Cloud Platform Architect

Mizuho Financial Group Inc.

New York (NY)

Hybrid

USD 112,000 - 205,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Mizuho Financial Group, Inc. seeks a Cloud Platform Architect specializing in identity to own our Microsoft Entra estate, leading authentication design, access policy, and hybrid identity as a core platform capability within the Cloud Platform team.

This role requires deep Entra ID experience in a regulated financial environment, ownership of external identity architecture, and the ability to turn policy into guardrails via code, with a strong emphasis on security and compliance.

Qualifications

  • 7+ years in identity or infrastructure engineering.
  • Proven experience with Microsoft Entra ID at enterprise scale.
  • Experience in regulated financial services or similarly regulated environments.
  • Strong knowledge of authentication standards: OIDC, OAuth 2.0, SAML.

Responsibilities

  • Own the Microsoft Entra estate configurations and policies.
  • Design hybrid identity and synchronization boundaries across systems.
  • Develop identity patterns for platform services and service principals.
  • Implement external and partner identity architecture per cloud roadmap.
  • Publish reusable identity designs and Terraform modules for standardization.
  • Collaborate with Security, Risk, and Compliance to integrate controls and evidence.

Skills

Entra ID
IAM
Hybrid identity
Azure Policy
RBAC
Graph API
PowerShell

Tools

Terraform
Azure AD Connect

Job description

Join Mizuho as a Cloud Platform Architect, Entra!

About the role

We are hiring a Cloud Platform Architect specializing in identity to own cloud identity as a platform capability within our Cloud Platform team. You will take ownership of our Microsoft Entra estate and everything from the synchronization boundary up: authentication design, access policy, hybrid identity, and the identity patterns the rest of the platform builds on. The platform operates on an enablement model: guardrails enforced in code and self-serve patterns as the default path. Your job is to make secure identity the easiest option, not a queue. This is a role for someone who wants a domain of their own: full technical ownership of cloud identity in a regulated financial environment, a direct line into platform and architecture decisions, and a roadmap that includes building our external identity capability from the ground up.

What you will own
  • The Microsoft Entra estate: tenant configuration, Conditional Access, Privileged Identity Management, entitlement management
  • Hybrid identity design: synchronization scope, attribute flow, authentication method, and cloud-only account policy
  • Identity patterns for platform services: workload identities, service account lifecycle, and non-human identity governance
  • Break-glass access design and its integration with the bank's privileged access management platform
  • External and business-partner identity architecture (Entra External ID) per the cloud roadmap
  • Identity blueprints, runbooks, and the documentation that makes the estate operable beyond one person
Responsibilities
  • Design and operate secure, compliant identity for our Azure estate using Microsoft Entra ID, aligned to regulatory and internal audit requirements, including access control and MFA provisions
  • Design, implement, and iterate Conditional Access policies, Privileged Identity Management, and entitlement management across the tenant
  • Publish identity standards as both clear documentation and consumable patterns: reference designs, reusable Terraform modules, and paved-road configurations that make the standard the easiest path to follow
  • Enforce identity guardrails through Azure Policy and automation rather than manual approval
  • Own hybrid identity and the technical interface with the directory services team: Entra Connect scope, what synchronizes, what stays cloud-only, and how the boundary is controlled
  • Design workload identity patterns for Azure services and pipelines: managed identities, workload identity federation, and service principal lifecycle
  • Partner with Security, Risk, and Compliance to integrate regulatory controls and evidence collection into identity designs
  • Represent cloud identity in audit and regulatory conversations
Qualifications
  • 7+ years in identity or infrastructure engineering, including deep hands-on Microsoft Entra ID experience at enterprise scale
  • Proven experience in regulated financial services (banking, capital markets, or insurance) or a comparably regulated environment
  • Strong command of Conditional Access design, Privileged Identity Management, hybrid identity (Entra Connect / cloud sync), and workload identity patterns
  • Experience taking ownership of an established identity estate and maturing its configuration, documentation, and controls
  • Working knowledge of authentication standards (OIDC, OAuth 2.0, SAML) and modern authentication policy (phishing-resistant MFA, token protection)
  • Solid working knowledge of the broader Azure platform: RBAC, Azure Policy, Key Vault, and how identity integrates with core infrastructure services
  • Familiarity with control frameworks and regulatory expectations for identity and access management
  • Scripting and automation proficiency (PowerShell, Microsoft Graph API); Infrastructure-as-Code experience preferred
What distinguishes a strong candidate

