Capital Farm Credit

Cloud Platform Engineering Manager

Capital Farm Credit · College Station, Texas, United States

Banking · 501-1,000 employees

5 h ago
Principal (10+ yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Cloud Platform Engineering Manager serves as the primary owner of the organization's Azure and Microsoft 365 environments, ensuring security, reliability, and regulatory compliance. This role involves leading engineering staff, defining platform strategy, and managing cloud governance, cost, and infrastructure lifecycle.

What they look for

Azure Microsoft 365 Cloud platform engineering Infrastructure-as-Code Microsoft Entra ID Azure tenant governance Zero Trust architecture Identity and access management Disaster recovery Business continuity FinOps Cloud security People management Regulatory compliance Risk management

Requirements

Candidates must have at least 10 years of experience in infrastructure or cloud engineering, including 4 years of specialized Azure experience and prior leadership roles. A bachelor's degree in a technical field is required, along with deep expertise in cloud security, identity management, and regulatory frameworks.

Benefits

Incentive program Annual leave Sick leave Paid holidays 401(k) retirement plan Medical insurance Dental insurance Vision insurance Paid parental leave Life insurance Disability insurance Tuition reimbursement Wellness expenses

Full description

About Us Capital Farm Credit is the largest rural lending cooperative in Texas, serving 192 counties through nearly 70 credit offices. With over $12 billion in assets and more than 600 team members, we provide essential financial services to farmers, ranchers, rural homeowners, and agribusinesses. As part of the nationwide Farm Credit System, we are dedicated to supporting rural communities and agriculture.

Why Join Us? We seek motivated individuals who share our core values: commitment, trust, value, and family-like respect. As a customer-owned cooperative, we align employee success with member success, offering competitive pay, growth opportunities, and a supportive environment.

Our Benefits:

  • Incentive Program: Company-wide, goals-based rewards.
  • Accrued Time Off: Earn 13 days of annual leave and 15 days of sick leave per year, plus enjoy 10-12 paid holidays annually.
  • Retirement: 401(k) with up to 9% employer contribution/match.
  • Health Coverage: Affordable medical, dental, and vision plans.
  • Parental Leave: 8 weeks of paid parental leave.
  • Life & Disability Insurance: Employer-paid coverage.
  • Education & Wellness: Tuition reimbursement and up to $400 for wellness expenses.

At Capital Farm Credit, you’ll find more than a job—you’ll find purpose.

EDUCATION AND EXPERIENCE

  • Bachelor's degree in Computer Science, Information Technology, Engineering, or a related field, or an equivalent combination of education and relevant experience.
  • Minimum of 10 years of progressive experience in infrastructure, cloud, or platform engineering, including at least 4 years specializing in Microsoft Azure.
  • One to three years of leadership or people management experience, with a demonstrated ability to lead technical teams and manage enterprise platform environments.
  • Expertise in Azure tenant governance, Microsoft Entra ID, networking, Infrastructure-as-Code (IaC), and cloud platform operations.
  • Strong understanding of cloud security principles, including Zero Trust architecture, identity and access management, and encryption and key management.
  • Experience within a regulated industry, preferably banking or financial services, with exposure to audits and regulatory examinations is strongly preferred.
  • Proven ability to design, implement, and validate disaster recovery and business continuity strategies for mission-critical systems, along with exceptional communication skills to effectively present technical concepts, risks, and trade-offs to senior leadership.
  • Preferred certifications include Microsoft Certified: Azure Solutions Architect Expert, Microsoft Certified: Azure Administrator Associate, Microsoft Certified: Cybersecurity Architect Expert or Azure Security Engineer Associate, and security or governance certifications such as CISSP, CCSP, or CISM. FinOps Certified Practitioner certification is a plus.

JOB SUMMARY

• The Cloud Platform Engineering Manager is the designated owner and single point of accountability (DRI) for Capital Farm Credit’s (CFC) Microsoft cloud platform, spanning the Azure and Microsoft 365 environments (including Exchange Online, SharePoint Online, OneDrive, and Teams). This leader is accountable for the security posture, reliability, governance, cost, and engineering of these environments, ensuring they meet the regulatory and operational expectations of a financial institution.

