Jobs and Careers
ME

Enterprise Cloud Security Architect- Azure

Merative
Remote – United States, United States, United StatesRemotefull_timeVerifiedPosted 9 Feb 2026
💰 $229,256/yr($152,837/yr$229,256/yr)

About the role

We are seeking an experienced Cloud Architect with strong expertise in Microsoft Azure, hybrid Active Directory, and enterprise identity and device management. This role will lead the design, implementation, and governance of secure, scalable cloud and hybrid environments, supporting both cloud-native and legacy systems while enabling modern workplace and identity solutions. The ideal candidate combines strategic architectural thinking with hands-on technical depth across Azure infrastructure, identity, endpoint management, and security.

Key Responsibilities 

Cloud & Infrastructure Architecture 

  • Design and maintain a Secure Cloud Architecture for IaaS, PaaS, and SaaS solutions with Microsoft security technologies such as Defender, Sentinel, Purview, Endpoint Management, and Entra ID to protect enterprise and client assets. 

  • Build and deploy security architecture that enforces Zero Trust principles across M365, tenants, Azure subscriptions, B2C tenants, enterprise virtual systems, landing zones, virtual desktops and devices.  

  • Establish security controls around DevOps, secrets management, key vaults, and managed identities to secure service to service patterns.  

  • Architect resilient, scalable, and cost-optimized cloud solutions using Azure best practices and risk-based spending alignment 

  • This role will own security architecture standards, reference architecture, guardrails, and exception decisions in partnership with the Chief Information Security Officer. 

 

Identity & Access Management 

  • Establish and enforce hardened identity management for identities including Entra ID, service principles, and workload identities while enforcing least-privilege across environments and mitigating path to privilege.  

  • Architect identity security using conditional access, MFA, phishing resistant authentication, Privileged Identity Management (PIM), and Zero Trust principles 

  • Design and integrate Privileged Access Management (PAM) tools in active directory environments which include both Windows and Linux to eliminate the use of interactive service accounts and password handling while providing secure privilege access management practices, automation, and secure service-to-service communications.  

  • Design and incorporate security best practice for device & endpoint management incorporating identity and access management with internet access restrictions supporting Windows, macOS, iOS, and Android devices.  
     

Security & Compliance 

<

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Merative

View company profile →