Job Summary
Citrix On-Premise to Azure Architect (VDI + Cloud + Security) (L4) Role Summary We are looking for a senior End-User Computing Architect to lead the transformation of the customer\'s on-premises Citrix Virtual Apps and Desktops estate to Azure under Lot 3. The architect will own the end-to-end solution across VDI, cloud landing zone and security, produce design artefacts for customer design authority approval, define the migration approach and wave plan, and provide technical leadership to the migration engineering team through to transition into BAU.
Key Responsibilities
Key Responsibilities Current-state assessment: Assess the existing Citrix estate — sites, Delivery Controllers, StoreFront, NetScaler / ADC, MCS / PVS, App Layering, WEM, profile management, policies, licensing — together with user personas, application inventory and utilisation / concurrency data. Target architecture & options: Define the target VDI platform on Azure (Citrix DaaS with Azure-hosted VDAs, native AVD, or a hybrid model) and produce options analyses and decision papers covering user experience, security, cost, risk and operability. Design artefacts: Author HLDs, LLDs, architecture decision records and build guides; present designs to the customer design authority and CAB; track open decisions and risks through to sign-off. Cloud landing zone integration: Integrate the VDI workload into the Azure landing zone — hub-spoke / Virtual WAN, ExpressRoute / VPN, Azure Firewall, NSG / ASG, private endpoints, private DNS — aligned to the Cloud Adoption Framework and customer policy. Identity & access: Design the identity model — AD DS / Entra hybrid join or Entra join, Conditional Access, MFA, SSO / Citrix FAS, Entra Kerberos for Azure Files — and the secure access path (Citrix Gateway service / NetScaler or ZTNA). Security architecture: Apply Zero Trust principles: image hardening (CIS baselines), Microsoft Defender for Endpoint / Defender for Cloud, Sentinel integration, encryption and Key Vault, privileged access (PIM), and data-exfiltration controls (clipboard, drive mapping, screen capture, watermarking). Image & application strategy: Define golden image pipelines (Azure Image Builder / Packer, Azure Compute Gallery, MCS), application layering or MSIX app attach approach, and application rationalisation and compatibility testing. Profiles & data: Design FSLogix on Azure Files Premium / Azure NetApp Files, the profile migration approach from Citrix UPM, and OneDrive Known Folder Move where applicable. Sizing, cost & FinOps: Select VM families (including GPU where needed), user density and autoscale (Citrix Autoscale / AVD scaling plans); build the cost model with Reserved Instances / Savings Plans and right-sizing guidance. Migration strategy & wave planning: Define the migration factory — pilot, UAT, persona-based waves, co-existence with on-premises Citrix, cutover and rollback, hypercare and decommissioning — and the runbooks used by the L2 migration engineers. Resilience & operations: Design BCDR (availability zones, secondary region, profile replication, RPO / RTO) and the monitoring model (Citrix Monitor, AVD Insights, Azure Monitor); define the operating model and handover into BAU. Technical leadership: Lead and review the work of migration engineers; engage customer architects, security, network and application owners; support effort estimation, SOW inputs and status reporting.
Skill Requirements
Mandatory Skills 10-12 years designing and delivering Citrix Virtual Apps and Desktops (7.x LTSR / current releases) including NetScaler / Citrix Gateway 4-6 years Azure infrastructure architecture — compute, networking, storage, identity, governance At least one end-to-end enterprise migration of on-premises VDI to Azure (Citrix DaaS on Azure and/or AVD) in an architect role Strong Azure networking and hybrid connectivity — hub-spoke / vWAN, ExpressRoute, Azure Firewall, private endpoints, DNS Identity and security architecture — AD DS, Entra ID, Conditional Access, Defender, Zero Trust controls for VDI FSLogix and profile migration design; golden image and application delivery strategy Authoring HLD / LLD documentation and presenting to design authority / CAB forums Sizing, capacity planning and Azure cost modelling for VDI workloads Good-to-Have Skills Azure Virtual Desktop and Windows 365 design experience Citrix DaaS / Citrix Cloud, WEM and App Layering Infrastructure as Code — Terraform or Bicep — and CI/CD for image pipelines Microsoft Intune and modern management of session hosts Zscaler ZPA / ZTNA or other SSE platforms Monitoring / DEX tools (e.g., ControlUp, uberAgent, Lakeside SysTrack) Exposure to VMware Horizon or other VDI platforms
Other Requirements
Certifications Microsoft Certified: Azure Solutions Architect Expert (AZ-305) — required / strongly preferred Microsoft Certified: Azure Virtual Desktop Specialty (AZ-140) — preferred Microsoft Cybersecurity Architect (SC-100) or Azure Security Engineer (AZ-500) — preferred Citrix Certified Expert / Professional – Virtualization (CCE-V / CCP-V) — preferred TOGAF or equivalent architecture certification — desirable Behavioural Competencies Confident client-facing communicator able to lead design workshops and defend design decisions Structured, governance-minded approach — decisions routed to accountable owners and recorded Mentors and leads engineers; balances delivery pace with quality and security Comfortable working with global stakeholders across time zones