
Cloud Security & AI Solutions Architect
Ernst and Young7 days ago
Katowice, PolandMid Level
Responsibilities
- Design secure cloud architectures in Microsoft Azure or AWS for AI applications, analytics platforms, and enterprise digital products.
- Define reference architectures and security patterns for AI solutions, AI agents, sandboxed code execution, runtime isolation, network segmentation, and controlled access.
- Establish standards for identity management, secrets management, encryption, zero-trust access, secure connectivity, logging, monitoring, and auditing.
- Define and maintain Infrastructure as Code standards using Terraform, Bicep, or ARM.
- Lead and support migrations to Azure DevOps or GitHub Enterprise.
- Establish secure CI/CD practices covering repository governance, branching, pull requests, automated testing, release controls, deployment approvals, traceability, and audit readiness.
- Deliver reusable templates, secure pipelines, and reference cloud architectures with engineering teams.
- Conduct architecture and design reviews, identify risks, and recommend secure, scalable, maintainable solutions.
- Collaborate with cloud, security, AI, data, quality engineering, compliance, and product teams.
- Mentor engineers and drive adoption of engineering practices across cloud, security, DevOps, and AI infrastructure.
Requirements
- Bachelor’s degree in IT, Computer Science, Computer Engineering, Cybersecurity, Information Systems, or a relevant discipline.
- At least 3 years of practical experience designing solutions in Microsoft Azure or Amazon AWS Cloud.
- At least 1 year of experience building or securing AI solutions.
- Strong cloud security expertise covering identity, networking, encryption, secrets management, logging, monitoring, and secure access patterns.
- Experience designing secure infrastructure for AI applications, AI agents, APIs, data-consuming applications, or internal developer platforms.
- Knowledge of network segregation, private endpoints, firewalls, virtual networks, controlled egress, and runtime isolation.
- Experience with Terraform, ARM, or Bicep for infrastructure provisioning and cloud architecture enablement.
- Experience with GitHub Enterprise, GitHub Actions, repository governance, branch protection, pull requests, and secure CI/CD patterns.
- Experience with Azure DevOps, preferably including migration from Azure DevOps to GitHub.
- Experience with Azure AI services, Azure OpenAI, Azure AI Foundry, agent frameworks, or secure GenAI application patterns.
- Experience with Databricks as a data source for downstream applications.
- Experience with containers, Kubernetes, Azure Container Apps, Azure Functions, or similar runtime platforms.
- Experience with GitHub Advanced Security, code scanning, secret scanning, dependency scanning, or policy-as-code.
- Preferred experience includes sandboxed code execution, Python runtime environments, containerized workloads, isolated compute patterns, Entra ID, managed identities, service principals, RBAC, and Snowflake.
- Relevant certifications such as Microsoft Azure Solutions Architect Expert, Azure Security Engineer Associate, DevOps Engineer Expert, AWS Certified Solutions Architect, GitHub Actions or GitHub Advanced Security, or HashiCorp Terraform certifications are advantageous.
- Ability to work hands-on with engineers while setting architecture direction and technical standards.
Benefits
- Hybrid work arrangement in Katowice with 2 days in the office and 3 days remote.
- Continuous learning through coaching and training programs.
- Tools and flexibility to make a meaningful impact and define success personally.
- Transformative leadership through insights, coaching, and confidence-building.
- Diverse and inclusive culture with opportunities to collaborate across EY’s global delivery network.
- Global projects, cross-functional collaboration, mentoring, and access to an extensive professional network.