What success looks like in this role:
Job Description – Associate Principal Cloud Engineer
Overview
The Associate Principal Cloud Engineer serves as a senior technical leader responsible for designing, implementing, optimizing, and governing cloud solutions across the enterprise. This role provides architectural guidance, drives automation, ensures operational excellence, and mentors engineering teams to deliver secure, scalable, and reliable cloud platforms.
We are mainly seeking an experienced Senior Azure Entra & Active Directory Engineer to manage and optimize enterprise identity and access management (IAM) solutions. This role requires deep expertise in Microsoft Entra ID (formerly Azure AD), Active Directory (AD), and related security technologies. The ideal candidate will design, implement, and maintain identity services that ensure high availability, security, and compliance for the organization's cloud and hybrid environments.
Key Responsibilities
Assoc Prin Cloud Eng
- Design, implement, and maintain Microsoft Entra ID (Azure AD) and on-premises Active Directory infrastructure.
- Administer and manage Azure infrastructure including VMs, Storage, Networking, Backup, Site Recovery, Key Vault, and Azure Monitor.
- Develop and enforce security policies, ensuring compliance with industry standards and best practices.
- Manage and optimize Identity and Access Management (IAM) solutions, including SSO (Single Sign-On), MFA (Multi-Factor Authentication), Conditional Access, and Privileged Identity Management (PIM).
- Administer and troubleshoot AD Federation Services (ADFS), Azure AD Connect, Group Policy (GPO), and DNS.
- Automate identity lifecycle management using PowerShell, Terraform, or other scripting languages.
- Integrate identity solutions with Azure, Microsoft 365, and third-party SaaS applications.
- Monitor and respond to security threats using Microsoft Defender, Azure Sentinel, and other security tools.
- Perform regular AD health checks, performance tuning, and patch management.
- Collaborate with security, cloud, and networking teams to improve IAM strategies.
- Lead migrations, upgrades, and modernization efforts, including Active Directory domain consolidations and hybrid identity implementations.
- Provide technical mentorship and training to junior engineers.
- Document system designs, processes, and best practices.
Cloud Architecture & Engineering
- Design, develop, and optimize cloud infrastructure solutions aligned with business and architectural standards.
- Lead cloud modernization initiatives including migration, re-architecture, and platform upgrades.
- Ensure high availability, scalability, and performance across cloud workloads.
Automation & DevOps
- Drive automation for provisioning, configuration management, and CI/CD pipelines.
- Reduce manual operations by identifying repetitive tasks and implementing automated solutions.
- Establish IaC best practices using tools such as Terraform, ARM/Bicep, CloudFormation, or similar.
Operations & Reliability
- Oversee cloud platform operations, monitoring, incident management, and root-cause analysis.
- OnPrem Active Directory and Windows servers administration and troubleshooting
- Implement SRE and FinOps principles to improve reliability and cost efficiency.
- Ensure compliance with security, governance, and regulatory standards.
- Administer and manage Azure infrastructure including VMs, Storage, Networking, Backup, Site Recovery, Key Vault, and Azure Monitor.
Leadership & Cross-Functional Collaboration
- Mentor cloud engineers and guide cross-functional teams across AVD, CloudOps, and Hybrid Cloud.
- Contribute to technical roadmaps, standards, and cloud strategy.
- Collaborate with security, application, and infrastructure teams to ensure cohesive cloud delivery.
Security & Governance
- Implement cloud security best practices, identity management, and policy enforcement.
- Conduct regular reviews to ensure adherence to governance frameworks and compliance controls.
Performance Improvement & Process Excellence
- Identify low‑performing areas within cloud operations and drive corrective actions.
- Promote team discipline, attentiveness, and continuous improvement culture.
- Optimize existing cloud systems to enhance productivity, reliability, and efficiency.
Required Skills & Qualifications
8–12 years of experience in cloud engineering or related roles.
Strong expertise in Azure / AWS
- Bachelor's degree in Computer Science, Information Technology, or a related field (or equivalent experience).
- 8+ years of experience in Active Directory, Azure AD (Entra ID), and IAM technologies.
- Strong expertise in Azure AD B2B/B2C, Conditional Access, and RBAC (Role-Based Access Control).
- Hands-on experience with Windows Server, DNS, DHCP, and AD Group Policy.
- Experience with PowerShell scripting and automation.
- Knowledge of Zero Trust security models and modern authentication protocols (OAuth, SAML, OpenID Connect).
- Experience with Azure AD Connect, ADFS, and Hybrid Identity.
