About this role
We never ask for payment as part of our selection process, and we always contact candidates via our corporate accounts and platforms. If you are approached for payment, this is likely to be fraudulent. Please check to see whether the role you are interested in is posted here, on our website.
TMF Group is a leading provider of administrative services, helping clients invest and operate safely around the world. As a global company with 11,000+ colleagues based in over 125 offices across 87 jurisdictions, we actively seek out people with the talent and potential to flourish at TMF Group, whatever their background, and offer job opportunities to the broadest spectrum of people. Once on board, we nurture and promote talented individuals, ensuring that senior positions are open to all.
TMF India is a Great Place to Work, ISO & ISAE certified organization.
Discover the Role
This role is positioned as a strategic architecture leader and enterprise design authority, not simply as a senior technical specialist. The ideal candidate combines deep Azure, infrastructure, cybersecurity, AKS, platform engineering and AI architecture expertise with the ability to influence global technology direction, govern enterprise standards, modernize platforms, reduce risk, and enable secure AI-driven transformation at scale.
Role shall be focused around Platform Landing Zone / AI Landing Zone, management groups, subscription structure, connectivity, identity, policy foundations, architecture governance, HLD/LLD/SOP/runbook transition gates, data/AI governance and reusable engineering patterns. TMF’s infrastructure standards is a hybrid setup across on-premises and cloud, with security, DR, monitoring, governance, application architecture, containerization, microservices/serverless and cost-management requirements, plus Azure PaaS / private endpoint expectations and AKS as a key Azure service. Use CAF methodologies for Strategy, Plan, Ready, Adopt, Govern, Secure and Manage, Azure landing zone design areas across identity, resource organization, network, security, governance, management and platform automation/DevOps, AKS baseline architecture patterns for secure, observable, production-ready clusters, and responsible AI practices built around identify, measure, mitigate and operate.
Key Responsibilities
1. Architecture Leadership & Technology Strategy
- Define and maintain the enterprise target-state architecture for cloud, infrastructure, cybersecurity, platform engineering, cloud-native services and AI enablement.
- Translate business strategy, risk appetite, regulatory needs and technology trends into actionable architecture roadmaps and investment priorities.
- Establish architecture principles, reference architectures, decision frameworks and reusable patterns for global technology delivery.
- Lead architecture governance through Architecture Review Board / TDA-style forums, ensuring early design alignment before delivery execution.
- Own architecture standards for landing zones, connectivity, identity, security, monitoring, automation, resilience, workload onboarding and operational readiness.
- Provide executive-level technology advisory, clearly explaining architectural trade-offs, risk implications, cost impacts and transformation benefits.
- Ensure architecture decisions are documented through architecture decision records, design standards, patterns, exceptions and lifecycle governance.
- Drive architecture maturity from reactive delivery to repeatable, governed engineering patterns, aligned with TMF’s stated architecture direction for reusable blueprints, governance and platform scale.
2. Cloud Transformation & Hybrid Infrastructure Modernization
- Lead the evolution of TMF’s Azure-first cloud architecture, including platform landing zones, management groups, subscriptions, policy, identity, connectivity and shared services.
- Define architecture patterns for hybrid cloud integration across Azure, on-premises Microsoft HCI / Azure Stack HCI, Azure Arc, data centers and public cloud services.
- Guide modernization of legacy infrastructure into scalable, resilient, secure and automation-enabled platforms.
- Establish standards for subscription segmentation, environment isolation, resource organization, tagging, cost allocation, network topology, DNS, private endpoints and region strategy.
- Design and govern hybrid connectivity patterns including ExpressRoute, VPN, hub-spoke networking, Azure Firewall, Azure WAF, Azure Front Door, private DNS and secure egress.
- Lead infrastructure lifecycle modernization, including technical debt reduction, operating system refresh, data center transformation, platform migration and cloud optimization.
- Drive resilience-by-design across backup, disaster recovery, failover, high availability, observability and recovery testing.
- Ensure cloud architecture aligns with CAF / Azure Landing Zone principles for identity, resource organization, network topology, security, governance, management and platform automation.
3. Cybersecurity Architecture, Governance & Risk Reduction
- Define enterprise security architecture patterns across identity, network, endpoint, cloud, application, data, container, AI and platform layers.
- Embed secure-by-design and Zero Trust principles into all architecture decisions.
