Cloud Architect

Bharti AXA Life Insurance · Mumbai

  • Experience5–8 yrs
  • SalaryNot disclosed
  • Work modeonsite
  • Posted25 Sept 2026

About Bharti AXA Life Insurance

Bharti AXA Life Insurance is hiring in Mumbai in insurance. This role looks for around 5+ years of experience.

Skills

  • AWS
  • Microsoft Azure
  • Google Cloud Platform
  • Terraform
  • OpenTofu
  • Ansible
  • Kubernetes
  • Infrastructure as Code
  • zero-trust security
  • Identity Federation
  • OIDC
  • SAML
  • Attribute-Based Access Control
  • Just-In-Time privileged access management
  • AWS KMS
  • Azure Key Vault
  • Google Cloud KMS
  • Hardware Security Modules
  • tokenization
  • TLS 1.3
  • confidential computing
  • Cloud Security Posture Management
  • Cloud Workload Protection Platform
  • PCI DSS
  • SOC 2
  • ISO 27001
  • SAST
  • DAST
  • Software Bill of Materials
  • micro-segmentation
  • next-generation firewall
  • Web Application Firewall
  • Content Delivery Network
  • DDoS protection
  • observability
  • Service Level Indicators
  • Service Level Objectives
  • Error Budgets
  • FinOps
  • Savings Plans
  • Reserved Instances
  • Committed Use Discounts
  • incident response
  • root-cause analysis

The role

A cloud architect at an insurance company designs multi-cloud infrastructure with Terraform, zero-trust security engineering, and disaster recovery for regulated financial services. The role governs AWS, Azure, and GCP environments, integrating cloud-native systems with core banking platforms and enforcing compliance.

Full job description

We, at Bharti Axa Life Insurance are seeking ambitious talent ready to make an immediate impact within our fast-paced and innovative workplace. We are hiring for our Information Technology Department.

About the Role:The Senior Lead Multi-Cloud Architect serves as the ultimate technical authority, strategist, and custodian of the enterprise's cross-cloud ecosystem spanning AWS, Azure, and GCP. Operating within the highly regulated Banking ,Financial Services, and Insurance (BFSI) domain, this role consolidates the strategic governance of core infrastructure, zero-trust security engineering, high-throughput financial networking, and continuous site reliability operations. The successful candidate bears full personal and professional accountability for the systemic uptime, cryptographic defense, regulatory compliance, and fiscal health of the entire global cloud estate.

Key Responsibilities:ENTERPRISE MULTI-CLOUD GOVERNANCE & LANDING ZONES: Design, implement, and maintain unified, compliant multi-account landing zones across AWS, Azure, and GCP. You will own the standardisation of global identity patterns, organizational units, and base resource policy guardrails across all cloud providers.DECLARATIVE INFRASTRUCTURE AS CODE (IaC) ENFORCEMENT: Mandate and architect strict IaC frameworks using Terraform, OpenToFu, and Ansible. You assume ultimate responsibility for eliminating manual configurations ("ClickOps") and maintaining automated validation pipelines to guarantee zero configuration drift across all environments.CROSS-CLOUD HIGH AVAILABILITY & DISASTER RECOVERY (DR): Architect resilient, active-active cross-cloud disaster recovery strategies for core ledger systems and transaction processing engines. You are directly accountable for achieving an RPO of 0 (zero data loss) and an RTO measured in single-digit minutes during a full provider failure.CORE BANKING & HYBRID MAINFRAME INTEGRATION: Orchestrate the integration topologies linking modern, cloud-native microservices with legacy, on-premises core banking mainframes, relational databases, and physical hardware security modules (HSMs).DATA SOVEREIGNTY, LIFECYCLE, & WORM COMPLIANCE: Design globally distributedstorage fabrics with strict lifecycle rules, immutable object locking, and write-once-read-many (WORM) configurations. You ensure all data persistence strategies strictly adhere to local central bank data residency mandates.ZERO-TRUST IDENTITY FEDERATION & ACCESS GOVERNANCE: Enforce a continuous zero-trust security posture across all public clouds. You will own the architecture for cross-cloud Identity Federation (OIDC/SAML), Attribute-Based Access Control (ABAC), and Just-In-Time (JIT) privileged access management to eliminate static, long-lived credentials.CRYPTOGRAPHIC KEY MANAGEMENT & DATA PROTECTION: Design and govern the enterprise cryptographic key management lifecycle utilizing AWS KMS, Azure Key Vault, and GCP Cloud KMS. You assume full ownership of HSM integrations, tokenization pipelines, and the enforcement of complete data encryption at rest, in transit (TLS 1.3), and in use via confidential computing.CLOUD POSTURE & WORKLOAD SECURITY (CSPM/CWPP): Direct the deployment, tuning, and real-time incident remediation of enterprise Cloud Securi Posture Management (CSPM) and Cloud Workload Protection Platforms (CWPP) to intercept misconfigurations and runtime vulnerabilities across containerized environments.FINANCIAL REGULATORY COMPLIANCE ENGINEERING: Author and automate continuous compliance mapping against strict banking benchmarks including PCI-DSS, SOC 2, ISO 27001, and local central bank guidelines. You will act as the primary technical interface during rigorous internal and external regulatory audits.DEVSECOPS & THREAT MODELING LEADERSHIP: Embed automated security gates (SAST/DAST, Software Bill of Materials verification) directly into cross-cloud CI/CD deployment pipelines. You will lead structured threat-modeling exercises on all financial software architectures before granting engineering sign-off.

Skill Set Required:GRANULAR NETWORK MICRO-SEGMENTATION: Enforce strict, application-level network micro-segmentation across massive Kubernetes (EKS/AKS/GKE) deployments. You shoulder the responsibility for ensuring that paymentgateways, customer records, and public-facing web layers reside in completely isolated network segments.DEEP PACKET INGRESS & EGRESS INSPECTION: Architect next-generation centralized firewall hubs (NGFW) and Web Application Firewalls (WAF) to perform continuous deep packet inspection on all inbound and outbound multi-cloud traffic, establishing an absolute defense against malicious data exfiltration.DDOS MITIGATION & EDGE PERFORMANCE ENGINEERING: Deploy and tune global Content Delivery Networks (CDNs) integrated with advanced DDoS protection layers (e.g., AWS Shield Advanced) to protect customer-facing retail banking portals and APIs from disruptive layer-7 application attacks.UNIFIED OBSERVABILITY & TELEMETRY FRAMEWORK: Design and govern a cross-cloud observability platform combining distributed logs, performance metrics, and application traces. You will own the definition and tracking of ServiceLevel Indicators (SLIs), Service Level Objectives (SLOs), and Error Budgets for all production banking services.MULTI-CLOUD FINOPS & COST STRATEGY: Own the financial optimization of the entire multi-cloud footprint. You are responsible for implementing automated right-sizing, managing cross-cloud savings commitments (Savings Plans, Reserved Instances, CUDs), detecting spend anomalies within hours,and driving clear cost-attribution chargebacks to internal business units.MISSION-CRITICAL INCIDENT COMMAND & ROOT CAUSE ANALYSIS: Serve as the ultimate escalation authority for high-severity cloud production outages. You will direct multi-disciplinary incident response squads to restore financial services rapidly, and personally own the post-incident review (PIR) and root-cause analysis (RCA) to drive structural engineering fixes.