Cloud Platform Architect
About the role
We are hiring a Cloud Platform Architect specializing in identity to own cloud identity as a platform capability within our Cloud Platform team. You will take ownership of our Microsoft Entra estate and everything from the synchronization boundary up: authentication design, access policy, hybrid identity, and the identity patterns the rest of the platform builds on.
The platform operates on an enablement model: guardrails enforced in code and self-serve patterns as the default path. Your job is to make secure identity the easiest option, not a queue.
This is a role for someone who wants a domain of their own: full technical ownership of cloud identity in a regulated financial environment, a direct line into platform and architecture decisions, and a roadmap that includes building our external identity capability from the ground up.
What you will own
- The Microsoft Entra estate: tenant configuration, Conditional Access, Privileged Identity Management, entitlement management
- Hybrid identity design: synchronization scope, attribute flow, authentication method, and cloud-only account policy
- Identity patterns for platform services: workload identities, service account lifecycle, and non-human identity governance
- Break-glass access design and its integration with the bank's privileged access management platform
- External and business-partner identity architecture (Entra External ID) per the cloud roadmap
- Identity blueprints, runbooks, and the documentation that makes the estate operable beyond one person
Responsibilities
- Design and operate secure, compliant identity for our Azure estate using Microsoft Entra ID, aligned to regulatory and internal audit requirements, including access control and MFA provisions
- Design, implement, and iterate Conditional Access policies, Privileged Identity Management, and entitlement management across the tenant
- Publish identity standards as both clear documentation and consumable patterns: reference designs, reusable Terraform modules, and paved-road configurations that make the standard the easiest path to follow
- Enforce identity guardrails through Azure Policy and automation rather than manual approval
- Own hybrid identity and the technical interface with the directory services team: Entra Connect scope, what synchronizes, what stays cloud-only, and how the boundary is controlled
- Design workload identity patterns for Azure services and pipelines: managed identities, workload identity federation, and service principal lifecycle
- Partner with Security, Risk, and Compliance to integrate regulatory controls and evidence collection into identity designs
- Represent cloud identity in audit and regulatory conversations
Qualifications
- 7+ years in identity or infrastructure engineering, including deep hands-on Microsoft Entra ID experience at enterprise scale
- Proven experience in regulated financial services (banking, capital markets, or insurance) or a comparably regulated environment
- Strong command of Conditional Access design, Privileged Identity Management, hybrid identity (Entra Connect / cloud sync), and workload identity patterns
- Experience taking ownership of an established identity estate and maturing its configuration, documentation, and controls
- Working knowledge of authentication standards (OIDC, OAuth 2.0, SAML) and modern authentication policy (phishing-resistant MFA, token protection)
- Solid working knowledge of the broader Azure platform: RBAC, Azure Policy, Key Vault, and how identity integrates with core infrastructure services
- Familiarity with control frameworks and regulatory expectations for identity and access management
- Scripting and automation proficiency (PowerShell, Microsoft Graph API); Infrastructure-as-Code experience preferred
What distinguishes a strong candidate
- You build a defensible picture of an environment before changing anything in it
- You know what you chose not to enforce, and why: policy design for you is about blast radius and rollout, not checklists
- You have made an identity control easier to follow instead of easier to bypass
- Your last hands-on work was recent, and you intend to keep it that way
Pay
The expected base salary ranges from $112k–$205k. Salary offers are based on a wide range of factors including relevant skills, training, experience, education, and, where applicable, certifications and licenses obtained. Market and organizational factors are also considered. In addition to salary and a generous employee benefits package, successful candidates are eligible to receive a discretionary bonus.