Skip to content
Aramis:Insight

Roles

Azure Security Architect

You own the security design of a Microsoft Azure estate: identity, network flows, governance, and recovery.

Competency areas

  • Cyber Resiliency (8)
  • Cryptography (3)
  • DevSecOps (3)
  • Artificial Intelligence (AI) Security (1)
Measure yourself against this role

Job description templates

Three ready-to-edit drafts for hiring managers and recruiters: copy one, replace the bracketed lines, and post it. Responsibilities and requirements are drawn from the same NICE statements this role is measured against.

Statements are shown in their official NICE Framework wording, which is maintained in English.

Azure Security Architect: Junior

We are hiring a junior Azure Security Architect. You will work under the guidance of senior colleagues, take ownership of well-scoped tasks, and grow into the full shape of the role. You own the security design of a Microsoft Azure estate: identity, network flows, governance, and recovery.

[Company] provides [what you do]. The security function is [size and shape: e.g., a five-person team reporting to the CTO]. Replace this paragraph with your own.

Responsibilities

  • Employ secure configuration management processes
  • Integrate new systems into existing network architecture
  • Integrate organizational goals and objectives into security architecture
  • Determine disaster recovery and continuity of operations system requirements
  • Develop network backup and recovery procedures
  • Determine if security control technologies reduce identified risk to acceptable levels
  • Determine if systems and architecture are consistent with cybersecurity architecture guidelines
  • Maintain baseline system security
  • Pair with senior colleagues and grow through structured feedback.
  • Document what you do so the team learns with you.

Required knowledge

  • Business continuity and disaster recovery (BCDR) policies and procedures
  • Identity and access management (IAM) principles and practices
  • Virtual private network (VPN) systems and software
  • Machine virtualization tools and techniques
  • Network firewall principles and practices
  • Personal Health Information (PHI) data security standards and best practices
  • Data-at-rest encryption (DARE) standards and best practices
  • Microsoft Entra ID identity types (users, groups, service principals, managed identities, and workload identities) and how each authenticates to and is authorized on Azure resources

Skills

  • Applying secure network architectures
  • Designing architectures
  • Deploying continuous monitoring technologies
  • Applying network access controls
  • Developing network infrastructure contingency and recovery plans

How to use this template

Copy the draft, replace every bracketed line, cut statements that do not apply to your opening, and add your compensation range and location policy. The statement lists come from the NIST NICE Framework v2.2.0, so candidates can be assessed against the same statements with Aramis:Insight.

Azure Security Architect: Mid-level

We are hiring a Azure Security Architect. You will own this work day to day, collaborate across the security function, and raise the bar on how it is done. You own the security design of a Microsoft Azure estate: identity, network flows, governance, and recovery.

[Company] provides [what you do]. The security function is [size and shape: e.g., a five-person team reporting to the CTO]. Replace this paragraph with your own.

Responsibilities

  • Employ secure configuration management processes
  • Integrate new systems into existing network architecture
  • Integrate organizational goals and objectives into security architecture
  • Determine disaster recovery and continuity of operations system requirements
  • Develop network backup and recovery procedures
  • Determine if security control technologies reduce identified risk to acceptable levels
  • Determine if systems and architecture are consistent with cybersecurity architecture guidelines
  • Maintain baseline system security
  • Perform security reviews
  • Identify gaps in security architecture
  • Determine the effectiveness of data redundancy and system recovery procedures
  • Develop data redundancy and system recovery procedures

Required knowledge

  • Business continuity and disaster recovery (BCDR) policies and procedures
  • Identity and access management (IAM) principles and practices
  • Virtual private network (VPN) systems and software
  • Machine virtualization tools and techniques
  • Network firewall principles and practices
  • Personal Health Information (PHI) data security standards and best practices
  • Data-at-rest encryption (DARE) standards and best practices
  • Microsoft Entra ID identity types (users, groups, service principals, managed identities, and workload identities) and how each authenticates to and is authorized on Azure resources
  • The Microsoft cloud security benchmark and Azure service security baselines and how they relate to the CIS Microsoft Azure Foundations Benchmark and NIST control catalogs
  • Azure routing behavior: system routes, user-defined routes, routes learned over BGP from virtual network gateways, gateway route propagation, and how Azure selects among them
  • The shared responsibility model for Azure infrastructure, platform services, and Azure VMware Solution, and which security controls the customer retains in each
  • The HIPAA Security Rule's administrative, physical, and technical safeguards and of business associate obligations as they apply to cloud-hosted systems and their service providers

