Experience:
5 to 10 yrs with IT company only.
Qualifications:
Bachelor degree education: B. Tech. in computer, computer science, information technology, or related field is required.
Role Overview:-
We are seeking a hands-on Cloud Architect who combines strategic architecture depth with practical engineering proficiency. You will be leading the architecture blueprints, building core Azure components, and driving data protection, identity, and governance automation through Microsoft Entra Suite and Purview.
This is a founding technical role — you’ll define patterns, build prototypes, and ensure every design decision enforces zero trust, data lineage, and cryptographic provenance.
Core Responsibilities
Solution Architecture & Engineering
- Architect end-to-end Data Trust Platform using Azure-native services.
- Design modular, scalable, and reliable architectures for document control, verifiable sharing, data consent, and provenance.
- Implement event-driven pipelines using Azure Functions, Service Bus, and Event Grid.
- Build multi-tenant secure API gateways (Azure API Management) with token-based authentication.
- Design and implement Zero-Trust Architecture:
- Integrate Entra Verified ID, Entra Permissions Management, Conditional Access, and Privileged Identity Management (PIM).
- Configure adaptive access policies, managed identities, and workload identities across systems and data stores.
- Deploy and harden cloud infrastructure using Infrastructure-as-Code (Bicep, Terraform, ARM) with security baselines.
- Integrate Key Vault, Confidential Ledger, and Confidential VMs to protect data at rest, in use, and in transit, including key and e-token storage for CI/CD pipelines.
- Automate data classification, lineage, and sensitivity tagging using Microsoft Purview SDKs and REST APIs.
- Utilize a PII reference system to isolate exposure to dedicated PII events.
Data Governance & Compliance
- Create and operationalize data policies and taxonomies across structured, unstructured, and semi-structured assets.
- Build dynamic data maps and lineage graphs in Purview with connectors to Azure SQL, Blob Storage, Synapse, and external SaaS platforms.
- Enable automatic data discovery and PII classification aligned with GDPR, DPDPA, ISO 27701, and the EU AI Act.
- Develop audit trail APIs for compliance reporting and incident traceability.
Security & Privacy Engineering
- Adopt encryption standards, manage HSM-backed keys, and enforce secret rotation across services.
- Embed privacy-by-design principles using Microsoft Information Protection SDKs.
- Implement data access governance using Purview Access Policies integrated with Entra roles.
- Build data egress and sovereignty controls to enforce geographical data boundaries.
DevSecOps & Automation
- Integrate security posture management with Defender for Cloud and Security Center APIs.
- Automate penetration testing and vulnerability testing.
- Integrate automated system test units into build and deployment strategies.
- Automate compliance scans and report generation.