Cloud Security Architect
⚲ Warszawa
36 288 - 38 472 PLN (B2B)
Wymagania
- AI
- Databricks
- Terraform
- GitHub
- Security
- DevOps
- Microsoft Azure
- Cloud security
- Python
- Azure
- Architecture
- Kubernetes (nice to have)
- GXP (nice to have)
- CSV (nice to have)
Opis stanowiska
O projekcie:
💻 Ework Group — founded in 2000 and listed on Nasdaq Stockholm — is a leading total talent solutions provider supporting clients across the private and public sectors, as well as independent professionals, in building sustainable talent supply chains.
With a strong focus on IT/OT, R&D, Engineering, and Business Development, Ework delivers value through an independent, holistic approach to total talent management.
For our Client from the healthcare sector, we are currently looking for:
☁️ Remote Staff Cloud Security Architect (AI Solutions)
📍 Location: Warsaw, Poland
🏢 Work model: Fully remote, ONLY IN POLAND, with occasional presence in the Warsaw Hub
📅 Start date: 03.08.2026
CONSULTANT MUST BE LOCATED IN POLAND
Recruitment language: English
Recruitment process: 2-stage online recruitment
Role overview:
We are looking for an experienced Cloud Security Architect to design and enable secure Azure-based architectures for modern AI-driven applications.
This is a hands-on, senior-level role, combining architectural ownership with close collaboration with engineering teams. You will define secure patterns, standards, and reusable frameworks while supporting teams in building scalable, compliant, and production-ready solutions.
The role focuses on secure cloud architecture, AI infrastructure, and DevOps modernization, rather than ownership of a single platform. Solutions are currently non-GxP, but must be designed with future regulatory readiness in mind.
Wymagania:
- Strong hands-on experience with Microsoft Azure cloud architecture- Excellent English speaking skills- Strong cloud security expertise, including identity, networking, encryption, secrets management, logging, monitoring, and secure access patterns- Experience designing secure infrastructure for AI applications, AI agents, APIs, data-consuming applications, or internal developer platforms- Experience with sandboxed code execution, Python runtime environments, containerized workloads, or isolated compute patterns- Familiarity with Databricks as a data source for applications- Strong knowledge of network segregation, private endpoints, firewalls, virtual networks, controlled egress, and runtime isolation- Strong experience with Terraform for infrastructure provisioning and cloud architecture enablement- Strong experience with GitHub Enterprise, GitHub Actions, repository governance, branch protection, pull requests, and secure CI/CD patterns- Experience with Azure DevOps, ideally including migration from Azure DevOps to GitHub- Experience with secrets management, key vaults, managed identities, service principals, RBAC, and Microsoft Entra ID- Understanding of secure software delivery, release controls, traceability, and audit-ready engineering practices- Ability to work hands-on with engineers while also setting architecture direction and technical standardsNice to have- Experience with Azure AI, Azure OpenAI, or GenAI application patterns- Experience with containers and orchestration (Kubernetes, Azure Container Apps, Functions)- Knowledge of GitHub Advanced Security (code scanning, secret scanning, dependency scanning)- Experience in regulated environments (healthcare, pharma, life sciences)- Understanding of GxP, CSV, CSA, or validation processes- Relevant certifications (e.g. Azure Solutions Architect, Azure Security Engineer, DevOps, Terraform)
Codzienne zadania:
- Design secure Azure cloud architectures for AI applications, data-driven applications, and internal digital products.
- Define architecture patterns for AI applications that consume data from Databricks and other enterprise data platforms.
- Establish secure patterns for AI agents, sandboxed Python/code execution, runtime isolation, network segregation, and controlled access to data and services.
- Design and implement standards for secrets management, identity, access control, encryption, logging, monitoring, and secure connectivity.
- Use Terraform to define, review, and enable repeatable cloud infrastructure patterns.
- Help drive the migration from Azure DevOps to GitHub Enterprise.
- Establish new GitHub-based CI/CD patterns, including repository standards, branching, pull requests, code reviews, automated testing, approvals, deployment gates, and release evidence.
- Define technical standards for secure software delivery, release traceability, and audit-ready engineering practices.
- Partner with engineering teams to implement reference architectures, reusable templates, pipelines, and secure cloud patterns.
- Review solution designs, identify security risks, and guide teams toward practical, compliant, and maintainable implementations.
- Collaborate with cloud, security, data, AI, quality, compliance, and product teams.
- Mentor engineers and improve engineering practices across cloud, security, DevOps, and AI infrastructure.
💻 Ework Group — founded in 2000 and listed on Nasdaq Stockholm — is a leading total talent solutions provider supporting clients across the private and public sectors, as well as independent professionals, in building sustainable talent supply chains.
With a strong focus on IT/OT, R&D, Engineering, and Business Development, Ework delivers value through an independent, holistic approach to total talent management.