Skills

  • Applying secure network architectures
  • Designing architectures
  • Deploying continuous monitoring technologies
  • Applying network access controls
  • Developing network infrastructure contingency and recovery plans
  • Testing network infrastructure contingency and recovery plans
  • Applying hardening techniques
  • Identifying privacy issues in partner interconnections

How to use this template

Copy the draft, replace every bracketed line, cut statements that do not apply to your opening, and add your compensation range and location policy. The statement lists come from the NIST NICE Framework v2.2.0, so candidates can be assessed against the same statements with Aramis:Insight.

Azure Security Architect: Senior

We are hiring a senior Azure Security Architect. You will set the direction for this work, mentor others in it, and be accountable for its outcomes at the organizational level. You own the security design of a Microsoft Azure estate: identity, network flows, governance, and recovery.

[Company] provides [what you do]. The security function is [size and shape: e.g., a five-person team reporting to the CTO]. Replace this paragraph with your own.

Responsibilities

  • Employ secure configuration management processes
  • Integrate new systems into existing network architecture
  • Integrate organizational goals and objectives into security architecture
  • Determine disaster recovery and continuity of operations system requirements
  • Develop network backup and recovery procedures
  • Determine if security control technologies reduce identified risk to acceptable levels
  • Determine if systems and architecture are consistent with cybersecurity architecture guidelines
  • Maintain baseline system security
  • Perform security reviews
  • Identify gaps in security architecture
  • Determine the effectiveness of data redundancy and system recovery procedures
  • Develop data redundancy and system recovery procedures
  • Advise on Risk Management Framework process activities and documentation
  • Determine cybersecurity design and architecture effectiveness
  • Create cybersecurity architecture functional specifications
  • Plan cybersecurity architecture
  • Mentor junior team members and review their work.
  • Represent this function to leadership and to auditors or clients.
  • Set standards, select tooling, and own the roadmap for this area.

Required knowledge

  • Business continuity and disaster recovery (BCDR) policies and procedures
  • Identity and access management (IAM) principles and practices
  • Virtual private network (VPN) systems and software
  • Machine virtualization tools and techniques
  • Network firewall principles and practices
  • Personal Health Information (PHI) data security standards and best practices
  • Data-at-rest encryption (DARE) standards and best practices
  • Microsoft Entra ID identity types (users, groups, service principals, managed identities, and workload identities) and how each authenticates to and is authorized on Azure resources
  • The Microsoft cloud security benchmark and Azure service security baselines and how they relate to the CIS Microsoft Azure Foundations Benchmark and NIST control catalogs
  • Azure routing behavior: system routes, user-defined routes, routes learned over BGP from virtual network gateways, gateway route propagation, and how Azure selects among them
  • The shared responsibility model for Azure infrastructure, platform services, and Azure VMware Solution, and which security controls the customer retains in each
  • The HIPAA Security Rule's administrative, physical, and technical safeguards and of business associate obligations as they apply to cloud-hosted systems and their service providers

Skills

  • Applying secure network architectures
  • Designing architectures
  • Deploying continuous monitoring technologies
  • Applying network access controls
  • Developing network infrastructure contingency and recovery plans
  • Testing network infrastructure contingency and recovery plans
  • Applying hardening techniques
  • Identifying privacy issues in partner interconnections
  • Performing cybersecurity architecture analysis
  • Evaluating a managed security provider's requests for telemetry and access: deciding which log sources and permissions serve detection and response, which exceed the need, and what to provide instead

How to use this template

Copy the draft, replace every bracketed line, cut statements that do not apply to your opening, and add your compensation range and location policy. The statement lists come from the NIST NICE Framework v2.2.0, so candidates can be assessed against the same statements with Aramis:Insight.

Related roles

Roles that share this one’s work or career stage. Each links to its own statements, sample questions, and job description templates.