Back to jobs

Azure Cloud Architect

New York, New York

HSO is seeking an Azure Cloud Architect to lead solution design and drive hands-on delivery of complex Microsoft Azure engagements for our clients. This role owns the architecture from discovery through implementation—spanning landing zones, migrations, identity & security, IaC, and cloud governance—while staying grounded in the platform and working directly alongside engineers and clients. A key part of the role is leading large-scale migrations and deployments, mentoring delivery teams, and building reusable assets. 

As an Azure Cloud Architect, you can expect to…

  • Azure Architecture & Platform Engineering 
    • Architect enterprise-scale Azure Landing Zones aligned to CAF and Well-Architected principles: management groups, subscriptions, Azure Policy, RBAC, and platform automation. 
    • Define compute and PaaS patterns: VM/VMSS sizing, AKS, App Service/Functions, and Container Registry as appropriate. 
    • Architect Azure Virtual Desktop solutions: host pool design, FSLogix profile strategy on Azure Files or Azure NetApp Files, Scaling Plans, and AVD Insights monitoring. 
    • Lead design sessions, produce Architecture Decision Records (ADRs), and validate approaches through hands-on proof-of-concept builds. 

  • Azure Migration 
    • Lead cloud migration programs across a range of scenarios: on-premises-to-Azure, cloud-to-cloud (e.g., AWS to Azure), and application modernization and refactoring efforts. 
    • Drive discovery and assessment: dependency mapping, workload inventory, rehost/replatform/refactor recommendations, and wave planning. 
    • Manage cutover execution and hypercare: tooling selection, replication monitoring, test migrations, rollback procedures, and stakeholder communication throughout. 

  • Identity & Security 
    • Architect Zero Trust models with Microsoft Entra ID: Conditional Access, PIM role patterns, hybrid identity (Entra Connect/Cloud Sync), and app registration governance. 
    • Define security blueprints: Azure Policy, Defender for Cloud, Microsoft Sentinel, Defender XDR integrations, and Key Vault design. 
    • Map controls to compliance frameworks (ISO 27001, SOC 2, HIPAA, PCI-DSS as applicable) and drive Secure Score improvements. 

  • Automation, IaC & CI/CD 
    • Build modular IaC frameworks in Terraform and/or Bicep: reusable landing zone modules, policy-as-code, and coding standards for delivery teams. 
    • Design CI/CD pipelines in Azure DevOps and/or GitHub Actions: environment gates, drift detection, and pre-deployment compliance checks. 
    • Author automation in PowerShell, Azure CLI, and Python: bootstrap scripts, governance tooling, and operational runbooks. 

  • Observability, Resilience & FinOps 
    • Design observability platforms: Log Analytics workspace architecture, Azure Monitor, Workbook/dashboard frameworks, and alerting. 
    • Architect BCDR solutions with Azure Backup, Site Recovery, and cross-region topologies; validate against RTO/RPO targets. 
    • Lead FinOps efforts: tagging standards, Cost Management reporting, reservation/Savings Plans strategy, and optimization roadmaps. 

  • Consulting & Client Engagement 
    • Lead discovery workshops, design sessions, and Well-Architected Reviews; present architecture options with clear trade-offs to technical and business stakeholders. 
    • Stay hands-on throughout delivery: validate designs through working code and demonstrate patterns directly alongside client teams. 
    • Mentor delivery engineers through design reviews, pairing on complex problems, and code reviews. 
    • Architect enterprise-scale Azure Landing Zones aligned to CAF and Well-Architected principles: management groups, subscriptions, Azure Policy, RBAC, and platform automation. 
    • Design network topologies (hub-and-spoke or Virtual WAN): Azure Firewall, Application Gateway/WAF, Private Link, ExpressRoute/VPN, and DDoS Protection. 
    • Contribute to pre-sales: solution scoping, proposal authoring, SOW definition, and engagement estimates. 

