Bachelor's degree in Computer Science, Information Technology, Engineering, or equivalent experience.
10+ years in infrastructure, cloud, or platform engineering; 4 years in Microsoft Azure.
1-3 years of leadership experience in managing technical teams.
Expertise in Azure governance, Microsoft Entra ID, and Infrastructure-as-Code.
Familiarity with cloud security, Zero Trust principles, and regulatory compliance.
Responsibilities
Own the design and governance of the Azure tenant and Microsoft 365 suite.
Define guardrails and standards using policy-as-code and Infrastructure-as-Code.
Manage enterprise identity through Microsoft Entra ID, focusing on access and RBAC.
Prioritize platform roadmap in alignment with IT strategy.
Oversee security posture applying Zero Trust and continuous monitoring.
Benefits
Work in a hands-on leadership role with technical authority.
Supervise and mentor cloud engineering and operations staff.
Engage with senior leadership on cloud strategies and risk management.
Opportunity to work in a regulated financial environment.
Full Job Description
EDUCATION AND EXPERIENCE
Bachelor's degree in Computer Science, Information Technology, Engineering, or a related field, or an equivalent combination of education and relevant experience.
Minimum of 10 years of progressive experience in infrastructure, cloud, or platform engineering, including at least 4 years specializing in Microsoft Azure.
One to three years of leadership or people management experience, with a demonstrated ability to lead technical teams and manage enterprise platform environments.
Expertise in Azure tenant governance, Microsoft Entra ID, networking, Infrastructure-as-Code (IaC), and cloud platform operations.
Strong understanding of cloud security principles, including Zero Trust architecture, identity and access management, and encryption and key management.
Experience within a regulated industry, preferably banking or financial services, with exposure to audits and regulatory examinations is strongly preferred.
Proven ability to design, implement, and validate disaster recovery and business continuity strategies for mission-critical systems, along with exceptional communication skills to effectively present technical concepts, risks, and trade-offs to senior leadership.
Preferred certifications include Microsoft Certified: Azure Solutions Architect Expert, Microsoft Certified: Azure Administrator Associate, Microsoft Certified: Cybersecurity Architect Expert or Azure Security Engineer Associate, and security or governance certifications such as CISSP, CCSP, or CISM. FinOps Certified Practitioner certification is a plus.
JOB SUMMARY
The Cloud Platform Engineering Manager is the designated owner and single point of accountability (DRI) for Capital Farm Credit's (CFC) Microsoft cloud platform, spanning the Azure and Microsoft 365 environments (including Exchange Online, SharePoint Online, OneDrive, and Teams). This leader is accountable for the security posture, reliability, governance, cost, and engineering of these environments, ensuring they meet the regulatory and operational expectations of a financial institution.
This hands-on leadership role pairs deep Azure and Microsoft 365 expertise with clear ownership. The Manager sets platform direction within the strategy established by Senior IT Leadership, supports the engineering and operations staff who run the platform, and serves as CFC's primary technical authority on Azure and Microsoft 365. They partner closely with Information Security, Risk, Compliance, Audit, and application teams - including on the data governance, retention, and information-protection controls (e.g., Microsoft Purview) across the M365 estate - advise the SVP on cloud risk, investment, and strategy, and escalate decisions beyond the platform's defined authority.
ESSENTIAL FUNCTIONS
Own the design, governance, and lifecycle of the Azure tenant and full M365 suite, aligned with the Azure Well-Architected and Cloud Adoption Frameworks.
Define and enforce guardrails, standards, and reference architecture through policy-as-code and Infrastructure-as-Code.
Own enterprise identity within the tenant (Microsoft Entra ID), including conditional access, privileged access, and least-privilege RBAC.
Maintain the platform roadmap and prioritize work in alignment with the CFC's IT strategy.
Own the security posture of the tenant in partnership with Information Security, applying Zero Trust and defense-in-depth controls.
Ensure encryption in transit and at rest, robust key and secrets management (Azure Key Vault, HSM-backed keys), and continuous monitoring (Microsoft Defender for Cloud, Sentinel, Purview).
Ensure the tenant satisfies applicable requirements (e.g., FFIEC guidance, GLBA, SOX, PCI-DSS, and relevant state/federal regulations) and support internal/external audits and regulatory examinations.
Own remediation of cloud-related audit and examination findings within agreed timelines.
Own availability, performance, and reliability of the platform against defined SLAs/SLOs.
Design, document, and regularly test high-availability, backup, disaster recovery (DR), and business continuity (BCP) capabilities, including recovery objectives (RTO/RPO).
Establish observability, alerting, incident management, and on-call practices; lead major-incident response and post-incident reviews.
Operate change, release, and configuration management in line with the CFC's frameworks.
Own cloud cost management for the tenant - budgeting, forecasting, optimization, and chargeback.
Manage the operational relationship with Microsoft and relevant MSP/third-party vendors, including support, reservations, and licensing.
Support third-party risk activities for cloud vendors with TPRM and procurement.
Lead, mentor, and develop cloud platform engineering and operations staff.
Advise the SVP and senior stakeholders on cloud risk, investment, and trade-offs; escalate decisions beyond the role's authority.
Partner with Security, Risk, Compliance, Audit, and application teams to deliver secure, compliant, and reliable services.
REQUIRED SKILLS
Experience migrating regulated workloads from on premises/data center environments to Azure.
Familiarity with the broader Microsoft ecosystem (Microsoft 365, Defender suite, Sentinel, Purview) and hybrid connectivity.
FinOps experience and demonstrated cloud cost optimization at scale.
Experience supporting risk committees, auditors, or regulators.
Experience building and managing SOC2 certifications
Ownership - takes single-threaded accountability for outcomes and sees issues through to resolution.
Technical authority - deep, current Azure expertise with sound architectural and risk judgment.
Security and risk mindset - treats security, compliance, and resilience as first-class design constraints.
Leadership - builds high-performing teams and earns trust across technical and business stakeholders.
Operational discipline - drives reliability, repeatability, and accountability through process and automation.