Microsoft Azure Technical Architect
Department: IT Infrastructure / Cloud Engineering
Reports To: Head of Infrastructure / IT Director
Employment Type: Full-Time
Role Summary
We are looking for an experienced Technical Architect with deep expertise in Active Directory (AD) and Microsoft Azure to design, implement, and govern our identity, directory, and cloud infrastructure. This role will lead architecture decisions across on-premises AD, Azure AD (Entra ID), hybrid identity, and Azure cloud infrastructure, ensuring security, scalability, and operational excellence.
Key Responsibilities
-
Design and implement enterprise-scale Active Directory architecture, including domains, forests, trusts, OU structures, Group Policy, and DNS/DHCP integration.
-
Architect hybrid identity solutions using Azure AD Connect / Entra Connect, ADFS, and Azure AD (Entra ID), ensuring seamless synchronization and authentication across on-prem and cloud environments.
-
Lead Azure infrastructure architecture including virtual networks, subnets, NSGs, ExpressRoute/VPN connectivity, Azure Virtual Desktop, and resource governance (management groups, policies, blueprints).
-
Define and enforce identity security best practices: conditional access, MFA, privileged identity management (PIM), role-based access control (RBAC), and Zero Trust principles.
-
Own AD and Azure disaster recovery, backup, and business continuity strategies.
-
Provide technical leadership on Azure migration projects (lift-and-shift, re-platforming) and AD consolidation/modernization initiatives.
-
Collaborate with security teams on identity governance, audit, compliance (SOX, ISO 27001, NIST, etc.), and incident response related to directory services.
-
Create architecture documentation, standards, and reference designs; review and approve infrastructure changes.
-
Mentor engineering teams and provide guidance on AD/Azure operational issues and escalations.
-
Evaluate emerging Microsoft technologies (Entra ID governance, Defender for Identity, Azure Arc, etc.) and recommend adoption where relevant.
Required Qualifications
-
Bachelor's degree in Computer Science, Information Technology, or related field (or equivalent experience).
-
5+ years of experience in IT infrastructure, with 5+ years focused on Azure architecture.
-
Deep hands-on expertise with Active Directory Domain Services (AD DS), Group Policy, DNS, and DHCP.
-
Deep hands-on expertise with Azure AD / Microsoft Entra ID and hybrid identity (Azure AD Connect, ADFS).
-
Deep hands-on expertise with Azure networking, compute, storage, and governance services.
-
Deep hands-on expertise with Conditional Access, MFA, PIM, and identity security tooling.
-
Proven experience architecting and executing AD-to-Azure migrations or hybrid environments.
-
Strong understanding of security frameworks and compliance requirements related to identity management.
-
Experience with PowerShell scripting for automation of AD/Azure tasks.
-
Excellent communication skills with ability to translate technical designs into business-friendly language.
Preferred Qualifications
-
Microsoft certifications: Azure Solutions Architect Expert, SC-300 (Identity and Access Administrator), or equivalent.
-
Experience with Microsoft Defender for Identity, Microsoft Sentinel, or other security monitoring tools.
-
Familiarity with Infrastructure-as-Code (Terraform, Bicep, ARM templates).
-
Experience in multi-forest, multi-domain enterprise environments.
-
Knowledge of Azure Virtual Desktop, Intune, and endpoint management.
Key Competencies
-
Strategic architectural thinking with attention to security and scalability.
-
Strong problem-solving and troubleshooting skills in complex hybrid environments.
-
Ability to lead cross-functional technical initiatives.
-
Documentation discipline and stakeholder communication.