Sr Systems Engineer - Azure

Posted Yesterday
Be an Early Applicant
9 Locations
In-Office
120K-150K Annually
Senior level
Fintech
The Role
Senior individual contributor owning Axos Banks Azure platform, identity governance, security posture, cost management, and automation. Design, deploy, and maintain Azure infrastructure and Entra ID; drive security remediation, compliance reporting, cost optimization, and ServiceNow-based change management. Act as technical peer for architecture, support hybrid identity, and enable audited operational discipline for a federally regulated financial institution.
Summary Generated by Built In
Axos Bank

Target Range:

$120,000.00 /Yr. - $150,000.00 /Yr.

Actual starting pay will vary based on factors including, but not limited to, geographic location, experience, skills, specialty, and education.

Eligible for an Annual Discretionary Cash Bonus Target: 10%

Eligible for an Annual Discretionary Restricted Stock Units Bonus Target: 10%

These discretionary target bonuses may be awarded semi-annually based upon your achievement of performance goals and targets.

About This Job

Axos Bank is seeking an experienced and technically deep Sr. Microsoft Azure Engineer to join the Microsoft Operations team in San Diego. This is a senior individual contributor role with full ownership of the Azure cloud platform and a primary partnership role alongside our Sr. Engineer and Technology Architect covering the broader Microsoft environment.
This is not a ticket-closing role. You will own the Azure platform, infrastructure, identity governance, security posture, cost management, and operational automation for a federally regulated financial institution. You will serve as technical peer and backup to our Sr. Architect, coordinate with sub-team leads covering identity, endpoint, and messaging domains, and play a direct role in positioning the team to support the bank's growing AI and data lake initiatives.
The right candidate is a well-rounded senior engineer who has operated in a regulated environment, brings genuine depth in both Azure infrastructure and Microsoft identity, and treats operational discipline, ticketing, documentation, change management, as a professional standard rather than an administrative requirement

Responsibilities:

Azure Infrastructure

  • Design, deploy, and maintain Azure subscription architecture including management groups, resource groups, and naming and tagging governance across all subscriptions
  • Own and administer Azure Virtual Network topology including hub-spoke design, VNets, subnets, NSGs, route tables, and VNet peering aligned to bank security requirements
  • Manage IaaS and PaaS resource lifecycle — provisioning, scaling, monitoring, and decommission — with full change management documentation in ServiceNow
  • Maintain the documented baseline state of the Azure environment; identify and remediate configuration drift from established standards on a defined cycle
  • Serve as the primary technical owner for Azure-dependent infrastructure projects including AXOS Private Cloud and data lake infrastructure initiatives

Identity and Access Management

  • Administer and maintain Entra ID (Azure Active Directory) tenancy health — user lifecycle, group management, application registrations, and service principal governance
  • Design, implement, and maintain Conditional Access policies, named locations, sign-in risk policies, and MFA enforcement in alignment with bank security policy and FFIEC guidance
  • Manage Privileged Identity Management (PIM) including role activation policy, access reviews for privileged accounts, and just-in-time access configuration
  • Monitor and maintain Azure AD Connect synchronization health; resolve sync conflicts; coordinate with the Sr. Architect on hybrid identity topology changes
  • Coordinate with the Intune/GPO/Entra sub-team on endpoint compliance integration with Conditional Access and device-based authentication requirements
  • Conduct and document semi-annual Azure RBAC assignment reviews and deliver findings to the Audit and Compliance Engineer

Security and Compliance Posture

  • Own Defender for Cloud operational posture — monitor, prioritize, and drive hands-on remediation of high and critical recommendations, not dashboard observation alone
  • Manage Azure Policy assignments for baseline compliance enforcement; author and test policy definitions as bank requirements evolve
  • Design and maintain RBAC assignments across Azure resources in alignment with least-privilege principles; document all role assignments with business justification
  • Produce quarterly Azure security posture reports for the Audit and Compliance Engineer; provide documentation sufficient to satisfy KPMG audit requests related to Azure infrastructure and identity
  • Participate as the Azure technical SME in KPMG audit preparation and response
  • Maintain working knowledge of FFIEC IT examination guidance and align Azure governance practices accordingly

Cost Management and Governance

  • Own Azure Cost Management analysis, reporting, budget alert configuration, and anomaly detection across all Azure subscriptions
  • Enforce tagging policy compliance; identify and remediate untagged or incorrectly tagged resources on a defined cycle
  • Provide monthly cost forecasting and variance analysis to the Sr. IT Manager — communicate material spend changes before they appear in billing, not after
  • Identify and recommend cost optimization opportunities including right-sizing, reserved instance analysis, and elimination of unused resources

