Azure Cloud ArchitectEnterprise Architecture & Landing Zone Design and implement enterprise-grade Azure Landing Zones aligned with: o Microsoft Cloud Adoption Framework (CAF) o Azure Enterprise-Scale Architecture o Zero Trust Security Model Define and implement: o Management Groups hierarchy o Subscription strategy and lifecycle management o Resource organization standards o Naming conventions and tagging strategy o RBAC and identity governance o Policy-driven governance and compliance Establish multi-subscription, multi-environment (Prod/Non-Prod/Sandbox) architecture. ________________________________________ Azure Networking Architect secure and scalable network topologies: o Hub-and-Spoke / Virtual WAN architectures o ExpressRoute and Site-to-Site VPN connectivity o Private Endpoints and Private DNS Zones o Azure Firewall, NSGs, ASGs, Route Tables o Load Balancers, Application Gateway, Front Door Design IP addressing strategy and network segmentation. Implement network security controls and traffic inspection models. Optimize network performance, availability, and resiliency. ________________________________________ Azure Security & Governance Implement enterprise security posture using: o Microsoft Defender for Cloud o Azure Policy and Initiative assignments o Azure Blueprints (where applicable) o Conditional Access and Identity Protection o Privileged Identity Management (PIM) Design secure identity architecture using: o Entra ID (Azure AD) o RBAC models and least-privilege access o Managed Identities Ensure compliance with regulatory standards (ISO, SOC2, CIS, NIST as applicable). Establish logging, monitoring, SIEM integration, and audit controls. ________________________________________ Infrastructure as Code & Automation Develop reusable, modular Infrastructure-as-Code using: o Terraform (preferred) and/or Bicep Create standardized deployment pipelines using: o Azure DevOps / GitHub Actions Implement CI/CD practices for infrastructure delivery. Enforce version control, peer reviews, testing, and promotion pipelines. Automate provisioning, governance, security baselines, and guardrails. ________________________________________ Operations, Reliability & Cost Management Design for: o High availability and disaster recovery o Backup and recovery o Scalability and performance optimization Implement observability using: o Azure Monitor, Log Analytics, Application Insights Enable cost governance: o Cost Management + Billing o Budgeting and chargeback/showback models o Rightsizing and optimization ________________________________________ Stakeholder Engagement & Leadership Translate business requirements into technical architecture. Produce high-quality architecture documentation, diagrams, and runbooks. Lead technical discussions with customers, auditors, security teams, and delivery teams. Mentor junior engineers and promote engineering excellence. Participate in design reviews, audits, and governance forums. ________________________________________ Required Skills & Qualifications Technical Skills Strong hands-on expertise with: o Microsoft Azure platform (IaaS, PaaS, Networking, Security) o Azure Landing Zone design and deployment o Enterprise networking architectures o Identity and access management o Azure security tooling and governance Expert-level proficiency in: o Terraform and/or Bicep o Git-based workflows o CI/CD pipelines for infrastructure Deep knowledge of: o TCP/IP, DNS, routing, firewall concepts o Hybrid connectivity models o Cloud security best practices o Infrastructure automation patterns Experience working in multi-subscription, enterprise environments.
We are seeking a highly skilled Senior Azure Cloud Architect with deep expertise in Azure Networking, Azure Security, and Enterprise-scale Landing Zone architecture. The candidate will be responsible for designing, building, securing, and operating production-grade Azure environments aligned with Microsoft Cloud Adoption Framework (CAF) and Well-Architected Framework principles. The role requires hands-on mastery of Infrastructure as Code (Terraform and/or Bicep), automation, governance, identity, security controls, and scalable network design. The individual will also serve as a technical advisor to stakeholders, lead cloud transformation initiatives, and mentor engineering teams. Strong communication, stakeholder management, documentation, and presentation skills are mandatory.

Keyskills: bicep Architecture Terraform Azure Cloud CAF
Barclaycard Payments, part of Barclays, specializes in merchant services and payment processing, offering secure solutions for card transactions and digital commerce. Careers span operations, product, risk, and technology, underscoring its mission to deliver scalable, innovative payment infrastructu...