---
title: Cloud Architect at EPAM Systems
description: We are seeking an experienced Cloud Architect to join our team and contribute to the delivery of a Unified Automation Platform. This Internal Developer Platform (IDP) will standardize new-project deli
---

# Cloud Architect

**Company:** EPAM Systems  
**Location:** Georgia  
**Posted:** 2026-09-03  
**Apply by:** 2026-10-18

**Tags:** architect

[Apply / View original posting](https://www.linkedin.com/jobs/view/4461697909)

## Job description

We are seeking an experienced Cloud Architect to join our team and contribute to the delivery of a Unified Automation Platform. This Internal Developer Platform (IDP) will standardize new-project delivery, centralize access to development resources, and enable software creation through templates and golden paths. The role focuses on architecting Azure-based infrastructure, identity, and Kubernetes foundations that power self-service capabilities across hybrid environments spanning Azure and on-premises VMware. Experience the freedom of remote work from anywhere in Georgia, whether from the comfort of your home, our modern offices in Tbilisi and Batumi or a coworking space in Kutaisi. Responsibilities Architect Infrastructure as Code modules (Terraform/OpenTofu) for Azure App Services, Container Apps, and Function Apps, as well as Azure SQL, Azure Cosmos DB, and Azure Postgres, including the Azure VMware Solution (AVS) private cloud module with managed-identity wiring, private endpoints, and diagnostic settings to Log Analytics Define the Azure identity architecture in partnership with the security team, covering Entra ID, Active Directory, and Group Policy Objects, along with M365 groups, SPN/app registrations, and managed identities, ensuring secrets land in OpenBao/Key Vault per platform standards Design the Azure Kubernetes Service (AKS) platform, including cluster and node-pool design, baseline add-on stack (ingress, cert-manager, external-dns, monitoring, policy), namespace/tenant onboarding, and an operations dashboard for cluster management Collaborate with the Network Architect on core connectivity (VNets, Application Gateway, WAF), Azure Firewall, NSGs, and DNS, NetBox IPAM, and ExpressRoute connectivity, ensuring Azure compute, database, and AKS modules integrate cleanly with the network foundation Define the Image Factory architecture for VM and container golden images, covering Linux and Windows/cloudbase-init baselines, CIS hardening, agent injection, and image scanning with Shared Image Gallery publishing/versioning Establish foundational Infrastructure as Code Engine standards (remote state/backend, locking, RBAC), including module registry, testing framework, drift detection, policy hooks, and secrets injection consumed by all other automation modules Partner with the Backstage Architect to expose Azure provisioning capabilities as Backstage golden-path templates, and with Integration Architects on observability, ITSM/CMDB, and security integrations touching Azure resources Provide architectural governance during Implementation, validate production deployments, and support module lifecycle ownership during Adoption Requirements 10+ years of proven Azure solution/enterprise architecture experience, ideally validated through Microsoft Azure partner-level engagements or equivalent certifications Deep expertise in Terraform/OpenTofu for Azure infrastructure automation, including module design, state management, and CI/CD-driven deployment pipelines (Azure DevOps) Working knowledge of Azure networking constructs (VNets, private endpoints, NSGs) sufficient to integrate compute and data modules with the network foundation owned by the Network Architect Hands-on experience architecting Azure Kubernetes Service (AKS) at production scale, including networking, policy, and multi-tenant namespace design Background in Azure identity and access architecture (Entra ID, Active Directory, managed identities, RBAC) and secrets integration (Azure Key Vault, dynamic secrets) Proficiency in Configuration as Code (Ansible) for VM post-provisioning and golden-image pipelines Excellent command of English (B2+ level), both written and spoken, with a strong emphasis on technical communication skills Nice to have Experience with Azure VMware Solution (AVS) private cloud provisioning Familiarity with certificate lifecycle management platforms (e.g., Venafi) and their integration with Azure Key Vault Skills in integrating Azure infrastructure automation with a Backstage-based (or comparable) developer portal Knowledge of policy-as-code engines (OPA/Conftest, Azure Policy) for automated compliance enforcement Prior experience in large-scale, multi-region Azure landing-zone or platform engineering We offer We connect like-minded people Delivering innovative solutions to industry leaders, making a global impact Enjoyable working environment, whether it is the vibrant office or the comfort of your own home Opportunity to work abroad for up to two months per year Relocation opportunities within our offices in 55+ countries Corporate and social events We invest in your growth Leadership development, career advising, soft skills and well-being programs Certifications, including GCP, Azure and AWS Unlimited access to EPAM's internal learning database Free English classes with certified teachers We cover it all Participation in the Employee Stock Purchase Plan Monetary bonuses for engaging in the referral program Comprehensive medical & family care package Five trust days per year (sick leave without a medical certificate) Benefits package (sports activities, a variety of stores and services) EPAM is global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and ambitious startups. With over thirty years of expertise in custom software, product and platform engineering, we empower our clients to become AI-Native enterprises, driving measurable value from innovation and digital investments.