Automation and Operational Excellence

  • Develop and maintain Azure Automation runbooks and PowerShell/Python scripts for operational task automation; prioritize progressive elimination of manual repetitive processes
  • Configure and maintain Azure Monitor alerts, Log Analytics workspaces, and operational dashboards for infrastructure health and performance visibility
  • Author and maintain runbook documentation for all operational procedures within the Azure domain — sufficient for another senior engineer to execute independently
  • Participate in quarterly cross-team cross-training; contribute at least one procedural training session per cycle

Architectural Partnership

  • Serve as primary backup to the Sr. Engineer and Technology Architect for Azure decisions, architecture reviews, and cross-domain escalation during periods of unavailability
  • Partner with the Sr. Engineer and Technology Architect on changes to hybrid identity topology, Entra tenant configuration, and Azure AD Connect sync rules — this is a genuine peer relationship with shared architectural ownership, not a sign-off chain
  • Contribute to architectural discussions, design reviews, and platform standards development as a senior technical voice on the Microsoft Operations team
  • Participate in the weekly leads synchronization meeting and contribute Azure platform status, blockers, and capacity to the standing agenda

ServiceNow and Change Management

  • You believe that undocumented work did not happen. Every change, request, incident, and proactive task gets a ServiceNow ticket before execution — full stop
  • Complete ServiceNow change requests for all Standard, Normal, and Emergency changes including full description, rollback plan, and approval routing per change management policy
  • Maintain change records with sufficient technical detail to serve as KPMG audit evidence
  • Author ServiceNow knowledge base articles for any procedure that required meaningful effort to develop, debug, or resolve — the team does not re-solve the same problem twice

Requirements:

  • Bachelor's degree in Computer Science, Information Technology, Information Systems, or a directly related field; OR equivalent combination of education and verifiable professional experience
  • 7+ years of hands-on, production-environment experience administering and engineering Microsoft Azure infrastructure and Microsoft identity technologies
  • 5+ years administering Active Directory Domain Services in a multi-domain enterprise environment — Group Policy, OU structure, trust relationships, and schema-level understanding
  • 4+ years with Entra ID (Azure Active Directory) including Conditional Access policy authoring, PIM configuration, and Azure AD Connect sync administration in a hybrid identity environment
  • 3+ years of experience in a federally regulated industry — banking, financial services, healthcare, or government — with direct exposure to audit processes, change management requirements, and compliance documentation
  • Demonstrated experience designing and maintaining Azure Virtual Network topology — hub-spoke architecture, NSG management, and on-premises connectivity
  • Demonstrated experience with Defender for Cloud and Azure Policy including hands-on security recommendation remediation — not limited to monitoring
  • Demonstrated experience with Azure Cost Management including budget configuration, cost anomaly detection, and spend forecasting across multiple subscriptions
  • Proficiency in PowerShell scripting for Azure and Active Directory automation — scripts that are maintainable and executable by other engineers

Required Certification

  • Microsoft Certified: Azure Administrator Associate (AZ-104)

Axos Employee Benefits May Include:

  • Medical, Dental, Vision, and Life Insurance

  • Paid Sick Leave, 3 weeks’ Vacation, and Holidays (about 11 a year)

  • HSA or FSA account and other voluntary benefits

  • 401(k) Retirement Saving Plan with Employer Match Program and 529 Savings Plan

  • Employee Mortgage Loan Program and free access to an Axos Bank Account with Self-Directed Trading

About Axos

Born digital-first, Axos delivers financial tools and services that allow individuals, small businesses, and companies to access and manage their money how, when, and where they want. We’re a diverse team of dynamic, insightful, and independent innovators who are excited to provide technology-driven solutions that offer unbeatable value to our customers.

Axos Financial is our holding company and is publicly traded on the New York Stock Exchange under the symbol "AX" (NYSE: AX).

Learn more about working at Axos

Pre-Employment Background Check and Drug Test:

All offers are contingent upon the candidate successfully passing a credit check, criminal background check, and pre-employment drug screening, which includes screening for marijuana. Axos Bank is a federally regulated banking institution. At the federal level, marijuana is an illegal schedule 1 drug; therefore, we will not employ any person who tests positive for marijuana, regardless of state legalization.

Equal Employment Opportunity:

Axos is an Equal Opportunity employer. We are committed to providing equal employment opportunities to all employees and applicants without regard to race, religious creed, color, sex (including pregnancy, breast feeding and related medical conditions), gender, gender identity, gender expression, sexual orientation, national origin, ancestry, citizenship status, military and veteran status, marital status, age, protected medical condition, genetic information, physical disability, mental disability, or any other protected status in accordance with all applicable federal, state, and local laws.