• This hands-on leadership role pairs deep Azure and Microsoft 365 expertise with clear ownership. The Manager sets platform direction within the strategy established by Senior IT Leadership, supports the engineering and operations staff who run the platform, and serves as CFC’s primary technical authority on Azure and Microsoft 365. They partner closely with Information Security, Risk, Compliance, Audit, and application teams — including on the data governance, retention, and information-protection controls (e.g., Microsoft Purview) across the M365 estate — advise the SVP on cloud risk, investment, and strategy, and escalate decisions beyond the platform’s defined authority.

ESSENTIAL FUNCTIONS

  • Own the design, governance, and lifecycle of the Azure tenant and full M365 suite, aligned with the Azure Well-Architected and Cloud Adoption Frameworks.
  • Define and enforce guardrails, standards, and reference architecture through policy-as-code and Infrastructure-as-Code.
  • Own enterprise identity within the tenant (Microsoft Entra ID), including conditional access, privileged access, and least-privilege RBAC.
  • Maintain the platform roadmap and prioritize work in alignment with the CFC’s IT strategy.
  • Own the security posture of the tenant in partnership with Information Security, applying Zero Trust and defense-in-depth controls.
  • Ensure encryption in transit and at rest, robust key and secrets management (Azure Key Vault, HSM-backed keys), and continuous monitoring (Microsoft Defender for Cloud, Sentinel, Purview).
  • Ensure the tenant satisfies applicable requirements (e.g., FFIEC guidance, GLBA, SOX, PCI-DSS, and relevant state/federal regulations) and support internal/external audits and regulatory examinations.
  • Own remediation of cloud-related audit and examination findings within agreed timelines.
  • Own availability, performance, and reliability of the platform against defined SLAs/SLOs.
  • Design, document, and regularly test high-availability, backup, disaster recovery (DR), and business continuity (BCP) capabilities, including recovery objectives (RTO/RPO).
  • Establish observability, alerting, incident management, and on-call practices; lead major-incident response and post-incident reviews.
  • Operate change, release, and configuration management in line with the CFC’s frameworks.
  • Own cloud cost management for the tenant — budgeting, forecasting, optimization, and chargeback.
  • Manage the operational relationship with Microsoft and relevant MSP/third-party vendors, including support, reservations, and licensing.
  • Support third-party risk activities for cloud vendors with TPRM and procurement.
  • Lead, mentor, and develop cloud platform engineering and operations staff.
  • Advise the SVP and senior stakeholders on cloud risk, investment, and trade-offs; escalate decisions beyond the role’s authority.
  • Partner with Security, Risk, Compliance, Audit, and application teams to deliver secure, compliant, and reliable services.

REQUIRED SKILLS

  • Experience migrating regulated workloads from on premises/data center environments to Azure.
  • Familiarity with the broader Microsoft ecosystem (Microsoft 365, Defender suite, Sentinel, Purview) and hybrid connectivity.
  • FinOps experience and demonstrated cloud cost optimization at scale.
  • Experience supporting risk committees, auditors, or regulators.
  • Experience building and managing SOC2 certifications
  • Ownership — takes single-threaded accountability for outcomes and sees issues through to resolution.
  • Technical authority — deep, current Azure expertise with sound architectural and risk judgment.
  • Security and risk mindset — treats security, compliance, and resilience as first-class design constraints.
  • Leadership — builds high-performing teams and earns trust across technical and business stakeholders.
  • Operational discipline — drives reliability, repeatability, and accountability through process and automation.

DISCLAIMER

We are an Equal Employment/Affirmative Action employer. We do not discriminate in hiring on the basis of sex, race, color, religious creed, national origin, physical or mental disability, protected Veteran status, or any other characteristic protected by federal, state, or local law. If you need a reasonable accommodation for any part of the employment process, please contact us by email at careers@capitalfarmcredit.com and let us know the nature of your request and your contact information. Requests for accommodation will be considered on a case-by-case basis. Please note that only inquiries concerning a request for reasonable accommodation will be responded to from this e-mail address. For more information, view the EEO - Know Your Rights and Pay Transparency Statement.

Applicants should personally complete and submit their application materials. Submissions generated through automated tools or third-party mass application services may not be reviewed.

Equal Opportunity Statement Capital Farm Credit is committed to creating a diverse and inclusive workplace. The position title and requirements may be adjusted based on the candidate's experience and qualifications. We welcome applicants of all backgrounds and do not discriminate based on race, color, gender, religion, national origin, disability, veteran status, or any other protected status. A full job description is available upon request. Candidates selected for hire will be required to complete a background check, including criminal history, education verification, and employment verification. A credit check will be required for roles that require NMLS registration.