---

🔔 [Monitor similar jobs on Gurify](https://gurify.com/?utm_source=techgeo&utm_medium=jobboard&utm_campaign=monitor_similar&role=Cloud+Architect) — get alerted when matching roles are posted in Georgia.

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Cloud Architect","description":"<p>We are seeking an experienced Cloud Architect to join our team and contribute to the delivery of a Unified Automation Platform. This Internal Developer Platform (IDP) will standardize new-project delivery, centralize access to development resources, and enable software creation through templates and golden paths. The role focuses on architecting Azure-based infrastructure, identity, and Kubernetes foundations that power self-service capabilities across hybrid environments spanning Azure and on-premises VMware. Experience the freedom of remote work from anywhere in Georgia, whether from the comfort of your home, our modern offices in Tbilisi and Batumi or a coworking space in Kutaisi. Responsibilities Architect Infrastructure as Code modules (Terraform/OpenTofu) for Azure App Services, Container Apps, and Function Apps, as well as Azure SQL, Azure Cosmos DB, and Azure Postgres, including the Azure VMware Solution (AVS) private cloud module with managed-identity wiring, private endpoints, and diagnostic settings to Log Analytics Define the Azure identity architecture in partnership with the security team, covering Entra ID, Active Directory, and Group Policy Objects, along with M365 groups, SPN/app registrations, and managed identities, ensuring secrets land in OpenBao/Key Vault per platform standards Design the Azure Kubernetes Service (AKS) platform, including cluster and node-pool design, baseline add-on stack (ingress, cert-manager, external-dns, monitoring, policy), namespace/tenant onboarding, and an operations dashboard for cluster management Collaborate with the Network Architect on core connectivity (VNets, Application Gateway, WAF), Azure Firewall, NSGs, and DNS, NetBox IPAM, and ExpressRoute connectivity, ensuring Azure compute, database, and AKS modules integrate cleanly with the network foundation Define the Image Factory architecture for VM and container golden images, covering Linux and Windows/cloudbase-init baselines, CIS hardening, agent injection, and image scanning with Shared Image Gallery publishing/versioning Establish foundational Infrastructure as Code Engine standards (remote state/backend, locking, RBAC), including module registry, testing framework, drift detection, policy hooks, and secrets injection consumed by all other automation modules Partner with the Backstage Architect to expose Azure provisioning capabilities as Backstage golden-path templates, and with Integration Architects on observability, ITSM/CMDB, and security integrations touching Azure resources Provide architectural governance during Implementation, validate production deployments, and support module lifecycle ownership during Adoption Requirements 10+ years of proven Azure solution/enterprise architecture experience, ideally validated through Microsoft Azure partner-level engagements or equivalent certifications Deep expertise in Terraform/OpenTofu for Azure infrastructure automation, including module design, state management, and CI/CD-driven deployment pipelines (Azure DevOps) Working knowledge of Azure networking constructs (VNets, private endpoints, NSGs) sufficient to integrate compute and data modules with the network foundation owned by the Network Architect Hands-on experience architecting Azure Kubernetes Service (AKS) at production scale, including networking, policy, and multi-tenant namespace design Background in Azure identity and access architecture (Entra ID, Active Directory, managed identities, RBAC) and secrets integration (Azure Key Vault, dynamic secrets) Proficiency in Configuration as Code (Ansible) for VM post-provisioning and golden-image pipelines Excellent command of English (B2+ level), both written and spoken, with a strong emphasis on technical communication skills Nice to have Experience with Azure VMware Solution (AVS) private cloud provisioning Familiarity with certificate lifecycle management platforms (e.g., Venafi) and their integration with Azure Key Vault Skills in integrating Azure infrastructure automation with a Backstage-based (or comparable) developer portal Knowledge of policy-as-code engines (OPA/Conftest, Azure Policy) for automated compliance enforcement Prior experience in large-scale, multi-region Azure landing-zone or platform engineering We offer We connect like-minded people Delivering innovative solutions to industry leaders, making a global impact Enjoyable working environment, whether it is the vibrant office or the comfort of your own home Opportunity to work abroad for up to two months per year Relocation opportunities within our offices in 55+ countries Corporate and social events We invest in your growth Leadership development, career advising, soft skills and well-being programs Certifications, including GCP, Azure and AWS Unlimited access to EPAM's internal learning database Free English classes with certified teachers We cover it all Participation in the Employee Stock Purchase Plan Monetary bonuses for engaging in the referral program Comprehensive medical & family care package Five trust days per year (sick leave without a medical certificate) Benefits package (sports activities, a variety of stores and services) EPAM is global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and ambitious startups. With over thirty years of expertise in custom software, product and platform engineering, we empower our clients to become AI-Native enterprises, driving measurable value from innovation and digital investments.</p>","identifier":{"@type":"PropertyValue","name":"TechGeo","value":"4461697909"},"url":"https://techgeo.ge/job/cloud-architect-eb33b3c","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Georgia","addressCountry":"GE"}},"hiringOrganization":{"@type":"Organization","name":"EPAM Systems"},"directApply":false,"datePosted":"2026-09-03","validThrough":"2026-10-18T23:59:59+04:00"}
```
