Azure Cloud Security Architect / Infrastructure - Remote
Requisition Name: Azure Cloud Security Architect
Start Date: 10/5/2026
Duration: 64 Weeks
Services Location: WY/Remote
Description Of Services:
Joint workshops with Cloud/Infra to define security guardrails feeding the landing zone design: identity model, network segmentation principles, logging/retention requirements, encryption standards, tagging and policy strategy.
Review Management Group hierarchy, subscription structure, custom RBAC role definitions, PIM eligible/active role design, and break-glass account setup proposed by Cloud/Infra for each tenant.
Validate hub-spoke topology, NSG/ASG rule sets, firewall placement, private endpoint usage, DDoS protection plan, and DNS architecture against security baseline.
Review and validate Azure Policy initiatives (deny public IP, enforce encryption at rest/in transit, allowed resource types/regions, mandatory tagging) assigned at each Management Group/subscription scope.
Validate the central Log Analytics workspace design, diagnostic settings scope (which resource types forward logs), retention periods, and confirm the workspace is correctly positioned for Sentinel onboarding.
Review Key Vault architecture (per-subscription vaults, RBAC vs. access policies, soft-delete/purge protection, private endpoint access) proposed for each landing zone.
Score each subscription tier (Prod/Non-Prod/Identity/Connectivity) against Azure Security Benchmark / CIS controls; issue formal security sign-off or a remediation list back to Cloud/Infra before tool deployment begins.