Mizuho Financial

Cloud Platform Architect

Mizuho Financial$112K — $205K *
Nye, MT 59061In-Person
Finance & Insurance
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years in identity or infrastructure engineering with hands-on Microsoft Entra ID experience at enterprise scale
  • Proven experience in regulated financial services or a comparably regulated environment
  • Strong expertise in Conditional Access design and Privileged Identity Management
  • Experience managing an established identity estate, including configuration and documentation
  • Knowledge of authentication standards like OIDC, OAuth 2.0, and SAML
  • Understanding of broader Azure services and how identity integrates with them
  • Proficiency in scripting and automation with PowerShell and Microsoft Graph API.

Responsibilities

  • Design and operate secure, compliant identity for the Azure environment using Microsoft Entra ID
  • Implement and iterate Conditional Access policies and manage identities
  • Publish clear documentation and consumable patterns for identity standards
  • Enforce identity guardrails through automation and Azure Policy
  • Manage hybrid identity and work with directory services team
  • Design workload identity patterns for Azure services
  • Collaborate with Security, Risk, and Compliance for regulatory integration.

Benefits

  • Generous employee benefits package
  • Discretionary bonus eligibility
  • Hybrid working program with flexible remote work opportunities
Full Job Description
About the role

We are hiring a Cloud Platform Architect specializing in identity to own cloud identity as a platform capability within our Cloud Platform team.

You will take ownership of our Microsoft Entra estate and everything from the synchronization boundary up: authentication design, access policy, hybrid identity, and the identity patterns the rest of the platform builds on. The platform operates on an enablement model: guardrails enforced in code and self-serve patterns as the default path. Your job is to make secure identity the easiest option, not a queue.

This is a role for someone who wants a domain of their own: full technical ownership of cloud identity in a regulated financial environment, a direct line into platform and architecture decisions, and a roadmap that includes building our external identity capability from the ground up.

What you will own
  • The Microsoft Entra estate: tenant configuration, Conditional Access, Privileged Identity Management, entitlement management
  • Hybrid identity design: synchronization scope, attribute flow, authentication method, and cloud-only account policy
  • Identity patterns for platform services: workload identities, service account lifecycle, and non-human identity governance
  • Break-glass access design and its integration with the bank's privileged access management platform
  • External and business-partner identity architecture (Entra External ID) per the cloud roadmap
  • Identity blueprints, runbooks, and the documentation that makes the estate operable beyond one person


Responsibilities
  • Design and operate secure, compliant identity for our Azure estate using Microsoft Entra ID, aligned to regulatory and internal audit requirements, including access control and MFA provisions
  • Design, implement, and iterate Conditional Access policies, Privileged Identity Management, and entitlement management across the tenant
  • Publish identity standards as both clear documentation and consumable patterns: reference designs, reusable Terraform modules, and paved-road configurations that make the standard the easiest path to follow
  • Enforce identity guardrails through Azure Policy and automation rather than manual approval
  • Own hybrid identity and the technical interface with the directory services team: Entra Connect scope, what synchronizes, what stays cloud-only, and how the boundary is controlled
  • Design workload identity patterns for Azure services and pipelines: managed identities, workload identity federation, and service principal lifecycle
  • Partner with Security, Risk, and Compliance to integrate regulatory controls and evidence collection into identity designs
  • Represent cloud identity in audit and regulatory conversations


Qualifications
  • 7+ years in identity or infrastructure engineering, including deep hands-on Microsoft Entra ID experience at enterprise scale
  • Proven experience in regulated financial services (banking, capital markets, or insurance) or a comparably regulated environment
  • Strong command of Conditional Access design, Privileged Identity Management, hybrid identity (Entra Connect / cloud sync), and workload identity patterns
  • Experience taking ownership of an established identity estate and maturing its configuration, documentation, and controls
  • Working knowledge of authentication standards (OIDC, OAuth 2.0, SAML) and modern authentication policy (phishing-resistant MFA, token protection)
  • Solid working knowledge of the broader Azure platform: RBAC, Azure Policy, Key Vault, and how identity integrates with core infrastructure services
  • Familiarity with control frameworks and regulatory expectations for identity and access management
  • Scripting and automation proficiency (PowerShell, Microsoft Graph API); Infrastructure-as-Code experience preferred


What distinguishes a strong candidate
  • You build a defensible picture of an environment before changing anything in it
  • You know what you chose not to enforce, and why: policy design for you is about blast radius and rollout, not checklists
  • You have made an identity control easier to follow instead of easier to bypass
  • Your last hands-on work was recent, and you intend to keep it that way


The expected base salary ranges from $112k-$205k. Salary offers are based on a wide range of factors including relevant skills, training, experience, education, and, where applicable, certifications and licenses obtained. Market and organizational factors are also considered. In addition to salary and a generous employee benefits package, successful candidates are eligible to receive a discretionary bonus.

#LI-Hybrid

Other requirements

Mizuho has in place a hybrid working program, with varying opportunities for remote work depending on the nature of the role, needs of your department, as well as local laws and regulatory obligations. Roles in some of our departments have greater in-office requirements that will be communicated to you as part of the recruitment process

#LI-MIZUHO

About Mizuho Financial

Mizuho Financial Group, Inc. is a Japanese banking holding company headquartered in the ?temachi district of Chiyoda, Tokyo, Japan. The name "mizuho" literally means "abundant rice" in Japanese. It holds assets in excess of $1.8 trillion US dollars through its control of Mizuho Bank, Mizuho Corporate Bank, and other operating subsidiaries. The company's combined holdings form the second largest financial services group in Japan. Its banking businesses rank third in Japan after Mitsubishi UFJ Financial Group and Sumitomo Mitsui Financial Group. It is the 15th largest banking institution in the world by total assets as of December 2018.
Learn more about Mizuho Financial
Size
54,492 employees
Market Cap
$35 billion
Industry
Net Income
$84.4 billion
5 Year Trend
-0.6%
NASDAQ

Similar Jobs

More Jobs at Mizuho Financial

More Finance & Insurance Jobs

Find similar Cloud Platform Architect jobs: