Haystack
← Back to Jobs
Technology

Senior Azure Cloud Architect

kjohn@samrusystems.comBoston, MA🇺🇸United StatesPosted 6 Aug 2026

Quick Overview

Work Type
Hybrid
Level
Mid Senior

Job Description

Role Overview

We are looking for a Senior Azure Architect to lead the strategy, design, and execution of our enterprise cloud foundation. In this role, you will be responsible for building secure, enterprise-grade Azure Landing Zones, configuring hybrid identity and access management (Active Directory / Microsoft Entra ID), and executing large-scale workload migrations—with a strong focus on Azure VMware Solution (AVS / VMC on Azure).

You will bridge the gap between legacy VMware data center architecture and modern native cloud capabilities while ensuring rigorous security postures and seamless network routing.


Responsibilities

1. Azure Landing Zone & Architecture

·         Architect and operationalize enterprise-grade Azure Landing Zones aligning with Microsoft’s Cloud Adoption Framework (CAF).

·         Establish management groups, subscription topologies, resource naming/tagging standards, and operational governance.

·         Implement Infrastructure as Code (IaC) using Terraform or Bicep/ARM to automate subscription vends and policy enforcement.

2. VMware Migration (AVS / VMC on Azure)

·         Lead end-to-end design, sizing, deployment, and migration of legacy on-premises VMware environments to Azure VMware Solution (AVS).

·         Plan and execute migration strategies using VMware HCX (bulk migration, RAV, cold/warm vMotion, and L2 network extensions).

·         Configure VMware NSX-T network virtualizations, vSAN storage profiles, vCenter integrations, and host lifecycle configurations within Azure.

3. Hybrid Networking & Security

·         Design secure, high-availability hybrid networks using ExpressRoute, Azure Virtual WAN (vWAN), Hub-and-Spoke topologies, and Azure Route Server.

·         Integrate Network Virtual Appliances (NVAs), Palo Alto / Fortinet firewalls, Azure Firewall, and Network Security Groups (NSGs).

·         Enforce Zero-Trust architecture across cloud environments, including micro-segmentation with NSX-T and Azure security boundaries.

4. Identity & Access Governance (AD / Entra ID)

·         Design and maintain hybrid identity solutions integrating on-premises Active Directory Domain Services (AD DS) with Microsoft Entra ID (formerly Azure AD).

·         Implement Role-Based Access Control (RBAC), Entra ID Privileged Identity Management (PIM), Conditional Access, Managed Identities, and Azure Key Vault.

·         Ensure proper DNS routing and resolution between on-premises AD, Azure Private Endpoints, and AVS SDDC infrastructure.



Required Qualifications & Technical Skills

·         Azure Expertise: 4+ years of hands-on design and architectural leadership in Microsoft Azure (Virtual Networks, Subscriptions, Management Groups, Policy, Log Analytics).

·         VMware / AVS Mastery: Direct experience designing or migrating to Azure VMware Solution (AVS) or equivalent hybrid VMware platforms (e.g., VMC).

·         Migration Tooling: Hands-on mastery of VMware HCX, Azure Migrate, or Site Recovery Manager (SRM).

·         Networking & Virtualization: Deep knowledge of VMware NSX-T (firewalling, segment creation, BGP routing) and Azure networking (ExpressRoute Global Reach, UDRs, vWAN).

·         Identity & Security: Strong Active Directory, Microsoft Entra ID (SAML, OAuth, Conditional Access, MFA, RBAC), and cloud security baseline management.

·         Automation: Proficiency in IaC with Terraform, Bicep, PowerShell, or Azure CLI.

Skills

MFA
OAuth
SAML
Active Directory
Azure
DNS
PowerShell
Terraform
VMware
Vault

Similar jobs