Haystack
← Back to Jobs
Technology

Senior Azure Cloud Architect

Neodym TechnologiesWashington, DC🇺🇸United StatesPosted 20 Jul 2026

Quick Overview

Work Type
Hybrid
Level
Mid Senior

Job Description

Role: Senior Azure Cloud Architect

Location: NEA Washington DC – Hybrid

Interview Type: MS Teams

Duration: 24 Months

 

Description:

Project Overview

The National Endowment for the Arts (NEA), Office of Information & Technology Management, operates and continues to modernize its enterprise environment on Microsoft Azure. The agency requires a Senior Azure Cloud Architect to own the design, governance, security posture, and migration of workloads across Azure compute, storage, networking, identity, data, and integration services.

This position specifically requires both deep hands-on Azure engineering and architecture-level design in a single individual. The Architect will produce reference architectures, diagrams, and architecture decision records that engineering teams can implement directly; define infrastructure as code standards for the team; lead architecture review boards and design authority meetings; and drive enterprise-scale landing zone design and governance aligned to the Microsoft Cloud Adoption Framework and the Azure Well-Architected Framework.

The Architect shall be adept at interpersonal communications, teamwork, goal setting, and business

process improvement, and shall be comfortable translating business requirements into technical designs and presenting solution designs and tradeoffs to CIOs, CTOs, and senior leadership.

 

Duties/Responsibilities

•       Work effectively with federal and contractor personnel to execute the project tasks;

•       Collaborate with NEA and other federal staff and contractors to refine and elaborate requirements;

•       Design enterprise-scale Azure solutions across compute services including Virtual Machines, VM Scale Sets, App Services, Azure Functions, Container Apps, AKS, and Azure Batch, selecting the right option for a given workload;

•       Architect advanced Azure networking spanning Virtual Networks, NSGs, UDRs, Private Endpoints, Load Balancer, Application Gateway, Azure Firewall, Front Door, Virtual WAN, ExpressRoute, and  VPN Gateway, including hub and spoke topologies and enterprise DNS strategy;

•       Design identity architecture using Microsoft Entra ID, including Conditional Access, Privileged Identity Management, B2B and B2C scenarios, federation with on-premises Active Directory, managed identities, and RBAC;

•       Apply the Azure Well-Architected Framework across reliability, security, cost optimization, operational excellence, and performance efficiency;

•       Implement Cloud Adoption Framework practices, including enterprise scale landing zone design and governance blueprints;

•       Design multi region, highly available, and disaster resilient solutions with defined recovery time and recovery point objectives;

•       Produce reference architectures, diagrams, and architecture decision records that an engineering team can implement directly;

•       Lead workload assessments using Azure Migrate and map applications to the five Rs of rehost, refactor, rearchitect, rebuild, and replace;

•       Perform wave planning for large scale datacenter exits, including dependency mapping and cutover planning;

•       Define infrastructure as code standards and repository structure for the team, and review and validate Bicep or Terraform code written by others;

•       Build and maintain CI/CD pipelines in Azure DevOps or GitHub Actions, including artifact management, secret scanning, and pipeline security hardening;

•       Implement release strategies including blue and green, canary, and ring based deployments;

•       Operate production AKS clusters, including upgrades, node pool management, and networking through Azure CNI or Calico, with Helm chart authoring and GitOps workflows using Flux or ArgoCD;

•       Implement security, compliance, and governance using Microsoft Defender for Cloud, Microsoft Sentinel, and Key Vault with secret rotation, together with Azure Policy, Management Groups, and Blueprints, applying Zero Trust principles across identity, network, and data layers;

•       Configure Azure Monitor, Log Analytics, and Application Insights, and author KQL queries for diagnostics, alerting, and dashboards;

•       Provide incident command, including root cause analysis and capacity planning at scale;

•       Drive FinOps practices using Azure Cost Management, reserved instances, savings plans, and rightsizing, and build total cost of ownership and return on investment models for executive stakeholders;

•       Lead a team of engineers, including task assignment and design reviews with clear, constructive feedback;

•       Lead architecture review boards and design authority meetings, and facilitate discovery workshops with business and technical stakeholders;

•       Mentor engineers and architects on design patterns and troubleshooting technique.

Required Education and Experience

•       Degree in Computer Science or related field.

•       Between 9 and 15 years of total IT experience, including at least 5 to 7 years of hands-on Azure engineering and at least 2 to 4 years operating at an architecture or technical leadership level.

•       A career path that progressed from hands-on engineering into architecture, since this position specifically requires both skill sets in one candidate.

•       Advanced, hands-on expertise across Azure compute services, including Virtual Machines, VM Scale Sets, App Services, Azure Functions, Container Apps, AKS, and Azure Batch.

•       Full lifecycle knowledge of Blob Storage, Azure Files, Managed Disks, and storage lifecycle management policies.

•       Advanced Azure networking experience at an enterprise level, including hub and spoke design and DNS strategy.

•       Identity expertise covering Microsoft Entra ID administration and architecture, including Conditional Access, Privileged Identity Management, B2B and B2C, federation, managed identities, and RBAC design.

•       Data platform experience across Azure SQL, Cosmos DB, PostgreSQL Flexible Server, Synapse Analytics, Microsoft Fabric, and Data Lake Storage, from both an administration and a solution design perspective.

•       Integration services knowledge including API Management, Service Bus, Event Grid, Event Hubs, and Logic Apps.

•       Deep mastery of the Azure Well-Architected Framework and fluency with the Cloud Adoption Framework.

•       Expert level, hands-on proficiency in Bicep or Terraform, including module design, state management, and reusable patterns.

•       Working knowledge of ARM templates for legacy or complex deployments.

•       Strong scripting ability in PowerShell, Bash, and Python for automation and validation.

•       Production experience operating AKS, including upgrades, node pool management, and networking through Azure CNI or Calico.

•       Hands-on experience with Microsoft Defender for Cloud, Microsoft Sentinel, and Key Vault, including secret rotation practices.

•       Governance design using Azure Policy, Management Groups, and Blueprints.

•       Advanced configuration of Azure Monitor, Log Analytics, and Application Insights, with strong KQL query writing.

•       Practical experience with Azure Cost Management, reserved instances, savings plans, and rightsizing.

•       Clear written and verbal communication, including polished design documentation, with strong stakeholder management, negotiation, and the ability to influence without direct authority.

Preferred Qualifications

•       Background in Windows Server, Linux administration, or virtualization platforms such as VMware, which is valuable for migration and hybrid scenarios.

•       Exposure to a regulated industry such as financial services, healthcare, or government.

•       Hybrid architecture experience using Azure Arc, Azure Stack HCI, and Azure Stack Edge.

•       Application modernization expertise, including microservices, event driven architectures, serverless patterns, and strangler fig migrations.

•       Familiarity with relevant frameworks such as the CIS Azure Benchmark, NIST 800-53, FedRAMP, HIPAA, or PCI DSS.

•       Working knowledge of service mesh concepts through Istio or Open Service Mesh.

 

Skills

Microservices
SQL
PCI DSS
Service Mesh
Active Directory
ArgoCD
Azure
Bash
DNS
GitHub Actions
HIPAA
Helm
Istio
PostgreSQL
PowerShell
Python
Stakeholder Management
Terraform
VMware
Vault
Zero Trust

Similar jobs