Back to jobs
New

Principal Architect, Cloud & Identity Infrastructure

Vancouver, British Columbia, Canada

Interested in joining one of Canada’s top performing asset managers? We are seeking a Principal Architect, Cloud & Identity Infrastructure to own the Cloud & Identity domain within the Infrastructure & Cloud Engineering organization. This includes public cloud platforms (Azure, AWS), identity and access management (Entra ID, Active Directory, hybrid identity), and Microsoft 365 platform services. The focus is platform ownership: defining architecture, standards, and guardrails, and ensuring platforms are scalable, secure, and cost-efficient. At the same time, strong delivery experience and hands-on technical depth are essential. You are expected to bring practical expertise, make sound technical decisions, and guide complex work with credibility while remaining accountable for direction and outcomes. You will act as the primary platform interface to business and application teams, translating needs into platform capabilities and clearly communicating strategy, constraints, and changes.  You will operate as a senior individual contributor, working closely with other Platform Owners, Security, and Operations. Engineering work is executed by Subject Matter Experts (SMEs), but you remain closely involved in design decisions, complex problem-solving, and key technical trade-offs.  You will treat platforms as products, enabling reusable patterns and low-friction consumption so teams can move faster with minimal dependency on central teams.  Our offices currently operate on a hybrid model with three days in office. 

What You Will Do

  • You will own the Cloud & Identity platform domain and be accountable for its health, direction, and outcomes. This includes Azure and AWS platforms, identity and access management across Entra ID and Active Directory, and Microsoft 365 from an architecture, security, and integration perspective.
  • You will define target architectures, standards, and guardrails to ensure scalability, security, cost efficiency, and consistency across the organization. You will drive deliberate platform decisions and reduce fragmentation.
  • You will own the organization’s identity foundation, including authentication and authorization models, access patterns, and security controls across cloud and legacy environments.
  • Your ownership also includes how the platform is understood and consumed, ensuring clear communication of capabilities, constraints, and roadmap to business and cross-functional stakeholders. You will partner with other Platform Owners to ensure clear boundaries and integration points, while SMEs execute implementation aligned to your standards.
  • You are accountable for platform outcomes, including scalability, cost efficiency, access integrity, and reliability, and for evolving the platform proactively based on business needs. 
  • Cloud & Identity Platforms: Own and evolve cloud platforms across Azure and AWS, and define how services are consumed. Provide architectural guidance in partnership with other Platform Owners (compute, network, storage). Ensure platforms meet requirements for scalability, resilience, observability, and recovery 
  • Identity & Microsoft Platforms: Own identity and access management across Entra ID, Active Directory, and hybrid environments. Define authentication, authorization, and privileged access standards in partnership with Security. Own Microsoft 365 architecture, security configuration, and identity integration, partnering with Workplace Technology on end-user experience and adoption
  • Architecture, Standards & Governance: Define and enforce platform standards, guardrails, and reusable patterns. Drive consistent, low-friction platform consumption models (self-service where possible). Balance innovation with stability, security, and long-term sustainability 
  • Business & Cross-Functional Engagement: Act as the primary platform point of contact for business and application teams. Translate business needs into platform capabilities, standards, and roadmap priorities. Communicate platform strategy, changes, and constraints clearly to technical and non-technical stakeholders. Work closely with Security, Operations, and Architecture to align priorities and resolve dependencies
  • Cross-Domain Collaboration: Work with other Platform Owners to define clear integration points and avoid overlap. Guide SMEs by setting direction, reviewing designs, and ensuring alignment with standards. Drive technical decisions and influence direction across teams and stakeholders
  • Cost & Platform HealthDefine and enforce cost management practices (tagging, allocation, optimization). Track and improve platform health across reliability, performance, cost, and adoption 

What You Bring 

  • Senior-level experience (typically 10+ years) across enterprise infrastructure and cloud platforms 
  • Strong background in hybrid environments (on-premises and public cloud integration) 
  • Deep knowledge of: Modern identity (Entra ID, Conditional Access, MFA, SSO, federation, identity governance, PIM/JIT), Microsoft 365 services (Exchange Online, Teams, SharePoint, OneDrive), Core infrastructure (Windows Server, Exchange, virtualization, storage, networking) 
  • Practical experience with Azure and AWS 
  • Understanding of automation and infrastructure-as-code (Terraform, ARM, Bicep, CI/CD) 
  • Platform-owner mindset focused on long-term outcomes and business impact with strong decision-making in complex environments 
  • Clear communicator across technical and business audiences 
  • Pragmatic and outcome-driven, comfortable with legacy and modern environments 

 

The salary range for this position is $140,000 - $150,000. The salary range provided reflects the base salary range for this position as required by legislation. In addition, there is an annual performance bonus which contributes to the total compensation of this position. Further questions may be directed to the HR team during the interview process. 

 

#LI-hybrid #LI-KC1 

 

For a closer look at how you can build your career with us, we invite you to explore cclgroup.com.  

CC&L Financial Group is committed to creating a diverse and inclusive environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to gender, ethnicity, religion, sexual orientation or expression, disability, or age.  

Your application will be reviewed by a member of the hiring team - AI is not used in the screening, assessment or selection of applications at this time.  

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...

I acknowledge that I have read and understood the CC&L Financial Group Privacy Policy [https://cclfg.cclgroup.com/privacy-confidentiality/].  I consent to CC&L processing my personal data as described in the Privacy Policy as summarized below, including to the transfer of my personal data to third parties located outside of my jurisdiction, and I understand my privacy rights and choices.

Select...

The CC&L Financial Group entity to which you are applying is the data controller for the personal data you provide during the recruitment process and can be contacted at privacy@cclgroup.com.

We process personal data about you to manage our recruitment activities, including evaluating your suitability for employment. By completing the acknowledgement above, you consent to this processing. In applicable jurisdictions, other lawful bases for this processing are: (i) legitimate interests, to collect and review application information, shortlist, conduct interviews and assessments, and verify candidates; and (ii) contract, where you have accepted a job offer and we need to take steps prior to entering into a contract of employment.

We collect personal data directly from you when you apply for a role and may also obtain personal data about you from other sources, including recruitment agencies, employee referrals, and professional networking sites, where permitted by applicable law. Your personal data may be shared within our group, with third parties who provide services to us (including Greenhouse Software, Inc., a cloud services provider located in the U.S. engaged to help manage our recruitment process), and where required by law. Where your personal data may be transferred outside of your state/province/region or internationally, appropriate safeguards are in place in accordance with applicable data protection law.

Your personal data will be retained for the duration of the recruitment process and for a period following the conclusion of the recruitment process, including for the purpose of considering you for future employment opportunities, contacting you about such opportunities, or as otherwise outlined in our Privacy Policy, in accordance with data protection laws.

You have various rights under applicable data protection law depending on where you live, including the right to access, correct, delete or restrict processing of your personal data, and to receive your data in a portable format. You may also object to processing or retention in some circumstances and, where we have asked for your consent, withdraw it at any time. These rights may be limited in certain circumstances.

If you have any concerns about how we handle your personal data or would like more information about what rights you have, please contact us at privacy@cclgroup.com in the first instance. You also have the right to lodge a complaint with your local supervisory authority. For UK applicants, this is the Information Commissioner's Office. For full details on how we process your personal data please see our Privacy Policy at [https://cclfg.cclgroup.com/privacy-confidentiality]

Select...
Select...