You’re great at…

  • Architecting enterprise-scale Azure Landing Zones aligned to Cloud Adoption Framework and Well-Architected principles.
  • Leading cloud migration programs across various scenarios, including discovery and assessment.
  • Defining security blueprints and architecting Zero Trust models with Microsoft Entra ID and Defender for Cloud.
  • Building modular Infrastructure as Code frameworks (Terraform/Bicep) and designing CI/CD pipelines.
  • Leading FinOps efforts, designing observability platforms, and architecting robust business continuity solutions.
  • Packaging, deploying, and maintaining applications using Intune
  • Managing escalated technical issues while remaining calm, professional, and client-focused
  • Learning new technologies quickly and applying them in real-world scenarios
  • Providing technical thought leadership in Modern Workplace, system integration, and automation
  • Communicating complex technical concepts clearly to non-technical stakeholders
  • Working independently while owning deliverables and collaborating effectively with team members
  • Promoting the mission and shared values of the company

Sound interesting? If so, you’ll have…

  • 8+ years of hands-on experience architecting and delivering Azure solutions across networking, compute, storage, identity, and security. 
  • Proven experience leading Azure migration programs—on-premises, cloud-to-cloud, or application modernization—including assessment, wave planning, cutover, and stabilization. 
  • Proven delivery of enterprise Azure Landing Zones: management group design, Azure Policy, RBAC frameworks, and platform automation. 
  • Solid IaC experience in Terraform and/or Bicep with Azure DevOps or GitHub Actions CI/CD pipelines. 
  • Strong Azure networking fundamentals: hub-and-spoke or Virtual WAN, Azure Firewall, Application Gateway/WAF, Private Link, and ExpressRoute/VPN. 
  • Microsoft Entra ID experience: Conditional Access, PIM, hybrid identity, and Zero Trust concepts. 
  • Familiarity with Azure security services: Defender for Cloud, Microsoft Sentinel, Key Vault, and compliance frameworks. 
  • AVD experience: host pool design, FSLogix profiles, Scaling Plans, and monitoring. 
  • Proficiency in PowerShell and Azure CLI; Python is a plus. 
  • Strong analytical, problem-solving, and troubleshooting skills
  • Excellent written, verbal, and presentation skills
  • Strong client-facing skills, empathy, and the ability to guide clients through complex technical challenges
  • Ability to work independently, take ownership, and translate goals into actionable outcomes
  • Preferred qualifications include: 
    • Experience with tenant-to-tenant Microsoft 365 migrations: Exchange Online, SharePoint/OneDrive, Teams, and Entra ID coexistence and cutover. 
    • Microsoft 365 platform: Intune, Exchange Online, SharePoint/OneDrive, Teams, and Purview. 
    • Copilot readiness/governance, Copilot Studio development, and Microsoft Foundry experience. 
    • AKS/Kubernetes and cloud data platform experience (SQL MI, Cosmos DB, Synapse Analytics, or Fabric). 
    • Pre-sales and consulting delivery: scoping workshops, SOW authoring, and client relationship management. 
    • Microsoft Certified: Azure Solutions Architect Expert (AZ-305) 
    • Microsoft Certified: Azure Administrator Associate (AZ-104) 
    • Microsoft Certified: Azure Security Engineer Associate (AZ-500) or Cybersecurity Architect Expert (SC-100) 
    • Microsoft Certified: DevOps Engineer Expert (AZ-400) 
    • Microsoft Certified: Azure Network Engineer Associate (AZ-700) 
    • Microsoft 365 Certified (e.g., Enterprise Administrator Expert)

The Perks

We offer competitive pay and a comprehensive benefits package designed to support your health, flexibility, and long-term success. Benefits include generous paid time off, medical, dental and vision coverage, flexible spending accounts, a health reimbursement account, and a 401(k) plan with company match. You’ll also work alongside collaborative, driven teammates in a dynamic and growing professional services environment.

HSO is an Equal Opportunity Employer.

 

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...
Select...
Select...
Select...
Select...
Select...
Select...
Select...
Select...

U.S. Standard Demographic Questions

We invite applicants to share their demographic background. If you choose to complete this survey, your responses may be used to identify areas of improvement in our hiring process.
Select...
Select...
Select...
Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in HSO Group B.V.’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.