Cloud Security Architect
Summary
Designs and implements secure Azure cloud architectures for AI-driven applications, focusing on identity, networking, encryption, and DevOps practices while ensuring future regulatory compliance.
π» Ework Group β founded in 2000 and listed on Nasdaq Stockholm β is a leading total talent solutions provider supporting clients across the private and public sectors, as well as independent professionals, in building sustainable talent supply chains.
With a strong focus on IT/OT, R&D, Engineering, and Business Development, Ework delivers value through an independent, holistic approach to total talent management.
For our Client from the healthcare sector, we are currently looking for:
βοΈ Remote Staff Cloud Security Architect (AI Solutions)
π Location: Warsaw, Poland
π’ Work model: Fully remote, ONLY IN POLAND, with occasional presence in the Warsaw Hub
π Start date: 03.08.2026
CONSULTANT MUST BE LOCATED IN POLAND
Recruitment language: English
Recruitment process: 2-stage online recruitment
Role overview:
We are looking for an experienced Cloud Security Architect to design and enable secure Azure-based architectures for modern AI-driven applications.
This is a hands-on, senior-level role, combining architectural ownership with close collaboration with engineering teams. You will define secure patterns, standards, and reusable frameworks while supporting teams in building scalable, compliant, and production-ready solutions.
The role focuses on secure cloud architecture, AI infrastructure, and DevOps modernization, rather than ownership of a single platform. Solutions are currently non-GxP, but must be designed with future regulatory readiness in mind.
- Strong hands-on experience with Microsoft Azure cloud architecture
- Excellent English speaking skills
- Strong cloud security expertise, including identity, networking, encryption, secrets management, logging, monitoring, and secure access patterns
- Experience designing secure infrastructure for AI applications, AI agents, APIs, data-consuming applications, or internal developer platforms
- Experience with sandboxed code execution, Python runtime environments, containerized workloads, or isolated compute patterns
- Familiarity with Databricks as a data source for applications
- Strong knowledge of network segregation, private endpoints, firewalls, virtual networks, controlled egress, and runtime isolation
- Strong experience with Terraform for infrastructure provisioning and cloud architecture enablement
- Strong experience with GitHub Enterprise, GitHub Actions, repository governance, branch protection, pull requests, and secure CI/CD patterns
- Experience with Azure DevOps, ideally including migration from Azure DevOps to GitHub
- Experience with secrets management, key vaults, managed identities, service principals, RBAC, and Microsoft Entra ID
- Understanding of secure software delivery, release controls, traceability, and audit-ready engineering practices
- Ability to work hands-on with engineers while also setting architecture direction and technical standards
Nice to have
- Experience with Azure AI, Azure OpenAI, or GenAI application patterns
- Experience with containers and orchestration (Kubernetes, Azure Container Apps, Functions)
- Knowledge of GitHub Advanced Security (code scanning, secret scanning, dependency scanning)
- Experience in regulated environments (healthcare, pharma, life sciences)
- Understanding of GxP, CSV, CSA, or validation processes
- Relevant certifications (e.g. Azure Solutions Architect, Azure Security Engineer, DevOps, Terraform)