- Govern implementation of security controls across Microsoft Entra ID, RBAC, Privileged Identity Management, Conditional Access, MFA, managed identities, Key Vault, private endpoints and network segmentation.
- Define architecture standards for cloud security posture management, vulnerability management, public exposure controls, privileged access, service accounts, secrets management and certificate lifecycle.
- Partner with cybersecurity, risk, compliance and engineering teams to align architecture with CIS, NIST, ISO 27001, SOC 2, GDPR and internal policy expectations.
- Drive architecture-level remediation plans for audit findings, red-team findings, CSPM gaps, insecure configurations and exception governance.
- Establish secure patterns for DevSecOps, CI/CD, code scanning, container image scanning, secrets scanning, infrastructure policy enforcement and automated compliance.
- Maintain audit-ready evidence of architecture decisions, design approvals, risk acceptances and security exceptions.
4. Cloud Operating Model, Platform Engineering & DevSecOps
- Define TMF’s cloud operating model across platform teams, application teams, cybersecurity, operations, FinOps and governance functions.
- Lead the design of internal developer / platform engineering capabilities that enable self-service, governed workload onboarding and repeatable infrastructure provisioning.
- Establish golden paths and reusable platform blueprints for compute, networking, identity, observability, security, CI/CD, IaaC and service onboarding.
- Govern Infrastructure-as-Code standards using Terraform, Bicep, ARM templates or equivalent enterprise tooling.
- Define DevSecOps patterns using Azure DevOps, GitHub Actions or equivalent platforms, including build, test, deploy, security validation, rollback and change governance.
- Implement policy-as-code, guardrails, automated compliance checks and deployment gates to reduce delivery risk.
- Drive FinOps architecture practices, including cost visibility, tagging, reserved capacity, rightsizing, budget alerts and cloud optimization.
- Ensure HLD, LLD, SOP, runbook, KT and support sign-off are treated as mandatory transition gates for production readiness, consistent with TMF’s internal architecture direction.
5. AKS, Containers & Cloud-Native Architecture
- Own enterprise architecture standards for Azure Kubernetes Service (AKS) and related Azure cloud-native services.
- Define production-grade AKS architecture patterns covering private clusters, Azure CNI, node pools, workload isolation, ingress/egress, WAF, API server security, autoscaling, upgrade strategy, backup, DR and multi-region design where required.
- Establish standards for Azure Container Registry, image governance, image signing/scanning, authorized registries, vulnerability scanning and container supply-chain security.
- Define GitOps-based cluster bootstrapping and configuration management using Flux v2, Argo CD or equivalent approaches.
- Govern Kubernetes policy enforcement using Azure Policy for AKS, OPA Gatekeeper, Kyverno or equivalent policy engines.
- Define architecture for observability across AKS and container workloads using Azure Monitor, Log Analytics, Dynatrace, Grafana, Application Insights, Open Telemetry and distributed tracing.
- Define cloud-native architecture standards for microservices, APIs, event-driven architectures, serverless workloads, containerized applications, PaaS services and resilient distributed systems.
- Ensure AKS designs align with Microsoft AKS baseline guidance, including observability, secure networking, private endpoints for services such as Azure Container Registry and Key Vault, private cluster considerations, GitOps, and workload / cluster operations. AKS Well-Architected guidance also emphasizes reliability, security, cost optimization, operational excellence and performance efficiency across cluster and workload responsibilities.
6. AI Platform Architecture & Enterprise AI Enablement
- Define the enterprise architecture for AI platform enablement across Azure AI Foundry, Azure OpenAI, Azure AI Services, Azure AI Search, Azure Machine Learning, Azure Bot Service, Microsoft Fabric / Databricks integrations and agentic AI platforms.
- Design and govern AI Landing Zone patterns covering management groups, subscriptions, network isolation, private endpoints, RBAC, managed identities, data classification, cost controls, logging and monitoring.
- Establish architecture standards for secure AI integration patterns including Retrieval Augmented Generation, embeddings, vector stores, grounding data, API gateways, model endpoints and enterprise knowledge integration.
- Define responsible AI governance requirements including AI impact assessment, model risk assessment, prompt-injection controls, content safety, guardrails, human-in-the-loop checkpoints, transparency, explainability, audit trails and feedback loops.
- Partner with data, security, legal, compliance and business teams to define AI usage policies, approved data pathways, data residency requirements, privacy controls and enterprise AI adoption guardrails.
