Ernst and Young

Azure Cloud Architect

Ernst and Young
Apply
17 hours ago
Timişoara, RomaniaSenior

Responsibilities

  • Design, deploy, and maintain Microsoft Azure cloud infrastructure using Infrastructure as Code, preferably Terraform.
  • Build and enhance Azure Landing Zones, management group hierarchies, subscription governance, and platform foundations.
  • Implement Azure governance controls using Azure Policy, RBAC, Management Groups, and Policy as Code.
  • Assess existing Azure environments and recommend improvements in security, scalability, reliability, performance, and cost management.
  • Integrate security controls into the software delivery lifecycle using DevSecOps principles.
  • Develop and maintain CI/CD pipelines using Azure DevOps, GitHub Actions, or similar platforms.
  • Support cloud migration and modernization initiatives, including rehosting, re-platforming, and cloud-native transformations.
  • Manage Terraform modules, remote state, reusable infrastructure patterns, and deployment standards.
  • Implement monitoring, observability, logging, and operational controls using Azure Monitor, Log Analytics, and related services.
  • Collaborate with security, networking, platform, and application teams to establish Azure cloud best practices.

Requirements

  • 10+ years of experience in DevOps, Cloud Engineering, Platform Engineering, or Infrastructure Engineering.
  • Strong hands-on experience with Microsoft Azure services, including Virtual Networks, Virtual Machines, Storage, Key Vault, App Services, Monitor, Log Analytics, DNS, Private Endpoints, RBAC, and Entra ID integration.
  • Proven experience implementing Infrastructure as Code with Terraform.
  • Experience designing and implementing Azure Landing Zones and enterprise-scale Azure governance.
  • Strong knowledge of Azure Management Groups, Azure Policy, subscription vending, and governance frameworks.
  • Experience building and managing CI/CD pipelines with Azure DevOps and/or GitHub Actions.
  • Experience supporting Azure migration and modernization projects.
  • Strong knowledge of Azure security services and practices, including Microsoft Defender for Cloud, Key Vault, Managed Identities, Private Link, Network Security Groups, Just-In-Time Access, and Zero Trust principles.
  • Strong troubleshooting, analytical, problem-solving, communication, and stakeholder management skills.
  • Preferred Microsoft certifications include Azure DevOps Engineer Expert, Azure Solutions Architect Expert, Azure Security Engineer Associate, and Azure Administrator Associate.
  • Preferred experience includes Azure Landing Zone implementations, Spacelift or other IaC orchestration platforms, Policy as Code, compliance automation, security monitoring, Docker, Kubernetes, AKS, AWS, GCP, hybrid or multicloud environments, FinOps, and regulated enterprise environments.
Ernst and Young

About Ernst and Young

10,000+ employees

Ernst & Young (EY) provides audit/assurance, tax, consulting, strategy and transactions services to enterprises, financial institutions, and public‑sector clients. Structured as a global network of partner‑owned member firms, it sells professional services on a fee basis, including a dedicated Financial Services Organization for banking, insurance, and capital markets. Headquartered in London, EY was formed in 1989 from the merger of Ernst & Whinney and Arthur Young, and operates in 150+ countries.

Contact me