- Strong troubleshooting skills in identity federation, authentication, and authorization issues.
- Familiarity with Privileged Access Management (PAM) solutions such as CyberArk, BeyondTrust, or Azure PIM.
- Excellent communication and documentation skills.
- Hands-on experience with IaC (Terraform, Bicep, CloudFormation, etc.)
- Proficiency in scripting (PowerShell, Python, Bash).
- Strong understanding of networking, security, identity, and hybrid cloud architectures.
- Experience with DevOps tools such as GitHub Actions, Jenkins, Azure DevOps, or similar.
- Strong problem-solving, analytical thinking, and leadership capabilities.
#LI-SN1
You will be successful in this role if you have:
Preferred Qualifications
- Cloud Architect or DevOps certifications (Azure Architect Expert, AWS Solutions Architect, GCP Professional, etc.)
- Experience in AVD, serverless, containerization (AKS/EKS/GKE), and microservices.
- Knowledge of FinOps, SRE practices, and cost optimization strategies.
- Exposure to enterprise-scale cloud governance frameworks.
- Engineering degree and 6-8 years’ relevant experience OR equivalent combination of education and experience.
Unisys is proud to be an equal opportunity employer that considers all qualified applicants without regard to age, blood type, caste, citizenship, color, disability, family medical history, family status, ethnicity, gender, gender expression, gender identity, genetic information, marital status, national origin, parental status, pregnancy, race, religion, sex, sexual orientation, transgender status, veteran status or any other category protected by law.
Local employment practices and rights may vary by jurisdiction and are subject to applicable local laws. This commitment includes our efforts to provide for all those who seek to express interest in employment the opportunity to participate without barriers.
If you are a US job seeker unable to review the job opportunities herein, or cannot otherwise complete your expression of interest, without additional assistance and would like to discuss a request for reasonable accommodation, please contact our Global Recruiting organization at [email protected]. US job seekers can find more information about Unisys’ EEO commitment here.
Skills Required
- 8-12 years of experience in cloud engineering or related roles
- Bachelor's degree in Computer Science, Information Technology, or a related field, or equivalent experience
- 8+ years of experience with Active Directory, Azure AD or Entra ID, and IAM technologies
- Strong expertise in Azure and AWS
- Experience with Azure AD B2B/B2C, Conditional Access, and RBAC
- Hands-on experience with Windows Server, DNS, DHCP, and AD Group Policy
- Experience with PowerShell scripting and automation
- Knowledge of Zero Trust security models and OAuth, SAML, and OpenID Connect
- Experience with Azure AD Connect, AD FS, and hybrid identity
- Strong troubleshooting skills for identity federation, authentication, and authorization issues
- Familiarity with CyberArk, BeyondTrust, or Azure PIM
- Excellent communication and documentation skills
- Hands-on experience with Terraform, Bicep, CloudFormation, or similar IaC tools
- Proficiency in PowerShell, Python, and Bash
- Strong understanding of networking, security, identity, and hybrid cloud architectures
- Experience with GitHub Actions, Jenkins, Azure DevOps, or similar DevOps tools
- Strong problem-solving, analytical thinking, and leadership capabilities
- Cloud Architect or DevOps certification
- Experience with AVD, serverless, containerization, and microservices
- Knowledge of FinOps, SRE practices, and cost optimization strategies
- Exposure to enterprise-scale cloud governance frameworks
- Engineering degree and 6-8 years of relevant experience, or equivalent combination of education and experience
Unisys Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Unisys and has not been reviewed or approved by Unisys.
-
Fair & Transparent Compensation — Fair & Transparent Compensation: Compensation terms at hire are often presented clearly and upfront, creating a straightforward “take it or leave it” expectation. Pay outcomes are also described as variable by role and geography, with some pockets viewed as satisfactory or above average.
-
Retirement Support — Retirement Support: A 401(k) plan with an employer match is commonly described as part of the core package. The match is often characterized as a meaningful component of total rewards relative to other benefits.
-
Healthcare Strength — Healthcare Strength: Core medical, dental, and vision coverage is described as available and broadly in line with a large IT-services employer. The underlying carrier network is sometimes viewed as solid even when cost concerns exist.
Unisys Insights
What We Do
Unisys is a global information technology company that builds high-performance, security-centric solutions for the most demanding businesses and governments on Earth. Unisys offerings include security software and services; digital transformation and workplace services; industry applications and services; and innovative software operating environments for high-intensity enterprise computing. We build better outcomes securely for our clients across the Government, Financial Services and Commercial









