A global financial institution is looking for a senior Cloud Platform Architect to take technical ownership of its Microsoft Entra and cloud identity environment.
This is a hands-on individual contributor opportunity for someone who understands identity as a platform capability rather than simply an administrative function. You will help mature an established enterprise identity estate while defining secure, reusable patterns for workforce, privileged, workload, and external identities.
The environment emphasizes automation, secure defaults, coded guardrails, and self-service patterns. Success requires someone who can make sound architecture decisions while remaining close enough to the technology to understand rollout risk, exceptions, production impact, and long-term operational support.
Responsibilities
- Own architecture and continuous improvement across the Microsoft Entra environment
- Design and evolve Conditional Access, privileged-access, and entitlement controls
- Define hybrid identity patterns across synchronization, authentication, attribute flow, and cloud-only identities
- Establish standards for managed identities, workload identity federation, service principals, and other non-human identities
- Create reusable identity patterns through automation, scripting, Infrastructure as Code, and platform guardrails
- Develop architecture standards, reference designs, runbooks, and reusable implementation patterns
- Partner with Security, Risk, Compliance, Audit, Directory Services, application teams, and cloud engineering
- Support identity-control evidence and architecture discussions in a highly regulated environment
Role Requirements
- 7+ years of identity, cloud, or infrastructure engineering experience
- Deep hands-on Microsoft Entra ID / Azure AD experience in an enterprise environment
- Hands-on Privileged Identity Management experience
- Strong hybrid identity knowledge, including Entra Connect, Azure AD Connect, or Cloud Sync
- Experience designing workload and non-human identity patterns
- Working knowledge of OIDC, OAuth 2.0, SAML, MFA, and modern authentication
- Understanding of Azure RBAC, Azure Policy, Key Vault, and identity integration across Azure services
- Hands-on PowerShell and Microsoft Graph API experience
- Experience operating in financial services or another comparably regulated enterprise
- Ability to communicate technical architecture and risk clearly to engineering, security, and control stakeholders
Nice to Have
- Terraform or other Infrastructure-as-Code experience
- Entra External ID experience
- Identity governance and Entitlement Management
- Break-glass and privileged-access architecture
- Banking, capital markets, or insurance experience
How We Work
- Senior architects remain technically credible and close to implementation
- Identity controls are designed around automation and reusable patterns rather than manual approval
- Architecture decisions are evaluated for security, maintainability, supportability, and blast radius
- The role partners closely with Cloud Platform, Security, Risk, Compliance, Directory Services, and application teams
- The position follows a hybrid New York schedule of five onsite days across every ten business days