Cloud Security Architect
⚲ Warsaw
Do uzgodnienia
Wymagania
- Documentation
- Network
- Security
- Python
- Artificial Intelligence (AI)
- Provisioning
- CI/CD
- Testing
- Cloud
- Microsoft Azure
Opis stanowiska
PROJECT INFORMATION:
Industry: Healthcare/ Pharmacy
Start: ASAP (flexible).
Rate: depending on experience.
Contract: B2B 12 months + prolongations.
Remote: up to 100%
Location: remote/ Warsaw.
Project language: English.
Business trips: some occasional included.
Recruitment process: 2 interviews.
Job Description
We are looking for a Staff Cloud Security Architect, AI Solutions to design and enable secure Azure-based architectures for AI applications that consume enterprise data from platforms such as Databricks.
This is a hands-on role for someone who can define architecture, security patterns, and technical standards while also working directly with engineering teams to implement them. The role is not primarily a Databricks platform architect role; the focus is on secure cloud architecture, AI application infrastructure, DevOps modernization, and compliant engineering foundations.
The architect will help teams build secure, scalable, and well-governed AI-enabled applications on Azure. This includes patterns for AI agents, sandboxed code execution, runtime isolation, network segregation, secrets management, CI/CD, Terraform, and GitHub Enterprise.
This role owns architectural design and technical standards but is not accountable for platform or application delivery.
The applications are currently non-GxP, but the architecture should support future GxP validation through traceability, controlled releases, documentation, and audit-ready engineering practices.
Significant experience in cloud architecture, cloud security architecture, platform engineering, or senior cloud engineering roles is required. The role demands proven hands-on experience designing and implementing secure Azure solutions and supporting engineering teams in building production-ready cloud applications.
Main Responsibilities
• Design secure Azure cloud architectures for AI applications, data-driven applications, and internal digital products.
• Define architecture patterns for AI applications that consume data from Databricks and other enterprise data platforms.
• Establish secure patterns for AI agents, sandboxed Python/code execution, runtime isolation, network segregation, and controlled access to data and services.
• Design and implement standards for secrets management, identity, access control, encryption, logging, monitoring, and secure connectivity.
• Use Terraform to define, review, and enable repeatable cloud infrastructure patterns.
• Help drive the migration from Azure DevOps to GitHub Enterprise.
• Establish new GitHub-based CI/CD patterns, including repository standards, branching, pull requests, code reviews, automated testing, approvals, deployment gates, and release evidence.
• Define technical standards for secure software delivery, release traceability, and audit-ready engineering practices.
• Partner with engineering teams to implement reference architectures, reusable templates, pipelines, and secure cloud patterns.
• Review solution designs, identify security risks, and guide teams toward practical, compliant, and maintainable implementations.
• Collaborate with cloud, security, data, AI, quality, compliance, and product teams.
• Mentor engineers and improve engineering practices across cloud, security, DevOps, and AI infrastructure.
Key Requirements
• Strong hands-on experience with Microsoft Azure cloud architecture.
• Strong cloud security expertise, including identity, networking, encryption, secrets management, logging, monitoring, and secure access patterns.
• Experience designing secure infrastructure for AI applications, AI agents, APIs, data-consuming applications, or internal developer platforms.
• Experience with sandboxed code execution, Python runtime environments, containerized workloads, or isolated compute patterns.
• Strong knowledge of network segregation, private endpoints, firewalls, virtual networks, controlled egress, and runtime isolation.
• Strong experience with Terraform for infrastructure provisioning and cloud architecture enablement.
• Strong experience with GitHub Enterprise, GitHub Actions, repository governance, branch protection, pull requests, and secure CI/CD patterns.
• Experience with Azure DevOps, ideally including migration from Azure DevOps to GitHub.
• Experience with secrets management, key vaults, managed identities, service principals, RBAC, and Microsoft Entra ID.
• Understanding of secure software delivery, release controls, traceability, and audit-ready engineering practices.
• Ability to work hands-on with engineers while also setting architecture direction and technical standards.
• A Bachelor’s degree in Computer Science, Software Engineering, Information Technology, Cybersecurity, Engineering, Mathematics, or equivalent practical experience is mandatory.
Nice to Have
• Experience with Azure AI services, Azure OpenAI, agent frameworks, or secure GenAI application patterns.
• Experience with Databricks as a data source for downstream applications.
• Experience with containers, Kubernetes, Azure Container Apps, Azure Functions, or similar runtime platforms.
• Experience with GitHub Advanced Security, code scanning, secret scanning, dependency scanning, or policy-as-code.
• Familiarity with life sciences, pharmaceuticals, healthcare, or another regulated industry.
• Understanding of GxP, CSV, CSA, SDLC controls, or validation documentation, especially for future validation readiness.
• Preferred Master’s degree in a relevant technical field, along with certifications like Microsoft Certified: Azure Solutions Architect Expert, Microsoft Certified: Azure Security Engineer Associate, Microsoft Certified: DevOps Engineer Expert, GitHub Actions or GitHub Advanced Security certification, and HashiCorp Terraform certification.
Industry: Healthcare/ Pharmacy
Start: ASAP (flexible).
Rate: depending on experience.
Contract: B2B 12 months + prolongations.
Remote: up to 100%
Location: remote/ Warsaw.
Project language: English.
Business trips: some occasional included.
Recruitment process: 2 interviews.
Job Description
We are looking for a Staff Cloud Security Architect, AI Solutions to design and enable secure Azure-based architectures for AI applications that consume enterprise data from platforms such as Databricks.
