Cloud Solutions Architect
Location: Singapore
Function: IT Infrastructure, Cloud Architecture and Engineering
Reports to: Head of Engineering and IT
About Us
Dymon Asia Capital is a Singapore headquartered multi-strategy hedge fund managing approximately USD 5 billion in assets. Founded in Singapore and built around Asian markets, we run a range of strategies across macro, commodities, and systematic trading. We employ around 350 people across nine offices globally, with Singapore as our headquarters and primary technology hub. We are regulated by the Monetary Authority of Singapore and operate under the regulatory regimes of the markets in which we invest.
The IT Infrastructure function is organized across four pillars: Network, Windows, Linux, and Cloud. It is a lean six-person team of senior engineers, working in close partnership with the Cybersecurity function and with the trading and research desks it supports.
This role owns the cloud and productivity platform. That means both the architecture and the hands that build it. There is no separate engineering layer to hand designs to. You will define the landing zone, build it, migrate workloads onto it, and run it. We are not looking for a design-only architect.
The estate is Microsoft-centric. Azure runs on a hub-and-spoke topology out of Singapore, connected to our offices over ExpressRoute and VPN, and we run Microsoft 365, Exchange Online, Entra ID, and Intune alongside it. There is a substantial program ahead: migrating remaining on-premises workloads to Azure, modernizing legacy applications onto platform services, and building out the data platform. Uptime and latency affect trading and research directly, so resilience and change discipline matter more here than breadth of technology. We want streamlined platforms sized for a fast-moving fund, not the complexity of a large bank.
Key Responsibilities
Own the Azure landing zone architecture, including subscription and management group design, governance guardrails, and policy baselines, right sized to the firm rather than to enterprise scale.
Design and build the Azure network fabric alongside the Network Architect, covering hub-and-spoke topology, peering, security groups, and hybrid connectivity across Azure Arc, VPN Gateway, and ExpressRoute.
Own the design and configuration of Azure Firewall, including forced tunnelling and traffic routing between DMZ and production environments.
Lead cloud migration strategy and execution, moving on-premises workloads to Azure IaaS, PaaS, and SaaS with clear cutover and rollback plans.
Re-architect and modernize legacy applications onto Azure Web Apps and platform services, improving scalability, fault tolerance, and API-based integration.
Build and maintain the data platform architecture, integrating Azure Data Factory, Synapse Analytics, Databricks, and Microsoft Purview for data governance and lineage.
Administer Microsoft 365 and Exchange Online, including mailbox management, conditional access, and email security, alongside Intune device management and compliance policy.
Design and test disaster recovery and backup strategies, and own monitoring and alerting across Azure Monitor, Log Analytics, and Application Insights, ensuring telemetry is available to the security operations function.
Optimize cloud spend through autoscaling, resource right-sizing, and reservation strategy, and report on run-rate and forecast.
Implement platform security controls including Entra ID, RBAC, Privileged Identity Management, Key Vault, and encryption, aligned to MAS Technology Risk Management guidelines and NIST CSF 2.0, with cybersecurity architecture review as a required gate on new designs.
Requirements
8 or more years in cloud and infrastructure roles, including at least 3 years carrying architecture and design ownership. Experience in a regulated financial services environment is advantageous.
Currently hands-on. You should be actively building and operating cloud infrastructure today, not directing others who do.
Demonstrated track record designing and delivering enterprise cloud migrations across hybrid environments, end to end.
Expert-level Azure IaaS, PaaS, and SaaS design and operation, with Azure CLI, PowerShell, and infrastructure as code using Terraform or Bicep.
Azure networking, including virtual networks, VPN Gateway, ExpressRoute, Load Balancer, Application Gateway, Traffic Manager, Azure Firewall, and security groups.
Microsoft 365 and Exchange Online administration, including conditional access, email security, and Intune device management and compliance.
Identity and platform security, including Entra ID, RBAC, Privileged Identity Management, Key Vault, and Defender for Cloud.
Application modernization, including legacy-to-platform migration, Azure Web Apps, and API-based re-architecture, alongside data services such as Azure SQL, Data Factory, Synapse, and Databricks.
DevOps and automation, including CI/CD pipelines, containerization with Docker and Kubernetes, and GitHub Actions or Azure DevOps.
Delivered platform builds or migrations in a lean team. Available to execute out-of-hours cutover windows, with communication skills to articulate the business value of technical work.
Preferred certifications: AZ-305 Azure Solutions Architect Expert or AZ-104 Azure Administrator Associate. AZ-500 Azure Security Engineer Associate and multi-cloud experience with AWS or Google Cloud are advantageous.