You build a defensible picture of an environment before changing anything in it

You know what you chose not to enforce, and why: policy design for you is about blast radius and rollout, not checklists

You have made an identity control easier to follow instead of easier to bypass

Your last hands-on work was recent, and you intend to keep it that way

Salary and benefits

The expected base salary ranges from $112k-$205k. Salary offers are based on a wide range of factors including relevant skills, training, experience, education, and, where applicable, certifications and licenses obtained. Market and organizational factors are also considered. In addition to salary and a generous employee benefits package, successful candidates are eligible to receive a discretionary bonus. #LI-Hybrid

Other requirements

Mizuho has in place a hybrid working program, with varying opportunities for remote work depending on the nature of the role, needs of your department, as well as local laws and regulatory obligations. Roles in some of our departments have greater in-office requirements that will be communicated to you as part of the recruitment process.

Company Overview

Mizuho Financial Group, Inc. is the 15th largest bank in the world as measured by total assets of ~$2 trillion. Mizuho's 60,000 employees worldwide offer comprehensive financial services to clients in 35 countries and 800 offices throughout the Americas, EMEA and Asia. Mizuho Americas is a leading provider of corporate and investment banking services to clients in the US, Canada, and Latin America. Through its acquisition of Greenhill, Mizuho provides M&A, restructuring and private capital advisory capabilities across Americas, Europe and Asia. Mizuho Americas employs approximately 3,500 professionals, and its capabilities span corporate and investment banking, capital markets, equity and fixed income sales & trading, derivatives, FX, custody and research. Visit www.mizuhoamericas.com. Mizuho Americas offers a competitive total rewards package.

EEO statement

We are an EEO/AA Employer - M/F/Disability/Veteran.

We participate in the E-Verify program. We maintain a drug-free workplace and reserve the right to require pre- and post-hire drug testing as permitted by applicable law. #LI-MIZUHO

Why Mizuho

Mizuho is in growth mode as we are climbing the league tables, disrupting the status quo, and attracting top talent. Positions are available across our corporate functions, and on our corporate and investment banking, capital markets, advisory, research, sales & trading, derivatives, and financing teams. We are looking for candidates who want to contribute to our entrepreneurial culture where people at all levels are inspired to share ideas. Our creativity sets us apart, and our perseverance drives results in creating bespoke, client-focused solutions. If you are interested in advancing your career working for a firm with a growth mindset and the resources of a global financial services team, we would like to hear from you. For more information, please view our Recruiting Brochure

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cloud Platform Architect
Cloud Platform Architect

Mizuho • New York (NY)

Hybrid
USD 112,000 - 205,000
Hybrid work program
Discretionary bonus
Lead Cloud Architect
Lead Cloud Architect

Mizuho Financial Group Inc. • New York (NY)

Hybrid
USD 160,000 - 225,000
Lead Cloud Architect
Lead Cloud Architect

Mizuho • New York (NY)

Hybrid
USD 160,000 - 225,000
Discretionary bonus
Hybrid work program
Comprehensive benefits
Enterprise Architecture Process Lead
Enterprise Architecture Process Lead

Mizuho Financial Group Inc. • New York (NY)

Hybrid
USD 200,000 - 260,000
Cyber Defense, Adversary Emulation Director
Cyber Defense, Adversary Emulation Director

Mizuho Financial Group Inc. • Northern (KY)

Hybrid
USD 150,000 - 225,000
Medical insurance
Dental insurance
401K plan
Cyber Defense, Adversary Emulation Director
Cyber Defense, Adversary Emulation Director

Mizuho Financial Group Inc. • United States

Hybrid
USD 150,000 - 225,000
Medical, Dental and 401K
Discretionary bonus
Privileged Access Management Lead
Privileged Access Management Lead

Mizuho Financial Group Inc. • United States

Hybrid
USD 200,000 - 275,000
Hybrid work model
Discretionary bonus
Competitive benefits
Senior VCS Engineer
Senior VCS Engineer

Mizuho Financial Group Inc. • United States

Hybrid
USD 111,000 - 180,000
AI, Analytics & RPA Support SRE Manager
AI, Analytics & RPA Support SRE Manager

Mizuho Financial Group Inc. • New York (NY), Northern (KY)

Hybrid
USD 112,000 - 150,000
Privileged Access Management Lead
Privileged Access Management Lead

Mizuho • Woodbridge Township (NJ)

Hybrid
USD 200,000 - 275,000
Hybrid work flexibility
Competitive compensation package
Discretionary bonus