This is a hands-on role for someone who can define architecture, security patterns, and technical standards while also working directly with engineering teams to implement them. The role is not primarily a Databricks platform architect role; the focus is on secure cloud architecture, AI application infrastructure, DevOps modernization, and compliant engineering foundations.
The architect will help teams build secure, scalable, and well-governed AI-enabled applications on Azure. This includes patterns for AI agents, sandboxed code execution, runtime isolation, network segregation, secrets management, CI/CD, Terraform, and GitHub Enterprise.
This role owns architectural design and technical standards but is not accountable for platform or application delivery.
The applications are currently non-GxP, but the architecture should support future GxP validation through traceability, controlled releases, documentation, and audit-ready engineering practices.
Significant experience in cloud architecture, cloud security architecture, platform engineering, or senior cloud engineering roles is required. The role demands proven hands-on experience designing and implementing secure Azure solutions and supporting engineering teams in building production-ready cloud applications.
Main Responsibilities
• Design secure Azure cloud architectures for AI applications, data-driven applications, and internal digital products.
• Define architecture patterns for AI applications that consume data from Databricks and other enterprise data platforms.
• Establish secure patterns for AI agents, sandboxed Python/code execution, runtime isolation, network segregation, and controlled access to data and services.
• Design and implement standards for secrets management, identity, access control, encryption, logging, monitoring, and secure connectivity.
• Use Terraform to define, review, and enable repeatable cloud infrastructure patterns.
• Help drive the migration from Azure DevOps to GitHub Enterprise.
• Establish new GitHub-based CI/CD patterns, including repository standards, branching, pull requests, code reviews, automated testing, approvals, deployment gates, and release evidence.
• Define technical standards for secure software delivery, release traceability, and audit-ready engineering practices.
• Partner with engineering teams to implement reference architectures, reusable templates, pipelines, and secure cloud patterns.
• Review solution designs, identify security risks, and guide teams toward practical, compliant, and maintainable implementations.
• Collaborate with cloud, security, data, AI, quality, compliance, and product teams.
• Mentor engineers and improve engineering practices across cloud, security, DevOps, and AI infrastructure.
Key Requirements
• Strong hands-on experience with Microsoft Azure cloud architecture.
• Strong cloud security expertise, including identity, networking, encryption, secrets management, logging, monitoring, and secure access patterns.
• Experience designing secure infrastructure for AI applications, AI agents, APIs, data-consuming applications, or internal developer platforms.
• Experience with sandboxed code execution, Python runtime environments, containerized workloads, or isolated compute patterns.
• Strong knowledge of network segregation, private endpoints, firewalls, virtual networks, controlled egress, and runtime isolation.
• Strong experience with Terraform for infrastructure provisioning and cloud architecture enablement.
• Strong experience with GitHub Enterprise, GitHub Actions, repository governance, branch protection, pull requests, and secure CI/CD patterns.
• Experience with Azure DevOps, ideally including migration from Azure DevOps to GitHub.
• Experience with secrets management, key vaults, managed identities, service principals, RBAC, and Microsoft Entra ID.
• Understanding of secure software delivery, release controls, traceability, and audit-ready engineering practices.
• Ability to work hands-on with engineers while also setting architecture direction and technical standards.
• A Bachelor’s degree in Computer Science, Software Engineering, Information Technology, Cybersecurity, Engineering, Mathematics, or equivalent practical experience is mandatory.
Nice to Have
• Experience with Azure AI services, Azure OpenAI, agent frameworks, or secure GenAI application patterns.
• Experience with Databricks as a data source for downstream applications.
• Experience with containers, Kubernetes, Azure Container Apps, Azure Functions, or similar runtime platforms.
• Experience with GitHub Advanced Security, code scanning, secret scanning, dependency scanning, or policy-as-code.
• Familiarity with life sciences, pharmaceuticals, healthcare, or another regulated industry.
• Understanding of GxP, CSV, CSA, SDLC controls, or validation documentation, especially for future validation readiness.
• Preferred Master’s degree in a relevant technical field, along with certifications like Microsoft Certified: Azure Solutions Architect Expert, Microsoft Certified: Azure Security Engineer Associate, Microsoft Certified: DevOps Engineer Expert, GitHub Actions or GitHub Advanced Security certification, and HashiCorp Terraform certification.
🔍 Dekoder Ogłoszenia
🔴
Rate: depending on experience.
Stawka będzie negocjowana, ale prawdopodobnie nie będzie najwyższa na rynku, jeśli nie masz bardzo specyficznych i poszukiwanych umiejętności.
🔴
Contract: B2B 12 months + prolongations.
Umowa jest na czas określony, a przedłużenia nie są gwarantowane, mimo że są sugerowane.
🔴
Business trips: some occasional included.
Może to oznaczać sporadyczne wyjazdy, ale również częstsze, jeśli projekt tego wymaga i nie jest to jasno określone.
🔴
This role owns architectural design and technical standards but is not accountable for platform or application delivery.
Będziesz odpowiedzialny za projektowanie i standardy, ale nie za faktyczne dostarczenie działającego produktu, co może oznaczać brak wpływu na ostateczny kształt rozwiązania.
🟡
The applications are currently non-GxP, but the architecture should support future GxP validation through traceability, controlled releases, documentation, and audit-ready engineering practices.
Obecnie nie ma rygorystycznych wymagań GxP, ale będziesz musiał projektować z myślą o przyszłych, potencjalnie bardziej złożonych i czasochłonnych procesach walidacyjnych.