Apply Edge Start your job search

Infrastructure Architect (Azure)

oryxsearch.io · Abu Dhabi, Abu Dhabi Emirate, United Arab Emirates

Apply & track with Apply Edge

Infrastructure Architect (Azure) Azure Cloud

Location: Abu Dhabi, United Arab EmiratesTeam: Cloud Platform TeamReports to: Head of Cloud Platform / Director of InfrastructureRole OverviewOur client is a large, highly regulated organisation based in Abu Dhabi seeking an experienced Infrastructure Architect to join its Cloud Platform team.You will own the design, build and governance of the Azure foundations that delivery teams across the organisation build on, including subscriptions, networking, firewall and WAF, AKS, and the underlying logging and SIEM estate.This is a hands-on architecture role.

You will produce high-level and low-level designs, deliver them as Infrastructure as Code alongside engineering teams, and ensure the platform operates reliably and securely in production.The wider technology estate includes on-premises infrastructure, databases and middleware. Experience designing highly available and disaster-resilient architectures across complex hybrid environments, while providing technical leadership to engineering teams, will be highly valued.Key ResponsibilitiesAzure Subscriptions & GovernanceManage Azure subscriptions, management groups and resource groups within an enterprise landing-zone model, enforcing naming, tagging, Azure Policy and RBAC standards.Govern platform identity through Entra ID, including managed identities, service principals and PIM.Monitor and optimise Azure cost, utilisation and capacity.Networking, Firewall & WAFDefine VNets, subnets, IP address plans, peering and hub-and-spoke architectures.Design hybrid connectivity using ExpressRoute/VPN, routing, DNS and Private Link.Design, configure and operate Azure Firewall, including network/application rules, TLS inspection and IDPS.Own WAF policies across Application Gateway and Front Door, including OWASP rule tuning.Define network segmentation, DDoS protection, secure administrative access and firewall change-management processes.Produce comprehensive HLDs, LLDs and SOPs.Container Platform — AKS / KubernetesDefine AKS reference architectures and hosting standards covering private clusters, node pools, networking, ingress, network policies and workload identity.Harden AKS environments using image scanning, admission policies, Defender for Containers and Key Vault integration.Support and guide migrations from existing container platforms onto AKS.Logging, Monitoring & SIEMArchitect the observability stack using Azure Monitor and Log Analytics, including workspace architecture, retention and cost management.Define SLO/SLI-based monitoring and alerting for critical services.Design and operate Microsoft Sentinel or equivalent SIEM platforms.Ensure firewall, WAF, AKS, identity and database logs are centrally collected and retained in accordance with security and audit requirements.Infrastructure as CodeBuild and maintain Terraform and/or Bicep for platform components, including reusable modules, remote state, environment promotion and drift detection.Deliver infrastructure through automated CI/CD pipelines.Establish IaC and policy-as-code standards using technologies such as Azure Policy, Checkov and tfsec.Automate operational processes using PowerShell, Bash or Python.Resilience & Technical LeadershipArchitect HA and DR across infrastructure, databases and middleware.Lead periodic DR exercises, L3 incident escalations and root-cause analysis.Review project architectures against platform standards and provide architecture sign-off.Mentor infrastructure, cloud and DevOps engineers.Essential Skills & Experience12+ years of experience across infrastructure and/or cloud architecture, including 5+ years designing and operating Azure at enterprise scale.Strong combination of architecture and hands-on engineering experience — candidates should have personally designed, built, configured and operated Azure environments.Proven experience managing Azure subscriptions, RBAC, Azure Policy and Entra ID within enterprise landing-zone architectures.Deep Azure networking expertise covering VNets, peering, hub-and-spoke, ExpressRoute/VPN, Private Link, DNS, NSGs and load balancing.Strong experience configuring and tuning Azure Firewall and WAF.Production experience architecting and operating Kubernetes/AKS, including networking, security hardening and upgrades.Experience designing centralised logging and SIEM platforms using Azure Monitor, Log Analytics, Microsoft Sentinel, Splunk or equivalent.Strong Terraform and/or Bicep capabilities alongside PowerShell, Bash or Python.Experience producing HLD/LLD documentation and designing and testing HA/DR solutions.Excellent stakeholder communication skills and experience leading technical teams within large, complex environments.Desirable Skills & ExperienceExperience within government, financial services, critical infrastructure or another highly regulated environment.Familiarity with recognised information-security standards and regulatory frameworks.Experience across hybrid or multi-cloud estates including OCI, AWS, VMware or OpenShift.Defender for Cloud, Key Vault, certificate lifecycle management and zero-trust networking.API Management and Redis within microservices architectures.Exposure to GPU/AI workloads within Azure, including GPU VM SKUs, AKS GPU node pools and Azure OpenAI.Relevant certifications such as Azure Solutions Architect Expert (AZ-305), AZ-700, AZ-500, CKA, HashiCorp Terraform Associate, CISSP or CCSP.Other RequirementsAbility to obtain and maintain any security clearance required for sensitive workloads.Based in, or willing to relocate to, Abu Dhabi, UAE.Willingness to participate in an on-call rotation and support occasional out-of-hours changes and disaster-recovery exercises.

Location: Abu Dhabi, UAE (on-site)