mizuho Americas employs approximately 3,500 professionals, and its capabilities span corporate and investment banking, capital markets, equity and fixed income sales & trading, derivatives, FX, custody and research. Visit www.mizuhoamericas.com.

Mizuho Americasoffers a competitive total rewards package.

We are an EEO/AA Employer -M/F/Disability/Veteran.

We participate in the E-Verify program.

We maintain a drug-free workplace and reserve the right to require pre- and post-hire drug testing as permitted by applicable law.

#LI-MIZUHO

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cloud Platform Architect
Cloud Platform Architect

Mizuho Financial Group Inc. • New York (NY)

Hybrid
USD 112,000 - 205,000
Lead Cloud Architect
Lead Cloud Architect

Mizuho • New York (NY)

Hybrid
USD 160,000 - 225,000
Discretionary bonus
Hybrid work program
Comprehensive benefits
Lead Cloud Architect
Lead Cloud Architect

Mizuho Financial Group Inc. • New York (NY)

Hybrid
USD 160,000 - 225,000
Privileged Access Management Lead
Privileged Access Management Lead

Mizuho • Woodbridge Township (NJ)

Hybrid
USD 200,000 - 275,000
Hybrid work flexibility
Competitive compensation package
Discretionary bonus
Cloud Data Engineer
Cloud Data Engineer

Mizuho • Woodbridge Township (NJ)

Hybrid
USD 160,000 - 200,000
Hybrid work program
Cloud Identity Platform Architect
Cloud Identity Platform Architect

Mizuho Financial Group Inc. • New York (NY)

Hybrid
USD 112,000 - 205,000
Privileged Access Management Lead
Privileged Access Management Lead

Mizuho Financial Group Inc. • United States

Hybrid
USD 200,000 - 275,000
Hybrid work model
Discretionary bonus
Competitive benefits
Cyber Defense, Adversary Emulation Director
Cyber Defense, Adversary Emulation Director

Mizuho • Woodbridge Township (NJ)

Hybrid
USD 150,000 - 225,000
Enterprise Architecture Process Lead
Enterprise Architecture Process Lead

Mizuho Financial Group Inc. • New York (NY)

Hybrid
USD 200,000 - 260,000
Enterprise Data Office - Product Management & Enablement Lead
Enterprise Data Office - Product Management & Enablement Lead

Mizuho • New York (NY)

Hybrid
USD 165,000 - 200,000
Hybrid work model
Discretionary bonus
Generous benefits package