MS + Azure Architect

VSG Business Solutions•Dallas, TX
•Onsite

About The Position

This role focuses on Security & Landing Zone Design within the MS + Azure ecosystem. The architect will lead workshops to define security guardrails for the landing zone, including identity models, network segmentation, logging, encryption, tagging, and policy strategy. They will also review governance structures, network topology, policy enforcement, logging and monitoring configurations, and secrets management. The role involves auditing subscriptions against security benchmarks, issuing sign-offs, and providing mentorship to client teams. Key deliverables include process flows, architecture diagrams, and technical documentation.

Requirements

  • Expert/Advanced experience with MS + Azure Architect.
  • Expert/Advanced experience with Azure Cloud Security Architect.
  • Expert/Advanced experience with Infrastructure.
  • Expert/Advanced experience with Azure Sentinel / Log Analytics.
  • Expert/Advanced experience with Azure Policy & RBAC / PIM.
  • Hands-on experience designing Azure security landing zones, hub-spoke network topologies, and RBAC/PIM governance models.
  • Prior experience executing all core duties outlined in the description of services (e.g., scoring against Azure Security Benchmark/CIS controls, configuring Azure Policy, Key Vault security).
  • Ability to work on-site 3 days a week (Tuesday through Thursday) in Dallas, TX.

Responsibilities

  • Lead joint workshops with Cloud/Infrastructure teams to define security guardrails feeding the landing zone design (identity model, network segmentation principles, logging/retention requirements, encryption standards, tagging, and policy strategy).
  • Review Management Group hierarchy, subscription structure, custom RBAC role definitions, PIM eligible/active role design, and break-glass account setup across all tenants.
  • Validate hub-spoke topology, NSG/ASG rule sets, firewall placement, private endpoint usage, DDoS protection plans, and DNS architecture against security baselines.
  • Validate Azure Policy initiatives (deny public IP, enforce encryption at rest/in transit, allowed resource types/regions, mandatory tagging) assigned at each Management Group and subscription scope.
  • Validate central Log Analytics workspace design, diagnostic settings scope across resource types, retention periods, and confirm workspace alignment for Sentinel onboarding.
  • Review Key Vault architecture (per-subscription vaults, RBAC vs. access policies, soft-delete/purge protection, private endpoints) per landing zone.
  • Score subscription tiers (Prod, Non-Prod, Identity, Connectivity) against Azure Security Benchmark / CIS controls; issue formal security sign-offs or remediation lists prior to tool deployment.
  • Provide mentorship and knowledge transfer to client project team members.
  • Author/co-author technical and security project deliverables.
  • Provide thought leadership and hands-on technical configuration/development.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service