Azure Security Architect
You own the security design of a Microsoft Azure estate: identity, network flows, governance, and recovery.
Competency areas
- Cyber Resiliency (8)
- Artificial Intelligence (AI) Security (6)
- Cryptography (5)
- DevSecOps (3)
Job description templates
Three ready-to-edit drafts for hiring managers and recruiters: copy one, replace the bracketed lines, and post it. Responsibilities and requirements are drawn from the same NICE statements this role is measured against.
Statements are shown in their official NICE Framework wording, which is maintained in English.
Azure Security Architect: Junior
We are hiring a junior Azure Security Architect. You will work under the guidance of senior colleagues, take ownership of well-scoped tasks, and grow into the full shape of the role. You own the security design of a Microsoft Azure estate: identity, network flows, governance, and recovery.
[Company] provides [what you do]. The security function is [size and shape: e.g., a five-person team reporting to the CTO]. Replace this paragraph with your own.
Responsibilities
- Employ secure configuration management processes
- Integrate new systems into existing network architecture
- Integrate organizational goals and objectives into security architecture
- Determine disaster recovery and continuity of operations system requirements
- Develop network backup and recovery procedures
- Determine if security control technologies reduce identified risk to acceptable levels
- Determine if systems and architecture are consistent with cybersecurity architecture guidelines
- Maintain baseline system security
- Pair with senior colleagues and grow through structured feedback.
- Document what you do so the team learns with you.
Required knowledge
- Business continuity and disaster recovery (BCDR) policies and procedures
- Identity and access management (IAM) principles and practices
- Virtual private network (VPN) systems and software
- Machine virtualization tools and techniques
- Data classification standards and best practices
- Data classification tools and techniques
- Network firewall principles and practices
- Personal Health Information (PHI) data security standards and best practices
Skills
- Applying secure network architectures
- Designing architectures
- Deploying continuous monitoring technologies
- Applying network access controls
- Developing network infrastructure contingency and recovery plans
How to use this template
Copy the draft, replace every bracketed line, cut statements that do not apply to your opening, and add your compensation range and location policy. The statement lists come from the NIST NICE Framework v2.2.0, so candidates can be assessed against the same statements with Aramis:Insight.
Azure Security Architect: Mid-level
We are hiring a Azure Security Architect. You will own this work day to day, collaborate across the security function, and raise the bar on how it is done. You own the security design of a Microsoft Azure estate: identity, network flows, governance, and recovery.
[Company] provides [what you do]. The security function is [size and shape: e.g., a five-person team reporting to the CTO]. Replace this paragraph with your own.
Responsibilities
- Employ secure configuration management processes
- Integrate new systems into existing network architecture
- Integrate organizational goals and objectives into security architecture
- Determine disaster recovery and continuity of operations system requirements
- Develop network backup and recovery procedures
- Determine if security control technologies reduce identified risk to acceptable levels
- Determine if systems and architecture are consistent with cybersecurity architecture guidelines
- Maintain baseline system security
- Perform security reviews
- Identify gaps in security architecture
- Determine the effectiveness of data redundancy and system recovery procedures
- Develop data redundancy and system recovery procedures
Required knowledge
- Business continuity and disaster recovery (BCDR) policies and procedures
- Identity and access management (IAM) principles and practices
- Virtual private network (VPN) systems and software
- Machine virtualization tools and techniques
- Data classification standards and best practices
- Data classification tools and techniques
- Network firewall principles and practices
- Personal Health Information (PHI) data security standards and best practices
- Data-at-rest encryption (DARE) standards and best practices
- Data classification levels
- Data exfiltration tools and techniques
- Common AI security risks
Skills
- Applying secure network architectures
- Designing architectures
- Deploying continuous monitoring technologies
- Applying network access controls
- Developing network infrastructure contingency and recovery plans
- Testing network infrastructure contingency and recovery plans
- Applying hardening techniques
- Identifying privacy issues in partner interconnections
How to use this template
Copy the draft, replace every bracketed line, cut statements that do not apply to your opening, and add your compensation range and location policy. The statement lists come from the NIST NICE Framework v2.2.0, so candidates can be assessed against the same statements with Aramis:Insight.
Azure Security Architect: Senior
We are hiring a senior Azure Security Architect. You will set the direction for this work, mentor others in it, and be accountable for its outcomes at the organizational level. You own the security design of a Microsoft Azure estate: identity, network flows, governance, and recovery.
[Company] provides [what you do]. The security function is [size and shape: e.g., a five-person team reporting to the CTO]. Replace this paragraph with your own.
Responsibilities
- Employ secure configuration management processes
- Integrate new systems into existing network architecture
- Integrate organizational goals and objectives into security architecture
- Determine disaster recovery and continuity of operations system requirements
- Develop network backup and recovery procedures
- Determine if security control technologies reduce identified risk to acceptable levels
- Determine if systems and architecture are consistent with cybersecurity architecture guidelines
- Maintain baseline system security
- Perform security reviews
- Identify gaps in security architecture
- Determine the effectiveness of data redundancy and system recovery procedures
- Develop data redundancy and system recovery procedures
- Advise on Risk Management Framework process activities and documentation
- Determine cybersecurity design and architecture effectiveness
- Create cybersecurity architecture functional specifications
- Plan cybersecurity architecture
- Mentor junior team members and review their work.
- Represent this function to leadership and to auditors or clients.
- Set standards, select tooling, and own the roadmap for this area.
Required knowledge
- Business continuity and disaster recovery (BCDR) policies and procedures
- Identity and access management (IAM) principles and practices
- Virtual private network (VPN) systems and software
- Machine virtualization tools and techniques
- Data classification standards and best practices
- Data classification tools and techniques
- Network firewall principles and practices
- Personal Health Information (PHI) data security standards and best practices
- Data-at-rest encryption (DARE) standards and best practices
- Data classification levels
- Data exfiltration tools and techniques
- Common AI security risks
- NIST AI Risk Management Framework
- Agentic AI principles and practices
Skills
- Applying secure network architectures
- Designing architectures
- Deploying continuous monitoring technologies
- Applying network access controls
- Developing network infrastructure contingency and recovery plans
- Testing network infrastructure contingency and recovery plans
- Applying hardening techniques
- Identifying privacy issues in partner interconnections
- Performing cybersecurity architecture analysis
- Evaluating a managed security provider's requests for telemetry and access: deciding which log sources and permissions serve detection and response, which exceed the need, and what to provide instead
How to use this template
Copy the draft, replace every bracketed line, cut statements that do not apply to your opening, and add your compensation range and location policy. The statement lists come from the NIST NICE Framework v2.2.0, so candidates can be assessed against the same statements with Aramis:Insight.
Related roles
Roles that share this one’s work or career stage. Each links to its own statements, sample questions, and job description templates.