Microsoft Cloud Architect

Posted 3 days ago

Worldwide

Summary

We're a Microsoft-focused managed and co-managed IT services partner serving growing mid-sized businesses (10–200 employees) across pharma and life sciences, manufacturing, nonprofits, food and beverage, architecture and engineering, professional services, commercial real estate, and healthcare. Our clients don't want five vendors pointing at each other — they want one accountable team covering strategy, operations, security, and compliance. We're looking for a Microsoft Cloud Architect to own the technical design behind that promise: the identity model, the endpoint baseline, the security posture, the migration plan, and the documentation that makes all of it repeatable. This is hands-on architecture, not slideware. You will design environments, then stand them up. What you'll own Identity as the foundation Entra ID as the central identity provider: user and group structure, role assignment, directory hygiene, application integration Conditional Access and MFA scoped to a client's actual risk posture and user populations — not a copy-pasted policy set SSPR, Privileged Identity Management with just-in-time elevation, and a real access review cadence for privileged roles Hybrid and federated designs where a non-Microsoft cloud directory or on-prem AD has to stay in the picture for a while License tier calls and their consequences: Business Premium vs. E3 or E5, where Entra ID P1 stops and P2 becomes necessary, what a client actually needs versus what they're paying for Endpoint and MDM Intune across mixed Windows and Apple fleets: enrollment, compliance policies, configuration profiles, app deployment, ongoing policy maintenance Windows Autopilot for zero-touch provisioning; Apple Business Manager including automatic enrollment through the client's reseller channel Hardening baselines covering security configuration, disk encryption, and update enforcement — plus the stricter baselines that NIST, CMMC, or HIPAA scopes demand Live asset inventory from the MDM agent, and a patch cadence for OS, Office, and the supported third-party catalog Security Defender for Endpoint and Defender for Business: deployment, detection and response policy, attack surface reduction rules Email security and anti-spoofing: spam and phishing filtering, sender authentication records, content policies Purview sensitivity labels and DLP across Exchange, SharePoint, OneDrive, and the collaboration workloads Audit logging and retention configured against compliance and legal hold requirements Working alongside our security operations partner — you set the architecture they monitor Email, tenant, and data migrations Tenant provisioning, defederation, and spin-outs from reseller platforms while preserving accounts, aliases, distribution groups, and domain configuration Mailbox migration into Exchange Online with wave-based cutover and reconciliation reporting at the close of each wave Mapping source-platform groups to the right Microsoft construct — distribution group, shared mailbox, or M365 group — and rebuilding forwarding and permissions so nothing breaks Monday morning SMTP relay and line-of-business app reconfiguration, documented and tested before the source platform is decommissioned DNS cutover runbooks covering mail routing, sender authentication, and autodiscover, with rollback procedures SharePoint information architecture, file share and cloud storage migration, and the permission restructuring that moves a client off individual file ownership onto group-based inheritance Hypercare through post-cutover stabilization Azure infrastructure IaaS reference architectures: VMs, managed disks, virtual networking, identity, security, backup Assessing when lift-and-shift is the honest answer and when a PaaS rearchitecture (Azure SQL Managed Instance, App Service) is worth the scope Resilience design, backup and recovery, and consumption modeling with reserved instances — Azure is billed by Microsoft directly, so cost estimates have to hold up Client-facing work and repeatability Discovery and environment audits producing license right-sizing recommendations and a prioritized gap list Solution design documents, baseline environment documentation, and roadmaps that feed the vCIO cadence Scoping and estimating with the sales team, and defending that scope in proposal review Recurring strategic reviews with client leadership on environment health, roadmap progress, and budget Runbooks, configuration baselines, and per-client onboarding and offboarding playbooks other engineers can execute without you Clean time entry, ticket notes, and task updates in our PSA. Documentation quality is part of the job, not overhead attached to it. What we're looking for Deep, current, production experience across Entra ID, Intune, Exchange Online, Defender, and Azure IaaS — in multi-tenant or managed services contexts, or supporting several distinct business units Real migration scars: you've cut mail routing over late on a Friday and know what breaks Working knowledge of at least one compliance framework in practice — FDA, CMMC, HIPAA, SOC 2 or similar Fluent written and spoken English, and the judgment to explain a tradeoff to a non-technical owner without condescending Someone who takes ownership, communicates proactively, and cares about the client outcome as much as the technical solution How we work We're a small, distributed team, built around people with real-world experience running IT inside companies like the ones we serve. Everything lives in client-owned Microsoft tenants rather than proprietary tools. Pricing is transparent and predictable, licensing passes through at list, and there are no long-term contracts to hide behind — which means the work has to be genuinely good. If you want meaningful, hands-on cloud architecture work for real companies without the bureaucracy of a large managed services firm, we'd like to hear from you.

  • More than 30 hrs/week
    Hourly
  • 6+ months
    Duration
  • Expert
    Experience Level
  • $35.00

    -

    $70.00

    Hourly
  • Remote Job
  • Ongoing project
    Project Type

Contract-to-hire opportunity

This lets talent know that this job could become full time.
Learn more
Skills and Expertise
Mandatory skills
Cloud Architecture
Cloud Security
Activity on this job
  • Proposals:20 to 50
  • Last viewed by client:2 days ago
  • Interviewing:
    3
  • Invites sent:
    13
  • Unanswered invites:
    9
About the client
Member since May 14, 2026
  • USA
    Chicago6:01 AM
  • $18K total spent
    6 hires, 6 active
  • 630 hours

Explore similar jobs on Upwork

Senior DevOps & Cloud EngineerFixed-price‐ Posted 2 weeks ago
DevOps
Linux System Administration
Embedded System
C
Online paid 45min interviews Belgium (FL)Fixed-price‐ Posted 1 month ago
Flemish Dialect
Dutch

How it works

  • Post a job icon
    Create your free profile
    Highlight your skills and experience, show your portfolio, and set your ideal pay rate.
  • Talent comes to you icon
    Work the way you want
    Apply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
  • Payment simplified icon
    Get paid securely
    From contract to payment, we help you work safely and get paid securely.
Want to get started? Create a profile

About Upwork

  • Rating is 4.9 out of 5.
    4.9/5
    (Average rating of clients by professionals)
  • G2 2021
    #1 freelance platform
  • 49,000+
    Signed contract every week
  • $2.3B
    Freelancers earned on Upwork in 2020

Find the best freelance jobs

Growing your career is as easy as creating a free profile and finding work like this that fits your skills.

Trusted by

  • Microsoft Logo
  • Airbnb Logo
  • Bissell Logo
  • GoDaddy Logo