Location: New York City, NY — Hybrid
Employment Type: Full-time
Position Overview
A growing organization is seeking a highly experienced Senior Microsoft Cloud Engineer / Cloud Solutions Architect to own the end-to-end design, architecture, security, governance, and ongoing evolution of its Microsoft cloud environment.
This is a high-autonomy, architect-level role for a hands-on technical leader who can translate enterprise business needs into secure, scalable cloud solutions. The successful candidate will work across Azure infrastructure, Microsoft 365, identity, endpoint management, cybersecurity, cloud governance, data platforms, and AI-enabled solutions.
The role requires someone who is equally comfortable leading technical design discussions, developing Infrastructure-as-Code, implementing cloud security controls, building deployment pipelines, administering enterprise platforms, and communicating architecture decisions to executive and technical stakeholders.
Key Responsibilities
- Design, implement, and continuously improve enterprise-scale Microsoft Azure infrastructure across multiple subscriptions, environments, and business units.
- Architect Azure networking, compute, storage, identity, monitoring, governance, cost management, and security capabilities.
- Define and maintain cloud landing zones, hub-and-spoke networking, hybrid identity, subscription-management, and environment-segmentation standards.
- Apply Microsoft Cloud Adoption Framework and Well-Architected Framework principles to cloud design, governance, resiliency, security, and operational efficiency.
- Own end-to-end Microsoft 365 architecture across Exchange Online, SharePoint Online, OneDrive, Teams, Microsoft Entra ID, Intune, and Microsoft Purview.
- Develop strategic approaches to Microsoft 365 information architecture, collaboration models, tenant governance, security boundaries, data retention, and compliance controls.
- Lead Microsoft 365 migrations, workload modernization, tenant architecture, identity consolidation, and complex cross-environment or tenant-to-tenant initiatives as needed.
- Design high-availability, disaster recovery, backup, business continuity, and resilience strategies for Azure and Microsoft 365 workloads.
- Define and lead Infrastructure-as-Code standards using Bicep, ARM templates, Terraform, or comparable technologies.
- Build, improve, and maintain CI/CD pipelines for secure, repeatable deployment of cloud infrastructure, configuration, data, and application resources.
- Establish DevOps and DevSecOps practices, including source control, peer review, automated testing, security scanning, deployment approvals, and environment promotion.
- Improve the reliability, consistency, observability, and supportability of cloud environments through automation, monitoring, alerting, and operational runbooks.
- Partner with engineering, security, data, and IT operations teams to establish scalable standards for cloud delivery.
Security & Governance
- Design and implement Zero Trust security architecture across identity, endpoints, networks, applications, cloud infrastructure, data, and AI solutions.
- Own the technical architecture of Microsoft security services, including Microsoft Defender for Cloud, Defender for Endpoint, Defender for Identity, Defender for Office 365, Microsoft Sentinel, and Microsoft Purview.
- Design and maintain Entra ID security controls, including Conditional Access, Multi-Factor Authentication, Privileged Identity Management, RBAC, identity governance, access reviews, hybrid identity, and privileged-access standards.
- Establish cloud-governance controls for subscription design, resource tagging, cost allocation, budgets, policy enforcement, Azure Policy, resource standards, and exception management.
- Implement data-governance and compliance controls such as data classification, sensitivity labels, DLP, retention, eDiscovery, information protection, data lineage, audit logging, and insider-risk controls.
- Ensure security-by-design and privacy-by-design principles are embedded in cloud, data, automation, and AI solution architecture.
- Support regulatory and compliance requirements that may include SOC 2, ISO 27001, GDPR, and other industry or customer obligations.
AI & Data Platform Solutions
- Architect and deploy AI and large-language-model solutions that integrate securely with enterprise cloud, collaboration, and data environments.
- Lead implementation and governance of Microsoft 365 Copilot, Copilot Studio, Azure AI Foundry, Azure OpenAI Service, and comparable AI platforms.
- Evaluate and support third-party AI and LLM providers, including Claude and comparable platforms, based on technical capabilities, data security, privacy, compliance, integration requirements, and business value.
- Design secure AI integration patterns, including identity-aware access, data-access boundaries, network isolation, logging, auditability, prompt/data governance, retrieval controls, and responsible-AI safeguards.
- Build and maintain retrieval-augmented generation (RAG) capabilities, AI-assisted workflows, agentic automation, knowledge-retrieval solutions, and integrations with approved enterprise data sources.
- Establish standards for securely connecting AI tools to Microsoft 365, line-of-business applications, enterprise data repositories, analytics systems, and knowledge bases.
- Monitor evolving AI capabilities and recommend practical, scalable use cases that improve productivity, decision-making, automation, and business performance.
Data Platform Administration
- Architect, administer, and optimize modern data platforms, including Snowflake and/or Databricks.
- Manage workspace or account configuration, identity integration, access controls, RBAC, cost governance, performance tuning, monitoring, and operational standards.
- Design secure data-platform integrations with Azure data services, including Azure Data Factory, Microsoft Fabric, Azure Synapse Analytics, Azure Data Lake Storage, and related services.