Job Functions and Work Environment:

While performing the duties of this position, the employee is required to sit for extended periods of time. Manual dexterity and coordination are required while operating standard office equipment such as computer keyboard and mouse, calculator, telephone, copiers, etc.

The work environment characteristics described here are representative of those an employee may encounter while performing the essential functions of this position. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of this position.

E-Verify and Right to Work Notices

Axos participates in the U.S. Department of Homeland Security E-Verify program in all facilities located in the United States. The E-Verify program is an internet-based employment eligibility verification system operated by the U.S. Citizenship and Immigration Services.

IER Right to Work Poster (English/Spanish)

E-Verify Participation Poster (English/Spanish)

Skills Required

  • Bachelor's degree in Computer Science, Information Technology, Information Systems, or equivalent experience
  • 7+ years administering and engineering Microsoft Azure infrastructure and Microsoft identity technologies in production
  • 5+ years administering Active Directory Domain Services in a multi-domain enterprise (Group Policy, OU structure, trusts, schema)
  • 4+ years with Entra ID (Azure AD) including Conditional Access, PIM, and Azure AD Connect in hybrid identity environments
  • 3+ years experience in a federally regulated industry with exposure to audits, change management, and compliance documentation
  • Demonstrated experience designing and maintaining Azure Virtual Network topology (hub-spoke, NSGs, peering, on-prem connectivity)
  • Demonstrated hands-on experience with Defender for Cloud and Azure Policy including remediation of security recommendations
  • Demonstrated experience with Azure Cost Management, budget configuration, anomaly detection, and spend forecasting across subscriptions
  • Proficiency in PowerShell scripting for Azure and Active Directory automation (maintainable scripts)
  • Experience using ServiceNow for change management, incidents, and knowledge base authoring
  • Microsoft Certified: Azure Administrator Associate (AZ-104)
  • Experience authoring automation runbooks and using Python for operational automation
  • Familiarity with Intune, GPO integration, and endpoint compliance integration with Conditional Access

Axos Bank Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Axos Bank and has not been reviewed or approved by Axos Bank.

  • Healthcare Strength Health coverage includes medical, dental, and vision with multiple plan choices, plus HSA/FSA options and an Employee Assistance Program. Employer HSA contributions and extras like pet insurance and onsite fitness centers at some locations expand the wellness offering.
  • Leave & Time Off Breadth Time off includes around 15 days of vacation for new hires, paid sick leave, and up to 11 company holidays annually. Availability of certain perks and holiday specifics can vary by location or subsidiary, but the baseline PTO/holiday combination is broadly competitive.
  • Retirement Support A 401(k) with company match is offered alongside additional financial programs like a 529 plan, employee mortgage loans, and banking/trading perks. Automatic enrollment and structured matching underscore tangible retirement support for longer‑tenured employees.

Axos Bank Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Diego, CA
1,001 Employees
Year Founded: 2000

What We Do

Axos is a technology-driven financial services company providing a diverse and ever-growing range of innovative products and services for personal, business and institutional clients nationwide. Powered by exceptional team members, a clearly defined set of values and a culture that is both meritocratic and self-governing, we are transforming banking as we know it. Our mission is summed up in two words: Banking Evolved. Banking Evolved means providing products and services that are technologically superior to our competitors and that offer our customers an unbeatable value proposition. Banking Evolved means continuously innovating and excelling in the following areas: • The incubation, creation and deployment of new businesses and tools that best serve our customers; • The evolution, optimization, delivery, distribution and marketing of our products; • The harnessing of data and technology to manage our business most effectively and efficiently; and • The development and engagement of our team members. To be part of the Axos team is to live our values as your own, to work with a strong sense of individual purpose and to embody a commitment to the shared success of our business. As a meritocracy, we believe that success is earned. We reward individuals on the basis of their achievements. As a self-governing organization, we derive strength from the internal resourcefulness of each individual. We emphasize independence, goal-setting and personal accountability.

Similar Jobs

Snap Inc. Logo Snap Inc.

Manager, Software Engineering, MDP

Artificial Intelligence • Cloud • Machine Learning • Mobile • Software • Virtual Reality • App development
Hybrid
4 Locations
5000 Employees
195K-343K Annually

Collectors Logo Collectors

Senior Software Engineer

Consumer Web • eCommerce • Machine Learning • Software • Sports • Analytics
Remote or Hybrid
US
2246 Employees
141K-229K Annually

HiBob Logo HiBob

Business Development Representative

HR Tech • Information Technology • Professional Services • Sales • Software
Remote or Hybrid
United States
1350 Employees
64K-64K Annually

HiBob Logo HiBob

Customer Experience Manager

HR Tech • Information Technology • Professional Services • Sales • Software
Remote or Hybrid
United States
1350 Employees
140K-170K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account