For our Client from the healthcare sector, we are currently looking for:
☁️ Remote Staff Cloud Security Architect (AI Solutions)
📍 Location: Warsaw, Poland
🏢 Work model: Fully remote, ONLY IN POLAND, with occasional presence in the Warsaw Hub
📅 Start date: 03.08.2026
CONSULTANT MUST BE LOCATED IN POLAND
Recruitment language: English
Recruitment process: 2-stage online recruitment
Role overview:
We are looking for an experienced Cloud Security Architect to design and enable secure Azure-based architectures for modern AI-driven applications.
This is a hands-on, senior-level role, combining architectural ownership with close collaboration with engineering teams. You will define secure patterns, standards, and reusable frameworks while supporting teams in building scalable, compliant, and production-ready solutions.
The role focuses on secure cloud architecture, AI infrastructure, and DevOps modernization, rather than ownership of a single platform. Solutions are currently non-GxP, but must be designed with future regulatory readiness in mind.
Wymagania:
- Strong hands-on experience with Microsoft Azure cloud architecture- Excellent English speaking skills- Strong cloud security expertise, including identity, networking, encryption, secrets management, logging, monitoring, and secure access patterns- Experience designing secure infrastructure for AI applications, AI agents, APIs, data-consuming applications, or internal developer platforms- Experience with sandboxed code execution, Python runtime environments, containerized workloads, or isolated compute patterns- Familiarity with Databricks as a data source for applications- Strong knowledge of network segregation, private endpoints, firewalls, virtual networks, controlled egress, and runtime isolation- Strong experience with Terraform for infrastructure provisioning and cloud architecture enablement- Strong experience with GitHub Enterprise, GitHub Actions, repository governance, branch protection, pull requests, and secure CI/CD patterns- Experience with Azure DevOps, ideally including migration from Azure DevOps to GitHub- Experience with secrets management, key vaults, managed identities, service principals, RBAC, and Microsoft Entra ID- Understanding of secure software delivery, release controls, traceability, and audit-ready engineering practices- Ability to work hands-on with engineers while also setting architecture direction and technical standardsNice to have- Experience with Azure AI, Azure OpenAI, or GenAI application patterns- Experience with containers and orchestration (Kubernetes, Azure Container Apps, Functions)- Knowledge of GitHub Advanced Security (code scanning, secret scanning, dependency scanning)- Experience in regulated environments (healthcare, pharma, life sciences)- Understanding of GxP, CSV, CSA, or validation processes- Relevant certifications (e.g. Azure Solutions Architect, Azure Security Engineer, DevOps, Terraform)
Codzienne zadania:
- Design secure Azure cloud architectures for AI applications, data-driven applications, and internal digital products.
- Define architecture patterns for AI applications that consume data from Databricks and other enterprise data platforms.
- Establish secure patterns for AI agents, sandboxed Python/code execution, runtime isolation, network segregation, and controlled access to data and services.
- Design and implement standards for secrets management, identity, access control, encryption, logging, monitoring, and secure connectivity.
- Use Terraform to define, review, and enable repeatable cloud infrastructure patterns.
- Help drive the migration from Azure DevOps to GitHub Enterprise.
- Establish new GitHub-based CI/CD patterns, including repository standards, branching, pull requests, code reviews, automated testing, approvals, deployment gates, and release evidence.
- Define technical standards for secure software delivery, release traceability, and audit-ready engineering practices.
- Partner with engineering teams to implement reference architectures, reusable templates, pipelines, and secure cloud patterns.
- Review solution designs, identify security risks, and guide teams toward practical, compliant, and maintainable implementations.
- Collaborate with cloud, security, data, AI, quality, compliance, and product teams.
- Mentor engineers and improve engineering practices across cloud, security, DevOps, and AI infrastructure.
🔍 Dekoder Ogłoszenia
🔴
This is a hands-on, senior-level role, combining architectural ownership with close collaboration with engineering teams.
Oczekuje się, że będziesz nie tylko projektować, ale także aktywnie wdrażać rozwiązania i pomagać zespołom inżynierskim w ich implementacji.
🔴
You will define secure patterns, standards, and reusable frameworks while supporting teams in building scalable, compliant, and production-ready solutions.
Twoja rola będzie polegać na tworzeniu szablonów i wytycznych, ale faktyczne wdrażanie i rozwiązywanie problemów będzie należeć do zespołów inżynierskich, którym będziesz pomagać.
🟡
The role focuses on secure cloud architecture, AI infrastructure, and DevOps modernization, rather than ownership of a single platform.
Nie będziesz ekspertem od jednej konkretnej technologii, ale będziesz musiał mieć szeroką wiedzę z kilku obszarów i umieć je integrować.
🟡
Solutions are currently non-GxP, but must be designed with future regulatory readiness in mind.
Obecnie projekt nie podlega ścisłym regulacjom medycznym, ale musisz projektować z myślą o przyszłych, potencjalnie bardziej restrykcyjnych wymogach.
🔴
Fully remote, ONLY IN POLAND, with occasional presence in the Warsaw Hub
Praca jest zdalna, ale wymaga posiadania miejsca zamieszkania w Polsce i gotowości do okazjonalnych wizyt w biurze w Warszawie.