AI Cloud Security Architect

๐Ÿ’ป Ework Group โ€” founded in 2000 and listed on Nasdaq Stockholm โ€” is a leading total talent solutions provider supporting clients across the private and public sectors, as well as independent professionals, in building sustainable talent supply chains.

With a strong focus on IT/OT, R&D, Engineering, and Business Development, Ework delivers value through an independent, holistic approach to total talent management.

For our Client from the healthcare sector, we are currently looking for:

โ˜๏ธ Remote Staff Cloud Security Architect (AI Solutions)

๐Ÿ“ Location: Warsaw, Poland

๐Ÿข Work model: Fully remote, ONLY IN POLAND, with occasional presence in the Warsaw Hub

๐Ÿ“… Start date: 03.08.2026

CONSULTANT MUST BE LOCATED IN POLAND

Recruitment language: English

Recruitment process: 2-stage online recruitment

Role overview:

We are looking for an experienced Cloud Security Architect to design and enable secure Azure-based architectures for modern AI-driven applications.

This is a hands-on, senior-level role, combining architectural ownership with close collaboration with engineering teams. You will define secure patterns, standards, and reusable frameworks while supporting teams in building scalable, compliant, and production-ready solutions.

The role focuses on secure cloud architecture, AI infrastructure, and DevOps modernization, rather than ownership of a single platform. Solutions are currently non-GxP, but must be designed with future regulatory readiness in mind.

This is a hands-on role, with approximately:

o 30% focused on security architecture

o 70% focused on cloud/platform implementation and engineering for AI solutions

The role is embedded within the project team, while also having a dotted-line reporting relationship to the Engineering organization.

Your responsibilities:

  • Design secure Azure cloud architectures for AI applications, data-driven applications, and internal digital products.
  • Define architecture patterns for AI applications that consume data from Databricks and other enterprise data platforms.
  • Establish secure patterns for AI agents, sandboxed Python/code execution, runtime isolation, network segregation, and controlled access to data and services.
  • Design and implement standards for secrets management, identity, access control, encryption, logging, monitoring, and secure connectivity.
  • Use Terraform to define, review, and enable repeatable cloud infrastructure patterns.
  • Help drive the migration from Azure DevOps to GitHub Enterprise.
  • Establish new GitHub-based CI/CD patterns, including repository standards, branching, pull requests, code reviews, automated testing, approvals, deployment gates, and release evidence.
  • Define technical standards for secure software delivery, release traceability, and audit-ready engineering practices.
  • Mentor engineers and improve engineering practices across cloud, security, DevOps, and AI infrastructure.

Requirements:

  • Strong hands-on experience with Microsoft Azure cloud architecture
  • Excellent English speaking skills
  • Strong cloud security expertise, including identity, networking, encryption, secrets management, logging, monitoring, and secure access patterns
  • Experience designing secure infrastructure for AI applications, AI agents, APIs, data-consuming applications, or internal developer platforms
  • Experience with sandboxed code execution, Python runtime environments, containerized workloads, or isolated compute patterns
  • Familiarity with Databricks as a data source for applications
  • Strong knowledge of network segregation, private endpoints, firewalls, virtual networks, controlled egress, and runtime isolation
  • Strong experience with Terraform for infrastructure provisioning and cloud architecture enablement
  • Strong experience with GitHub Enterprise, GitHub Actions, repository governance, branch protection, pull requests, and secure CI/CD patterns
  • Experience with Azure DevOps, ideally including migration from Azure DevOps to GitHub
  • Experience with secrets management, key vaults, managed identities, service principals, RBAC, and Microsoft Entra ID
  • Understanding of secure software delivery, release controls, traceability, and audit-ready engineering practices
  • Ability to work hands-on with engineers while also setting architecture direction and technical standards

Contact person: nicola.urbanska@eworkgroup.com

Client Code: MM03

Do you know someone who would fit this position? Recommend a candidate by sending her/his CV to: polecenia@eworkgroup.com

Whistleblowing Policy, which provides guidelines for reporting misconduct can be found on Ework website: https://www.eworkgroup.com/about-us/our-responsibility

  • Locations: Remote
  • Technologies: Azure, Continuous Integration / Continuous Deployment, Databricks, Python, Terraform
  • Language: English