- Govern Azure OpenAI and Foundry deployments for data security, including private networking, identity-based access, monitoring, abuse prevention, content filtering, prompt/response logging policies and data-retention considerations.
- Drive AI adoption roadmaps that prioritize use cases by business value, technical feasibility, data readiness, risk and operational maturity.
- Support AI-powered operations, intelligent automation, copilots and agent-based workflows while ensuring adoption is governed, secure and measurable.
- Microsoft’s responsible AI guidance recommends identifying, measuring, mitigating and operating against potential AI harms, while Microsoft Foundry architecture supports governance through a top-level Foundry resource, project-level development boundaries and connected Azure services such as Storage, Key Vault and Azure AI Search with separate governance boundaries. Azure OpenAI / Foundry data privacy guidance states that prompts, completions, embeddings and training data are not available to other customers and are not used to train generative AI foundation models without permission or instruction.
7. Stakeholder Management, Governance Forums & Strategic Roadmaps
- Work closely with senior stakeholders across Technology, Security, Operations, Product, Data, Finance, Risk and business functions.
- Chair or actively guide architecture governance forums, ensuring decisions are transparent, traceable and aligned to enterprise standards.
- Build multi-year roadmaps for cloud modernization, infrastructure transformation, AKS adoption, platform engineering, cybersecurity architecture and AI enablement.
- Support technology due diligence, M&A integration architecture, platform onboarding, global rollout planning and integration risk assessment.
- Evaluate emerging technologies, vendors and platforms, producing recommendations based on business value, security, scalability, operational fit and total cost of ownership.
- Mentor architects, engineers and technical leads, raising architecture quality and building enterprise-wide technical capability.
Key Requirements
Competencies & Skills
Enterprise Architecture & Strategic Leadership
- Expert ability to define enterprise target-state architecture, transition architecture and multi-year roadmaps.
- Strong knowledge of enterprise architecture frameworks such as TOGAF, ArchiMate, SABSA or equivalent practical architecture methods.
- Ability to govern architecture across complex global environments while balancing agility, risk, cost and operational constraints.
- Strong executive communication, decision framing, stakeholder management and architecture storytelling skills.
- Proven ability to influence without direct authority and drive alignment across senior technical and business stakeholders.
Azure & Hybrid Cloud Architecture
- Expert-level Azure architecture across landing zones, management groups, subscriptions, Azure Policy, Azure Monitor, Azure Arc, Azure Key Vault, Azure Firewall, Azure WAF, Azure Front Door, Azure DNS, Private Link, ExpressRoute, VPN Gateway and hybrid networking.
- Deep understanding of Microsoft Entra ID, RBAC, PIM, Conditional Access, MFA, managed identities and workload identity.
- Strong experience with hybrid platforms including Microsoft HCI / Azure Stack HCI, Azure Arc-enabled servers and hybrid governance.
- Strong understanding of IaaS, PaaS, SaaS, serverless, event-driven and cloud-native design patterns.
AKS, Kubernetes & Cloud-Native Engineering
- Expert knowledge of AKS architecture, Kubernetes concepts, node pools, namespaces, ingress/egress, service discovery, Helm, CRDs, operators, autoscaling and upgrade patterns.
- Strong experience designing secure private AKS clusters, Azure CNI, network policies, workload identities, Key Vault CSI driver, ACR integration and Kubernetes RBAC.
- Strong knowledge of Azure Container Registry, Azure Container Apps, Azure Arc-enabled Kubernetes and Azure Kubernetes Configuration Management.
- Strong observability knowledge across Azure Monitor, Log Analytics, Managed Prometheus, Grafana, Application Insights, Open Telemetry, distributed tracing and SLO/SLA design.
Cybersecurity Architecture
- Strong security architecture experience across Zero Trust, identity, network segmentation, endpoint, cloud, container, application and data security.
- Deep understanding of encryption, secrets management, Key Vault, certificate lifecycle, vulnerability management, CSPM, Defender for Cloud, Microsoft Sentinel and SIEM integrations.
- Knowledge of security frameworks and compliance expectations such as CIS, NIST, ISO 27001, SOC 2, GDPR and cloud security benchmarks.
- Ability to perform threat modeling and define architecture controls to reduce risk before delivery.
