Cloud Architect (AZURE)
Indexed description
Key skills: Azure orchestration, Kubernetes, Terraform, Git, Claude, Containerization, best practices, security
Senior Azure Application Architect
About the Environment
Veritiv Corporation is a leading North American distribution company running a large, complex Azure environment shaped by significant M&A activity — seven acquired entities, multiple inherited application portfolios, and a mandate to modernize. This role sits on the application side of the house, not infrastructure. You will be designing, governing, and modernizing the way applications are built and run in Azure — working closely with development teams, data engineering, and business stakeholders. You will also play a hands-on role in establishing standards, guiding deployments, and enforcing application security across the environment.
What You'll Do
Application Architecture & Design
- Own Azure application architecture across a complex, post-M&A environment — assessing the current application portfolio and defining a target-state modernization roadmap
- Design cloud-native architectures using Azure PaaS services — App Services, Azure Functions, API Management, Service Bus, Event Grid, and Logic Apps
- Establish and govern application design patterns — microservices, event-driven architecture, API-first, and containerized workloads — and ensure consistency across development teams
- Define integration architecture across internal systems, acquired-entity applications, and external partners
- Lead application rationalization decisions across the inherited M&A portfolio — consolidate, retire, rebuild, or retain
Orchestration, Containers & Kubernetes
- Architect and govern containerization strategy across the Azure environment — defining standards for image management, container security, and registry governance via Azure Container Registry (ACR)
- Design and manage Azure Kubernetes Service (AKS) clusters — including node pool design, autoscaling, namespace strategy, network policies, and workload scheduling
- Implement Kubernetes orchestration patterns for microservices deployments — Helm charts, Kustomize, pod disruption budgets, and horizontal pod autoscaling
- Define and enforce container security standards — image scanning, runtime policies, and secrets management via Azure Key Vault integration
- Evaluate and implement Azure Container Apps where appropriate as a managed orchestration alternative to full AKS
Infrastructure as Code & GitOps
- Define and enforce IaC standards using Terraform — every environment must be version-controlled, repeatable, and peer-reviewed before deployment
- Establish GitOps workflows using Git (GitHub or Azure Repos) as the single source of truth for application and infrastructure state
- Implement branch strategy, PR review gates, and policy enforcement as part of the deployment pipeline
- Govern environment promotion (dev → staging → production) through pipeline-enforced controls, not manual processes
- Integrate Terraform state management, module strategy, and drift detection into standard operating procedure
CI/CD & Deployment Standards
- Design and govern CI/CD pipeline standards using Azure DevOps and/or GitHub Actions — covering build, test, security scan, and release stages
- Establish deployment standards across the application portfolio — blue/green, canary, and rolling deployment patterns where appropriate
- Define and enforce pipeline security gates — static code analysis, dependency scanning, container image scanning, and secrets detection before any artifact reaches production
- Partner with development teams to adopt and maintain deployment standards consistently across teams and business units
AI-Assisted Development with Claude
- Integrate Claude (Anthropic) into the development workflow as an AI coding and architecture assistant — establishing standards for responsible and effective use across engineering teams
- Define guardrails for AI-assisted code generation — review requirements, security considerations, and quality gates before AI-generated code reaches production
- Champion the use of AI tooling to accelerate development velocity while maintaining code quality and security standards
- Stay current on Claude and broader AI coding assistant capabilities as they evolve, and advise leadership on adoption opportunities
Application Security
- Embed security into every layer of the application architecture — this is not a handoff to a security team, it is a core responsibility of this role
- Design application-level identity and authorization patterns using Azure Entra ID — app registrations, Managed Identities, service principals, OAuth2/OIDC flows, and API authorization policies
- Govern secrets management across all applications using Azure Key Vault — no hardcoded credentials, no exceptions
- Enforce secure pipeline practices — secrets scanning, SAST/DAST tooling, and dependency vulnerability checks integrated into every CI/CD pipeline
- Define and govern network-level application security — private endpoints, API Management policies, WAF rules, and ingress controller security for AKS workloads
- Lead threat modeling sessions for new application designs and major changes
Stakeholder Engagement & Standards
- Develop and maintain architecture standards documentation — patterns, guardrails, and decision records that teams can actually use
- Conduct architecture reviews for new projects and major changes — ensuring alignment to standards before development begins
- Translate business requirements into application architecture decisions and communicate tradeoffs clearly to senior IT leadership and C-suite stakeholders
- Partner closely with development teams, data engineering, and business unit leads across the Veritiv portfolio
What You Bring
Non-Negotiable Requirements
- 8+ years in software or solutions architecture with 5+ years designing and delivering applications on Azure
- Deep hands-on expertise with Azure PaaS application services: App Service, AKS, Azure Functions, API Management, Service Bus, Event Grid, Cosmos DB, Azure SQL
- Strong Kubernetes experience — AKS in production, Helm, networking, security, and autoscaling
- Containerization expertise — Docker, ACR, image lifecycle management, and container security
- Proficient in Terraform for IaC at enterprise scale — modules, state management, and pipeline integration
- Git fluency — GitOps workflows, branching strategy, PR governance, and pipeline-as-code
- Hands-on CI/CD experience with Azure DevOps and/or GitHub Actions
- Application security depth — Entra ID integration, Key Vault, secrets management, pipeline security gates, and network-level controls
- Microsoft Certified: Azure Solutions Architect Expert (AZ-305) — required
Preferred
- Experience integrating AI coding assistants (Claude, GitHub Copilot, or similar) into engineering workflows
- Azure Developer Associate (AZ-204) or Azure DevOps Engineer Expert (AZ-400)
- Experience with ERP-adjacent integrations (SAP, Oracle, NetSuite, MS Dynamics)
- Background in distribution, manufacturing, supply chain, or logistics verticals
- PE-backed enterprise experience — you understand delivery pressure and ROI accountability
You Are...
- An Azure application specialist — not an infrastructure architect who also touches apps
- Equally strong at architecture, standards-setting, and hands-on delivery — you can design it, document it, and validate it in code
- Security-minded by default — you don't bolt security on at the end
- A strong communicator who can bridge business requirements and technical execution without losing either audience
- Someone who has walked into a complex, inherited application environment and brought order to it — standards, guardrails, and all
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search