Logo
The Planet Group

Sr. Cloud Engineer/Architect

The Planet Group, New York, New York, us, 10261

Save Job

Job Description

Job Title: Senior Azure Cloud Engineer / Architect (Azure Landing Zones) Location: New York, NY (Hybrid - 3 Days Onsite at Midtown Manhattan Office, 2 Days Remote) Salary Range: $200,000 + Annual Bonus Benefits: Full medical/dental/vision, 401(k) match, 20 PTO days Employment Type: Full-Time, Direct Hire Introduction The Planet Group is partnering with a prestigious global investment firm to hire a Sr. Cloud Engineer / Architect for their infrastructure team. This role is focused on architecture, engineering, and design-not maintenance or deployment. You'll lead strategic cloud initiatives in a fast-paced, highly regulated financial environment with exposure to cutting-edge technology across cloud, security, AI, and networking.

This opportunity is ideal for professionals who thrive in high-impact roles where they can shape infrastructure design and collaborate across departments to drive innovation and compliance. The ideal candidate has deep expertise in Microsoft 365, Azure, and identity management, and has built secure, scalable landing zones from scratch. Required Skills & Qualifications

Built and implemented Azure landing zones and tenants from the ground up 5+ years of architecture and design experience with Office 365, Azure, and cloud-hosted infrastructure Experience in highly regulated industries (finance, healthcare, legal) with knowledge of SOX, GLBA, or FFIEC compliance Proven success leading enterprise IAM, Zero Trust architecture, and identity lifecycle automation Expertise with tools and technologies such as:

Azure AD / Entra ID, Conditional Access, MFA, PIM, JIT Microsoft Defender for Office 365, Exchange Online, Teams, OneDrive, SharePoint PowerShell, Graph API, Logic Apps Okta, SSO, SAML, MDM Cloud networking: TCP/IP, DNS, Application Gateways, Azure DNS Enterprise SaaS integration

Experience managing third-party vendors, product evaluations, and infrastructure assessments Strong documentation, verbal, and presentation skills-must be comfortable speaking to senior leadership Bachelor's degree in Computer Science, Engineering, or related field preferred U.S. work authorization required (no visa sponsorship available) Preferred Certifications (Nice to Have)

SC-300: Microsoft Identity and Access Administrator MS-500: Microsoft 365 Security Administrator AZ-104: Azure Administrator Associate SC-400: Microsoft Information Protection Administrator CISSP or equivalent cybersecurity certification Day-to-Day Responsibilities

Lead cloud architecture design and implementation to improve availability, performance, and business continuity Build and support secure Microsoft 365 environments with full lifecycle policy management Manage identity & access controls, conditional access, and identity governance across platforms Integrate financial SaaS apps and internal systems with Azure AD for seamless SSO Collaborate with InfoSec to define and enforce Zero Trust and insider risk mitigation policies Ensure systems are compliant with internal audit, SOX, and financial industry standards Automate operations using PowerShell, Graph API, or Logic Apps Generate dashboards and usage reports for access and authentication metrics Serve as SME for enterprise-wide IT modernization initiatives Participate in internal audits, provide documentation, and manage remediation plans Company Culture & Benefits

Join a high-tenure organization that values internal promotion and technical leadership Hybrid work schedule: 3 days onsite in Midtown Manhattan Exposure to AI, cybersecurity, and cloud transformation projects Competitive base salary + annual performance bonus Health, dental, vision, and 401(k) match Generous 20-day PTO plan Be part of a tight-knit infrastructure team driving innovation-not responding to tickets #LI-MG1 #TECH #Hybrid #Manhattan

The staffing industry has seen an increase in people falsely representing themselves as recruiters to gather personal information from job seekers. For your safety, do not provide sensitive data to anyone you have not spoken with thoroughly, never provide banking information during the application process and always double check the email address of the Recruiter to ensure it's from an official Planet domain (@theplanetgroup.com or @launchcg.com) - and not a domain with an alternative extension like .net, .org or .jobs.

The Planet Group and our companies are equal opportunity employers. It is our practice not to discriminate against any employee or applicant based on any criteria, condition or basis protected by laws or regulations in the locations where we do business. All qualified applicants are encouraged to apply. We celebrate diversity and are committed to providing an environment of mutual respect. We believe that diversity, equity and inclusion enable us to better meet our mission and values while serving our clients across the globe. If you have a disability or handicap and would like us to accommodate you in any reasonable way, please inform your recruiter, or contact us, so that we can discuss the appropriate alternatives available.