Platform Engineering, Automation & DevSecOps
- Strong expertise in Infrastructure-as-Code using Terraform, Bicep, ARM templates or equivalent tooling.
- Strong CI/CD and DevSecOps experience using Azure DevOps, GitHub Actions or equivalent platforms.
- Experience defining golden paths, reusable platform templates, policy-as-code, automated compliance and self-service workload onboarding.
- Ability to build engineering standards that reduce complexity, improve consistency and accelerate secure delivery.
AI Architecture & Responsible AI
- Strong exposure to Azure AI Foundry, Azure OpenAI, Azure AI Services, Azure AI Search, Azure Machine Learning, Azure Bot Service, Microsoft Fabric and Databricks integrations.
- Understanding of RAG, embeddings, vector databases, grounding, prompt engineering, model evaluation, LLMOps / GenAIOps and AI observability.
- Knowledge of responsible AI governance including impact assessments, guardrails, content safety, prompt injection mitigation, data privacy, transparency, explainability and human oversight.
- Ability to define secure AI integration patterns across enterprise applications, APIs, data platforms, identity and network controls.
Required Experience
- Typically 15+ years of progressive technology experience, including significant experience in enterprise architecture, infrastructure, cloud, cybersecurity or platform engineering.
- Typically 8+ years of architecture leadership experience across enterprise-scale infrastructure, cloud, security or platform modernization.
- Proven experience defining and governing architecture in a large, global, hybrid enterprise environment.
- Demonstrated experience with Microsoft Azure enterprise architecture, Azure landing zones, hybrid connectivity, cloud governance, security architecture and operational resilience.
- Hands-on or architecture leadership experience with AKS, Kubernetes, container platforms, cloud-native architectures and DevSecOps delivery models.
- Experience leading architecture governance forums, design reviews, technology standards, architecture roadmaps and strategic decision-making.
- Experience partnering with cybersecurity, infrastructure, operations, application, data, finance and business stakeholders.
- Demonstrated ability to mentor senior engineers / architects and raise enterprise architecture maturity.
- Experience in regulated or compliance-sensitive environments is strongly preferred.
Required Technical Depth
- Azure enterprise architecture, hybrid cloud, landing zones, identity, networking, security and governance.
- AKS / Kubernetes architecture, container platforms, GitOps, IaC, CI/CD and observability.
- Cybersecurity architecture including Zero Trust, cloud security posture, identity security, network segmentation and data protection.
- AI platform architecture exposure, including Azure OpenAI / Azure AI Foundry and responsible AI governance.
- Strong understanding of architecture documentation, HLD, LLD, SOP, runbook, operational readiness and architecture decision records.
Education
- Bachelor’s degree in Computer Science, Information Technology, Engineering, Cybersecurity or related discipline, or equivalent enterprise technology experience.
- Master’s degree in technology, business, engineering, cybersecurity or related discipline is preferred.
Preferred Certifications
- Microsoft Certified: Azure Solutions Architect Expert.
- Microsoft Certified: Cybersecurity Architect Expert.
- Microsoft Certified: Azure Security Engineer Associate.
- Microsoft Certified: DevOps Engineer Expert.
- Microsoft Certified: Azure AI Engineer Associate.
- Certified Kubernetes Administrator, Certified Kubernetes Application Developer or Certified Kubernetes Security Specialist.
- Enterprise architecture certification.
- CISSP, CCSP, CISM, CISA or equivalent cybersecurity certification.
- FinOps Certified Practitioner or equivalent cloud cost-management certification.
What’s in it for you?
Pathways for career development
- Work with colleagues and clients around the world on interesting and challenging work;
- We provide internal career opportunities so you can take your career further within TMF;
- Continuous development is supported through global learning opportunities from the TMF Business Academy.
Making an impact
- You’ll be helping us to make the world a simpler place to do business for our clients;
- Through our corporate social responsibility programme, you’ll also be making a difference in the communities where we work.
A supportive environment
- Strong feedback culture to help build an engaging workplace;
- Our inclusive work environment allows you to work from our offices around the world, as well as from home, helping you find the right work-life balance to perform at your best.
Other Benefits
- Anniversary & Birthday Leave policy
- Be part of One TMF
- Paternity & Adoption leaves
- Salary advance policy
- Work flexibility – Hybrid work model
- Talk about growth opportunities (we invest in talent)
- Well-being initiatives
We’re looking forward to getting to know you!