Cloud / Infra Architect (Pune)

Cloud / Infra Architect (Pune)

02 Oct
|
TMF Group
|
Pune

02 Oct

TMF Group

Pune

Job Summary

This role is positioned as a strategic architecture leader and enterprise design authority, not simply as a senior technical specialist. The ideal candidate combines deep Azure, infrastructure, cybersecurity, AKS, platform engineering and AI architecture expertise with the ability to influence global technology direction, govern enterprise standards, modernize platforms, reduce risk, and enable secure AI-driven transformation at scale. This role shall be focused around Platform Landing Zone / AI Landing Zone, management groups, subscription structure, connectivity, identity, policy foundations, architecture governance, HLD/LLD/SOP/runbook transition gates, data/AI governance and reusable engineering patterns. TMF's infrastructure standards is a hybrid setup across on-premises and cloud, with security, DR, monitoring, governance, application architecture, containerization, microservices/serverless and cost-management requirements, plus Azure PaaS / private endpoint expectations and AKS as a key Azure service. Use CAF methodologies for Strategy, Plan, Ready, Adopt, Govern, Secure and Manage, Azure landing zone design areas across identity, resource organization, network, security, governance, management and platform automation/DevOps, AKS baseline architecture patterns for secure, observable, production-ready clusters, and responsible AI practices built around identify, measure, mitigate and operate.

We never ask for payment as part of our selection process, and we always contact candidates via our corporate accounts and platforms. If you are approached for payment, this is likely to be fraudulent. Please check to see whether the role you are interested in is posted here, on our website.

General Information

- Location: Pune, India
- Work Types: Full Time
- Categories: Information Technology

Key Responsibilities

- Architecture Leadership Technology Strategy: Define and maintain the enterprise target-state architecture for cloud, infrastructure, cybersecurity, platform engineering, cloud-native services and AI enablement.
- Translate business strategy, risk appetite, regulatory needs and technology trends into actionable architecture roadmaps and investment priorities.
- Establish architecture principles, reference architectures, decision frameworks and reusable patterns for global technology delivery.
- Lead architecture governance through Architecture Review Board / TDA-style forums, ensuring early design alignment before delivery execution.
- Own architecture standards for landing zones, connectivity,



identity, security, monitoring, automation, resilience, workload onboarding and operational readiness.
- Provide executive-level technology advisory, clearly explaining architectural trade-offs, risk implications, cost impacts and transformation advantages.
- Ensure architecture decisions are documented through architecture decision records, design standards, patterns, exceptions and lifecycle governance.
- Drive architecture maturity from reactive delivery to repeatable, governed engineering patterns, aligned with TMF's stated architecture direction for reusable blueprints, governance and platform scale.
- Cloud Transformation Hybrid Infrastructure Modernization: Lead the evolution of TMF's Azure-first cloud architecture, including platform landing zones, management groups, subscriptions, policy, identity, connectivity and shared services.
- Define architecture patterns for hybrid cloud integration across Azure, on-premises Microsoft HCI / Azure Stack HCI, Azure Arc, data centers and public cloud services.
- Guide modernization of legacy infrastructure into scalable, resilient, secure and automation-enabled platforms.
- Establish standards for subscription segmentation, environment isolation, resource organization, tagging, cost allocation, network topology, DNS, private endpoints and region strategy.
- Design and govern hybrid connectivity patterns including ExpressRoute, VPN, hub-spoke networking, Azure Firewall, Azure WAF, Azure Front Door, private DNS and secure egress.
- Lead infrastructure lifecycle modernization, including technical debt reduction, operating system refresh, data center transformation, platform migration and cloud optimization.
- Drive resilience-by-design across backup, disaster recovery, failover, high availability, observability and recovery testing.
- Ensure cloud architecture aligns with CAF / Azure Landing Zone principles for identity, resource organization, network topology, security, governance, management and platform automation.
- Cybersecurity Architecture, Governance Risk Reduction: Define enterprise security architecture patterns across identity, network, endpoint, cloud,



application, data, container, AI and platform layers.
- Embed secure-by-design and Zero Trust principles into all architecture decisions.
- Govern implementation of security controls across Microsoft Entra ID, RBAC, Privileged Identity Management, Conditional Access, MFA, managed identities, Key Vault, private endpoints and network segmentation.
- Define architecture standards for cloud security posture management, vulnerability management, public exposure controls, privileged access, service accounts, secrets management and certificate lifecycle.
- Partner with cybersecurity, risk, compliance and engineering teams to align architecture with CIS, NIST, ISO 27001, SOC 2, GDPR and internal policy expectations.
- Drive architecture-level remediation plans for audit findings, red-team findings, CSPM gaps, insecure configurations and exception governance.
- Establish secure patterns for DevSecOps, CI/CD, code scanning, container image scanning, secrets scanning, infrastructure policy enforcement and automated compliance.
- Maintain audit-ready evidence of architecture decisions, design approvals, risk acceptances and security exceptions.
- Cloud Operating Model, Platform Engineering DevSecOps: Define TMF's cloud operating model across platform teams, application teams, cybersecurity, operations, FinOps and governance functions.
- Lead the design of internal developer / platform engineering capabilities that enable self-service, governed workload onboarding and repeatable infrastructure provisioning.
- Establish golden paths and reusable platform blueprints for compute, networking, identity, observability, security, CI/CD, IaaC and service onboarding.
- Govern Infrastructure-as-Code standards using Terraform, Bicep, ARM templates or equivalent enterprise tooling.
- Define DevSecOps patterns using Azure DevOps, GitHub Actions or equivalent platforms, including build, test, deploy, security validation, rollback and change governance.
- Implement policy-as-code, guardrails, automated compliance checks and deployment gates to reduce delivery risk.
- Drive FinOps architecture practices, including cost visibility, tagging, reserved capacity, rightsizing, budget alerts and cloud optimization.

Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

📌 Cloud / Infra Architect (Pune)
🏢 TMF Group
📍 Pune

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: cloud / infra architect (pune) / pune