Principal Azure Security Architect
Indexed description
Do you want to work on innovative projects, collaborate with a dynamic and supportive team, and receive investment in your professional development? At DTCC, we are at the forefront of innovation in the financial markets. We are committed to helping our employees grow and succeed. We believe that you have the skills and drive to make a real impact. We foster a thriving internal community and are committed to creating a workplace that looks like the world that we serve.
The Information Technology group delivers secure, reliable technology solutions that enable DTCC to be the trusted infrastructure of the global capital markets. The team delivers high-quality information through activities that include development of essential, building infrastructure capabilities to meet client needs and implementing data standards and governance.
Pay And Benefits
- Competitive compensation, including base pay and annual incentive
- Comprehensive health and life insurance and well-being benefits, based on location
- Pension / Retirement benefits
- Paid Time Off and Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
- DTCC offers a flexible/hybrid model of 3 days onsite and 2 days remote (onsite Tuesdays, Wednesdays and a third day unique to each team or employee).
Your Primary Responsibilities
- Embed security architecture into Azure-native and hybrid cloud solutions from design through deployment.
- Define and publish reusable security patterns across Microsoft ecosystems (Azure, Power Platform, Copilot Studio).
- Partner with platform and engineering teams to ensure secure adoption of AI, low-code, and data governance capabilities.
- Mentor engineering teams on security architecture, secure coding, and cloud-native control implementations.
- Drive consistency through governed, scalable security patterns that reduce the need for per-integration reviews.
Qualifications
- 5+ years of cybersecurity work experience
- Strong background in cloud security architecture, with emphasis on Microsoft Azure.
- Experience working with enterprise engineering teams in agile and DevSecOps environments.
- Bachelor’s degree preferred (or equivalent experience).
- Deep experience with Microsoft Azure security architecture (IAM, networking dependencies, PaaS security, RBAC, Conditional Access).
- Experience implementing security controls across hybrid and multi-cloud environments.
- Microsoft Purview (data governance, data classification, DLP, insider risk concepts).
- Power Platform security model: - Environment strategy, tenant isolation, connector governance
- Data loss prevention (DLP) policies
- Copilot Studio / AI platform security considerations: - Secure plugin/integration design
- Prompt and data protection considerations
- Identity-aware access control patterns
- Strong understanding of authentication, authorization (OAuth2/OIDC), and token-based access models.
- Secure API and integration patterns, including RESTful services and event-driven architectures.
- Knowledge of OWASP Top 10, SAMM, and application security testing approaches (SAST, DAST, SCA).
- Experience integrating security into CI/CD pipelines and cloud-native development workflows.
- Familiarity with infrastructure-as-code security and policy-as-code enforcement.
- Experience creating reusable security patterns and reference architectures.
- Ability to define enforceable standards that align with governance bodies (e.g., Architecture Review Boards).
- Strong ability to translate risk into actionable engineering guidance.
- Strong analytical and problem-solving skills.
- Ability to communicate complex technical concepts to both technical and non-technical stakeholders.
- Excellent written, presentation, and collaboration skills.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search