With a company culture rooted in collaboration, expertise and innovation, we aim to promote progress and inspire our clients, employees, investors and communities to achieve their greatest potential. Our work is the catalyst that helps others achieve their goals. In short, We Enable Possibility℠. The Position A mid-level Infrastructure Cloud Engineer responsible for designing, operating, and evolving our Azure environment. This role focuses on architecture, hands-on operations, and translating business/technical requirements into sound Azure designs that Corporate then implements. This role will be responsible for automation of operations for infrastructure and financial operations to maintain predicable cost. Job Responsibilities Design Azure infrastructure architecture for new projects (networking topology, resource organization, subscription/resource group structure) Evaluate Azure services against business requirements and recommend solutions Produce and maintain architecture diagrams, design documents, and decision records for review with stakeholders Assess proposed changes for scalability, resilience, and cost impact before build Participate in architecture review sessions with Arch Re Enterprise Architecture team and Service Delivery management. Monitor resource health, utilization, and cost; flag optimization opportunities Design and build dashboards, scripts, tools and other assets to be used by the Infrastructure Operations team. Develop thresholds, alerting and supporting processes for incident routing. Troubleshoot infrastructure issues and produce root-cause analysis and remediation specs for Corporate to execute as a member of the level 3 Infrastructure support team Design and maintain in collaboration with Network Engineer specifications for VNets, subnets, peering, ExpressRoute/VPN, load balancers, and firewalls Design and maintain DNS and hybrid connectivity between on-prem and Arch cloud environments in Azure and AWS Design IAM/RBAC models and least-privilege access structures in Azure AD/Entra ID Review conditional access policies set by Corporate for segment requirements and access review processes and how they impact users and services delivered by Reinsurance IT Partner with security/compliance on identity governance given regulatory obligations (insurance/financial services) Ensure architecture designs meet compliance requirements (SOC 2, applicable insurance/financial regulations) Review security posture of existing cloud resources and recommend remediation Assist product teams with DevSecOps processes and remediations of findings where applicable. Support audits with architecture documentation and evidence Translate architecture designs into specifications and runbooks Corporate's build teams can execute (Terraform/ARM/Bicep requirements, pipeline requests) Review Corporate's IaC output against intended design for correctness Required Qualifications 3–5 years in infrastructure, systems administration, or cloud engineering At least 3 years hands-on experience with Azure native services (compute, storage, networking, Entra ID) AZ-104 or AZ-305 required Solid networking fundamentals (TCP/IP, DNS, VPN, load balancing, hybrid connectivity) Demonstrated 2 years’ experience writing and troubleshooting Infrastructure as Code (IaC) (Terraform or Bicep) Github in use for infrastructure scripting and IaC Scripting proficiency (PowerShell or Python) for diagnostics and reporting Experience with Windows/Linux server administration Preferred Qualifications Experience in a regulated industry (insurance, financial services) Familiarity with Azure AD/Entra ID governance, conditional access, and PIM Exposure to architecture frameworks (Azure Well-Architected Framework) AZ-305 (Azure Solutions Architect) certification Soft Skills Ability to design solutions independently while working within a shared build-automation model Strong documentation skills — designs must be handed off cleanly to a separate build team Strong communications skills – ability to interface directly with stakeholders in group meetings and one-on-one via email. Comfortable operating at the design/implementation boundary Strong sense of accountability and ownership. Able to take an incident or project to closure. For individuals assigned or hired to work in the location(s) indicated below, the base salary range is provided. Range is as of the time of posting. Position is incentive eligible. $125,000 - $155,000/year Total individual compensation (base salary, short & long-term incentives) offered will take into account a number of factors including but not limited to geographic location, scope & responsibilities of the role, qualifications, talent availability & specialization as well as business needs. The above pay range may be modified in the future. Arch is committed to helping employees succeed through our comprehensive benefits package that includes multiple medical plans plus dental, vision and prescription drug coverage; a competitive 401k with generous matching; PTO beginning at 20 days per year; up to 12 paid company holidays per year plus 2 paid days of Volunteer Time Offer; basic Life and AD&D Insurance as well as Short and Long-Term Disability; Paid Parental Leave of up to 10 weeks; Student Loan Assistance and Tuition Reimbursement, Backup Child and Elder Care; and more. Click here to learn more on available benefits. Do you like solving complex business problems, working with talented colleagues and have an innovative mindset? Arch may be a great fit for you. If this job isn’t the right fit but you’re interested in working for Arch, create a job alert! Simply create an account and opt in to receive emails when we have job openings that meet your criteria. Join our talent community to share your preferences directly with Arch’s Talent Acquisition team. 10200 Arch Capital Services LLC