Cloud Architect
28 days ago
City of London
Azure IaaS Cloud Architect â Azure Networking (Primary), SAP Migration, Landing Zones & FinOps Role Summary We are seeking a Senior Azure IaaS Cloud Architect with Azure Networking as the primary skill, complemented by deep SAP on Azure IaaS experience and strong FinOps discipline. This role owns the networkâfirst, costâaware infrastructure architecture for SAP workloads on Azure, ensuring secure, highâperformance, highly available, and financially optimized Azure environments. The architect will design enterprise Azure networking, lead SAP migrations to Azure IaaS, and apply FinOps principles to control and optimize infrastructure spend across SAP landscapes. Primary Skill Area: Azure Networking (Critical & Mandatory) The successful candidate must be a strong Azure Network Architect first, with SAP, IaaS, and FinOps capabilities built on top of this foundation. Azure Networking Responsibilities ⢠Architect and own enterprise Azure networking designs, including:, ⢠Hubâandâspoke topology, ⢠Virtual WAN (where applicable), ⢠Design SAPâoptimized Azure network architectures, covering:, ⢠VNet and subnet design per SAP tier, ⢠Latency, throughput, MTU, and routing considerations, ⢠SAP interâtier communication flows, ⢠Lead hybrid connectivity architecture, including:, ⢠ExpressRoute (mandatory, primary connectivity), ⢠SiteâtoâSite VPN (secondary / DR), ⢠Design and govern:, ⢠Network Security Groups (NSGs), ⢠User Defined Routes (UDRs), ⢠Azure Firewall and/or NVAs, ⢠Architect secure ingress and egress using:, ⢠Azure Load Balancer, ⢠Application Gateway (WAF), ⢠Define DNS, routing, and trafficâflow strategies for SAP users, integrations, and management services, ⢠Ensure networking aligns with Zero Trust, enterprise security, and SAP certification requirements Azure IaaS Architecture (Secondary, CostâAware) ⢠Architect enterpriseâscale Azure IaaS platforms for SAP workloads, ⢠Design and govern:, ⢠SAPâcertified Azure Virtual Machines, ⢠Managed disks (Premium / Ultra), ⢠Availability Sets and Availability Zones, ⢠Own infrastructure sizing, capacity planning, and performance tuning for SAP HANA, ⢠Define OSâlevel standards (Linux / Windows) for SAP, ⢠Design HA/DRâready infrastructure meeting strict RTO/RPO targets SAP on Azure IaaS â Migration & Runtime ⢠Lead SAP ECC and SAP S/4HANA migrations to Azure IaaS, ⢠Architect SAPâcertified designs including:, ⢠ASCS/ERS high availability, ⢠HANA scaleâup and scaleâout, ⢠Crossâzone and crossâregion resilience, ⢠Design SAP disaster recovery using Azure Site Recovery, ⢠Work closely with SAP Basis teams to ensure SAP supportability, ⢠Support cutover, goâlive, and postâmigration stabilization Azure Landing Zones â Networkâ & CostâCentric ⢠Design and implement Azure Landing Zones with a networkâfirst and costâaware approach, ⢠Define:, ⢠Management group and subscription hierarchy, ⢠Networkâcentric landing zone patterns, ⢠Shared services and connectivity hubs, ⢠Build SAPâready landing zones, ensuring:, ⢠Network isolation per SAP tier, ⢠Controlled ingress/egress, ⢠Hybrid integration with onâprem SAP landscapes, ⢠Act as the design authority for Azure network, platform, and cost governance standards FinOps & Cost Optimization (Explicit Responsibility) ⢠Embed FinOps principles into Azure IaaS and SAP architecture decisions, ⢠Design costâoptimized Azure network and infrastructure architectures, including:, ⢠Rightâsizing SAP VMs and HANA instances, ⢠Storage tier selection and performanceâcost tradeâoffs, ⢠Network cost optimization (ExpressRoute, egress, traffic flows), ⢠Define and enforce:, ⢠Resource tagging standards, ⢠Cost allocation by SAP system, environment, and business unit, ⢠Use Azure Cost Management to:, ⢠Monitor SAP infrastructure spends, ⢠Identify cost anomalies and optimization opportunities, ⢠Support forecasting and budgeting for SAP landscapes, ⢠Advise stakeholders on cost vs resilience vs performance tradeâoffs, ⢠Support ongoing cost optimization postâmigration, not just initial design Infrastructure Automation & Azure DevOps ⢠Deliver networking, IaaS, and costâgovernance automation using:, ⢠Terraform (preferred), ⢠ARM / Bicep, ⢠Build Azure DevOps pipelines for:, ⢠Landing zone deployment, ⢠Network and connectivity provisioning, ⢠SAP infrastructure rollout, ⢠Enforce governance, cost controls, and consistency through code Required Skills & Experience Mandatory (Primary Screening Criteria) ⢠Deep Azure Networking expertise (PRIMARY SKILL), ⢠Proven experience designing enterprise Azure network architectures, ⢠Strong ExpressRoute and hybrid connectivity experience, ⢠Extensive experience as an Azure IaaS / Infrastructure Architect, ⢠Proven SAP on Azure IaaS experience, ⢠Azure Landing Zone design and implementation, ⢠Strong FinOps / cost optimization experience for Azure IaaS, ⢠Infrastructure as Code (Terraform preferred), ⢠Azure DevOps CI/CD experience, ⢠Led multiple SAP migration programs, ⢠Strong Linux and Windows OS expertise for SAP, ⢠Dataâcenter to Azure network migration experience, ⢠Experience advising customers on SAP cloud cost governance Certifications (Preferred) ⢠Microsoft Certified: Azure Solutions Architect Expert (AZâ305), ⢠Microsoft Certified: Azure for SAP Workloads Specialty, ⢠AZâ104 (Azure Administrator Associate), ⢠FinOps Foundation Practitioner (nice to have) Role Level ⢠Senior / Lead Azure Infrastructure Architect, ⢠Azure Networking, SAP IaaS & FinOps Design Authority