- Develop secure, governed data pipelines supporting AI, analytics, reporting, and business-intelligence initiatives.
- Partner with data engineering, analytics, and business teams to improve data quality, data lineage, accessibility, performance, scalability, governance, and compliance.
- Support data cataloging and governance practices using tools such as Microsoft Purview, Unity Catalog, or comparable platforms.
- Serve as the organization’s subject-matter authority for Azure, Microsoft 365, cloud security, cloud governance, AI, and modern data-platform architecture.
- Partner with senior technology leaders, security teams, data teams, engineering teams, and business stakeholders to define roadmaps and make architecture decisions.
- Translate complex technical concepts, risks, and tradeoffs into clear recommendations for executive and non-technical audiences.
- Mentor cloud engineers, systems administrators, and IT staff; raise team capabilities through technical leadership, documentation, standards, and knowledge sharing.
- Create and maintain architecture diagrams, architecture decision records, technical standards, security patterns, runbooks, deployment documentation, and operational procedures.
- Stay current with developments across Microsoft Azure, Microsoft 365, AI/LLM platforms, data technologies, cloud security, and enterprise governance practices.
Required Qualifications
- 8+ years of experience in infrastructure engineering, cloud engineering, systems engineering, or related enterprise technology roles.
- 5+ years of hands-on Azure and Microsoft 365 experience at a solution architecture, engineering, or design level—not solely routine platform administration.
- Azure networking, VNets, subnets, routing, private connectivity, VPN, ExpressRoute, Azure Firewall, network security groups, and network segmentation.
- Azure storage, backup, disaster recovery, monitoring, logging, governance, identity, access controls, and cost-management practices.
- Deep Microsoft 365 architecture and engineering knowledge across Exchange Online, SharePoint Online, OneDrive, Teams, Intune, Microsoft Entra ID, and Microsoft Purview.
- Experience with Microsoft 365 governance, information architecture, identity design, tenant configuration, complex migrations, and collaboration/security strategy.
- Strong cloud-security architecture experience, including Zero Trust principles, Conditional Access, MFA, RBAC, PIM, identity governance, network segmentation, Microsoft Defender, Microsoft Sentinel, and Microsoft Purview.
- Demonstrated ability to design secure AI and LLM solution architectures, including data-governance, access-control, network-security, model-integration, auditing, monitoring, and responsible-AI considerations.
- Hands‑on experience administering or architecting at least one modern data platform, such as Snowflake or Databricks.
- Experience with Infrastructure-as-Code using Terraform, Bicep, ARM templates, or comparable tools.
- Strong scripting and automation skills using PowerShell, Python, Azure CLI, Azure PowerShell, APIs, or similar technologies.
- Experience designing or supporting CI/CD pipelines, cloud deployment practices, source control, and DevOps or DevSecOps workflows.
- Strong written and verbal communication skills, including the ability to present technical recommendations to executive stakeholders.
Preferred Qualifications
- Production experience with Microsoft 365 Copilot, Copilot Studio, Azure AI Foundry, Azure OpenAI Service, Claude, or similar enterprise AI/LLM platforms.
- Experience designing AI agents, copilots, knowledge assistants, RAG architectures, AI workflow automation, or enterprise AI integrations.
- Experience with Microsoft Power Platform, including Power Automate, Power Apps, Power BI, or related low-code automation and analytics technologies.
- Experience with Microsoft Purview, Unity Catalog, Snowflake governance capabilities, or other data cataloging, lineage, classification, and governance tools.
- Experience with Azure Data Factory, Azure Synapse Analytics, Microsoft Fabric, Azure Data Lake Storage, Databricks, Snowflake, or comparable enterprise data services.
- Experience using Azure DevOps, GitHub Actions, Git, Azure Repos, GitHub, CI/CD pipelines, and Infrastructure-as-Code release practices.
- Experience in a regulated, security-sensitive, or data-intensive industry such as financial services, healthcare, insurance, legal, government, or professional services.
- Experience leading cloud migrations, Microsoft 365 tenant consolidations, identity modernization, enterprise security transformation, or major cloud architecture initiatives.
- Prior experience mentoring engineers or leading technical initiatives across multiple stakeholders and teams.
Preferred Certifications
- Microsoft Certified: Azure Solutions Architect Expert.
- Microsoft Certified: Cybersecurity Architect Expert.
- SnowPro Advanced Architect, SnowPro Core, or comparable Snowflake certification.
- Databricks Certified Data Engineer, Data Analyst, Machine Learning Professional, or Solution Architect certification.
- Relevant AI, machine learning, cloud security, data engineering, or governance certifications.
What the Organization Offers
- Opportunity to define and mature enterprise cloud, security, data, and AI architecture from the ground up.
- High-visibility role with direct partnership and influence across executive leadership, technology, data, security, and business teams.
- Ownership of strategic initiatives involving cloud modernization, AI enablement, data platforms, cybersecurity, and enterprise automation.
- Comprehensive benefits package, including health coverage, retirement benefits, paid time off, and additional employee programs.