Senior Cloud Security & Data Governance Architect (Microsoft Fabric & Azure)
We are seeking a highly experienced Cloud Security & Data Governance Architect to design, implement, and govern secure, compliant, and scalable data platforms built on Microsoft Azure and Microsoft Fabric. This role is responsible for end-to-end security architecture, identity and access governance, data protection, compliance, and continuous monitoring across enterprise data environments.
The ideal candidate brings deep hands-on experience with Zero Trust security models, Entra ID, Microsoft Fabric, Purview, and Azure security services, and has a strong background supporting regulated data (PII/PHI) at scale.
Design and maintain secure Microsoft Fabric architectures, including workspaces, capacities, domains, and role models
Implement enterprise-wide RBAC and ABAC across Azure and Fabric using Microsoft Entra ID
Configure and manage SSO, MFA, Conditional Access, and identity federation
Design and enforce Zero Trust security boundaries across dev/test/prod environments and business domains
Secure network access using Private Endpoints, VNET integration, NSGs, and firewalls
Implement encryption at rest and in transit across Fabric, OneLake, ADLS, SQL databases, and data warehouses
Design and operate Customer-Managed Key (CMK) architectures using Azure Key Vault
Manage key rotation, secrets governance, and certificate lifecycle hygiene
Implement PII/PHI protection controls, including column-level encryption, masking, and tokenization
Design secure, encrypted data lifecycle patterns across Bronze/Silver/Gold data zones
Architect encrypted backup and restore workflows with controlled access and auditability
Implement and manage Microsoft Purview scanning, cataloging, and metadata governance
Configure sensitivity labels, access policies, and DLP rules
Build and maintain custom classification rules for PII/PHI aligned with governance standards
Design and maintain end-to-end data lineage across multiple source and downstream systems
Implement and maintain audit logging across Fabric, Entra ID, ADLS, SQL, and Purview
Integrate security telemetry into Microsoft Sentinel or equivalent SIEM platforms
Build security alerting and automated incident response workflows
Participate in or lead security audits, penetration tests, and remediation efforts
Configure continuous compliance and security posture management using Azure Policy and Defender for Cloud