About this role
What success looks like in this role:
Job Description – Associate Principal Cloud Engineer
Overview
The Associate Principal Cloud Engineer serves as a senior technical leader responsible for designing, implementing, optimizing, and governing cloud solutions across the enterprise. This role provides architectural guidance, drives automation, ensures operational excellence, and mentors engineering teams to deliver secure, scalable, and reliable cloud platforms.
We are mainly seeking an experienced Senior Azure Entra & Active Directory Engineer to manage and optimize enterprise identity and access management (IAM) solutions. This role requires deep expertise in Microsoft Entra ID (formerly Azure AD), Active Directory (AD), and related security technologies. The ideal candidate will design, implement, and maintain identity services that ensure high availability, security, and compliance for the organization's cloud and hybrid environments.
Key Responsibilities
Assoc Prin Cloud Eng
- Design, implement, and maintain Microsoft Entra ID (Azure AD) and on-premises Active Directory infrastructure.
- Administer and manage Azure infrastructure including VMs, Storage, Networking, Backup, Site Recovery, Key Vault, and Azure Monitor.
- Develop and enforce security policies, ensuring compliance with industry standards and best practices.
- Manage and optimize Identity and Access Management (IAM) solutions, including SSO (Single Sign-On), MFA (Multi-Factor Authentication), Conditional Access, and Privileged Identity Management (PIM) .
- Administer and troubleshoot AD Federation Services (ADFS), Azure AD Connect, Group Policy (GPO), and DNS .
- Automate identity lifecycle management using PowerShell, Terraform, or other scripting languages .
- Integrate identity solutions with Azure, Microsoft 365, and third-party SaaS applications .
- Monitor and respond to security threats using Microsoft Defender, Azure Sentinel, and other security tools .
- Perform regular AD health checks, performance tuning, and patch management .
- Collaborate with security, cloud, and networking teams to improve IAM strategies.
- Lead migrations, upgrades, and modernization efforts, including Active Directory domain consolidations and hybrid identity implementations .
- Provide technical mentorship and training to junior engineers.
- Document system designs, processes, and best practices.
Cloud Architecture & Engineering
- Design, develop, and optimize cloud infrastructure solutions aligned with business and architectural standards.
- Lead cloud modernization initiatives including migration, re-architecture, and platform upgrades.
- Ensure high availability, scalability, and performance across cloud workloads.
Automation & DevOps
- Drive automation for provisioning, configuration management, and CI/CD pipelines.
- Reduce manual operations by identifying repetitive tasks and implementing automated solutions.
- Establish IaC best practices using tools such as Terraform, ARM/Bicep, CloudFormation, or similar.
Operations & Reliability
- Oversee cloud platform operations, monitoring, incident management, and root-cause analysis.
- OnPrem Active Directory and Windows servers administration and troubleshooting
- Implement SRE and FinOps principles to improve reliability and cost efficiency.
- Ensure compliance with security, governance, and regulatory standards.
- Administer and manage Azure infrastructure including VMs, Storage, Networking, Backup, Site Recovery, Key Vault, and Azure Monitor.
Leadership & Cross-Functional Collaboration
- Mentor cloud engineers and guide cross-functional teams across AVD, CloudOps, and Hybrid Cloud.
- Contribute to technical roadmaps, standards, and cloud strategy.
- Collaborate with security, application, and infrastructure teams to ensure cohesive cloud delivery.
Security & Governance
- Implement cloud security best practices, identity management, and policy enforcement.
- Conduct regular reviews to ensure adherence to governance frameworks and compliance controls.
Performance Improvement & Process Excellence
- Identify low‑performing areas within cloud operations and drive corrective actions.
- Promote team discipline, attentiveness, and continuous improvement culture.
- Optimize existing cloud systems to enhance productivity, reliability, and efficiency.
Required Skills & Qualifications
8–12 years of experience in cloud engineering or related roles.
Strong expertise in Azure / AWS
- Bachelor's degree in Computer Science, Information Technology, or a related field (or equivalent experience).
- 8+ years of experience in Active Directory, Azure AD (Entra ID), and IAM technologies .
- Strong expertise in Azure AD B2B/B2C, Conditional Access, and RBAC (Role-Based Access Control) .
- Hands-on experience with Windows Server, DNS, DHCP, and AD Group Policy .
- Experience with PowerShell scripting and automation.
- Knowledge of Zero Trust security models and modern authentication protocols (OAuth, SAML, OpenID Connect) .
- Experience with Azure AD Connect, ADFS, and Hybrid Identity .
- Strong troubleshooting skills in identity federation, authentication, and authorization issues .
- Familiarity with Privileged Access Management (PAM) solutions such as CyberArk, BeyondTrust, or Azure PIM .
- Excellent communication and documentation skills.
- Hands-on experience with IaC (Terraform, Bicep, CloudFormation, etc.)
- Proficiency in scripting (PowerShell, Python, Bash).
- Strong understanding of networking, security, identity, and hybrid cloud architectures.
- Experience with DevOps tools such as GitHub Actions, Jenkins, Azure DevOps, or similar.
- Strong problem-solving, analytical thinking, and leadership capabilities.
#LI-SN1
You will be successful in this role if you have:
Preferred Qualifications
- Cloud Architect or DevOps certifications (Azure Architect Expert, AWS Solutions Architect, GCP Professional, etc.)
- Experience in AVD, serverless, containerization (AKS/EKS/GKE), and microservices.
- Knowledge of FinOps, SRE practices, and cost optimization strategies.
- Exposure to enterprise-scale cloud governance frameworks.
- Engineering degree and 6-8 years’ relevant experience OR equivalent combination of education and experience.
Unisys is proud to be an equal opportunity employer that considers all qualified applicants without regard to age, blood type, caste, citizenship, color, disability, family medical history, family status, ethnicity, gender, gender expression, gender identity, genetic information, marital status, national origin, parental status, pregnancy, race, religion, sex, sexual orientation, transgender status, veteran status or any other category protected by law.
Local employment practices and rights may vary by jurisdiction and are subject to applicable local laws. This commitment includes our efforts to provide for all those who seek to express interest in employment the opportunity to participate without barriers.
If you are a US job seeker unable to review the job opportunities herein, or cannot otherwise complete your expression of interest, without additional assistance and would like to discuss a request for reasonable accommodation, please contact our Global Recruiting organization at [email protected] . US job seekers can find more information about Unisys’ EEO commitment here .