Remote Principal Cloud Engineer (Microsoft Azure)

MRIOA HOLDINGS, LLC
United States
about 1 month ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Shift work
Job source

Tech stack

Microsoft Access Artificial Intelligence Architectural Patterns Audit Trail Microsoft Azure Bash Shell Cloud Computing Cloud Engineering Cyber Security Information Systems Continuous Integration DevOps
+30 more
Disaster Recovery Domain Name System (DNS) Electronic Data Interchange (EDI) Github Network Topologies Identity and Access Management Virtual Private Networks (VPN) Python (Programming Language) Key Management Network Security Network Connections Network Segmentation Windows PowerShell Role-Based Access Control Zero Trust Network Access Runbook Security Software Scripting Computer Networking Systems File Transfer Protocol (FTP) Firewalls (Computer Science) Gitlab Information Technology Health Level Seven International Bicep Cloud Migration Cloud Optimization Terraform Api Management Key Vault

Job description

Our Principal Cloud Engineer is a senior technical leader responsible for designing, governing, and optimizing cloud infrastructure and platforms across the organization.

In this role, you will serve as the organization’s senior technical authority for cloud architecture and infrastructure, bringing extensive expertise to establish engineering standards and governance, and to lead complex cloud initiatives from design through delivery.

Beyond technical leadership, you will mentor and guide the Systems Administration and Information Security teams, ensuring knowledge is shared through documentation, standards, and coaching. You will translate complex technical concepts into clear business and operational decisions, provide leadership during critical production events, and set the benchmark for engineering excellence.

Roles: Serve as the highest-level technical authority and subject matter expert for all Azure cloud infrastructure and architecture Define cloud engineering standards, architectural patterns, and governance practices that the organization adopts and follows Own and lead cloud infrastructure projects end-to-end - from design and planning through execution, delivery, and post-deployment operations Support the Manager of IT & IS on cloud strategy, architecture roadmap, and platform investment decisions Mentor and develop the Systems Administration and Information Security teams - building organizational cloud competency through hands-on guidance, deliberate coaching, and knowledge transfer Participate in evaluating and onboarding new cloud engineering talent as the team grows Collaborate with Development teams to design and deliver application infrastructure on Azure Provide Tier 2/3 escalation support to the IT Help Desk for complex infrastructure and cloud issues Partner with the Information Security team to implement and evidence compliance controls for HITRUST 11.3r2 and SOC2

Major Responsibilities or Assigned Duties: Architect, deploy, and manage a secure Azure cloud environment including hub-spoke network topology, Virtual Networks, Network Security Groups, Azure Firewall, Application Gateway, API Management, and Private Endpoints Define and enforce cloud governance standards including subscription management, Azure Policy, resource organization, tagging taxonomy, and cost management across all environments Establish and maintain Infrastructure as Code (Terraform and/or Azure Bicep) practices including module structure, state management, review workflow, and environment promotion - ensuring all infrastructure changes are version-controlled, peer-reviewed, and auditable with no undocumented manual changes in production Build and own CI/CD pipelines for infrastructure deployments with automated security scanning, testing, and progressive delivery Establish change management and release governance processes ensuring all infrastructure changes are reviewable, approved, and auditable in a regulated healthcare environment - without becoming a bottleneck Lead cloud migration projects - assess workloads, develop migration strategies, execute cutovers, validate post-migration health, and decommission legacy infrastructure Design and deliver Azure infrastructure for new application onboarding; create reusable patterns and templates the team follows for future workloads Manage hybrid connectivity including ExpressRoute, VPN Gateway, and site-to-site connectivity between Azure and on-premises environments Design and maintain cloud observability covering metrics, logs, and alerting with SLOs that reflect real operational impact - ensuring the team catches issues before they affect the business Establish formal incident response processes including runbooks, escalation paths, and post-incident reviews; own disaster recovery and business continuity planning with defined and tested RPO/RTO targets Manage Azure identity and access architecture including Entra ID, Role-Based Access Control (RBAC), Privileged Identity Management (PIM), Key Vault, and Managed Identities Implement cloud security controls as defined by the Information Security team; build audit logging, evidence generation, and access-review processes that satisfy HITRUST 11.3r2, SOC2, and HIPAA requirements and hold up during audits Manage DNS, certificate lifecycle, and network connectivity supporting data exchange with payers, health plans, and external partners Develop scripting and automation solutions (PowerShell, Python, or Bash) to reduce manual operational burden and improve team efficiency Define the engineering standards, runbooks, and documentation the team inherits; manage infrastructure and platform vendor relationships and SLAs Create and maintain comprehensive technical documentation - architecture diagrams, runbooks, standard operating procedures, and how-to guides - that build team knowledge and reduce key-person dependency Support after-hours availability and on-call response for critical infrastructure events as requested Complete other duties as requested

Requirements

7-10 years of experience in infrastructure, systems, or cloud engineering. 5 years of senior or principal-level experience in Microsoft Azure Demonstrated experience building or establishing a cloud engineering practice or function - not just operating an existing one; comfort setting standards others follow Expert-level knowledge of Azure networking including hub-spoke topology, Virtual Networks, NSGs, Azure Firewall, Application Gateway, ExpressRoute, Private Endpoints, and DNS Proven ability to independently architect Azure environments - designing governance, security, and operational frameworks from the ground up, not inheriting them Expert-level experience with Infrastructure as Code (Terraform or Azure Bicep), including module design, state management, CI/CD integration, and enforcement of no-manual-change disciplines Strong experience with CI/CD pipeline tooling (Azure DevOps, GitLab, or GitHub Actions), including automated security scanning and progressive delivery practices Demonstrated experience leading cloud migration projects, including workload assessment, planning, execution, and legacy decommission Strong project leadership - able to own and drive multiple complex initiatives simultaneously with minimal oversight Proven ability to mentor and develop technical staff across multiple teams; experience building organizational capability through deliberate knowledge transfer and hands-on coaching Experience establishing incident response, disaster recovery, and business continuity practices with defined and tested RPO/RTO targets Expert-level knowledge of Azure identity and security services, including Entra ID, RBAC, PIM, Key Vault, and Defender for Cloud Strong networking and security fundamentals: network segmentation, secrets management, least-privilege access, and certificate lifecycle management Proficiency in at least one scripting or automation language (PowerShell, Python, or Bash) Working knowledge of compliance frameworks (HITRUST, SOC2, HIPAA) with experience building audit evidence processes that hold up under scrutiny Clear written communication and sound judgment under production pressure - able to make decisions and convey technical context to non-technical stakeholders Experience with Zero Trust Network Access (ZTNA) solutions preferred Experience with Azure AI and platform services preferred Familiarity with healthcare data exchange standards (EDI, HL7, or SFTP-based interfaces) preferred

Education and Certifications

Bachelor’s degree in Information Technology, Computer Science, Information Systems, or a related field, or equivalent professional experience AZ-104 (Azure Administrator Associate) required - must already hold AZ-700 (Azure Network Engineer Associate) required - must already hold AZ-305 (Azure Solutions Architect Expert) required - must already hold AZ-400 (DevOps Engineer Expert) strongly preferred, Ability to sit at a desk, utilize a computer, telephone, and other basic office equipment is required. This role is designed to be a remote position (work-from-home).

Benefits & conditions

Pulled from the full job description

  • Health insurance
  • 401(k) matching
  • Vision insurance
  • Dental insurance
  • Paid holidays, A competitive compensation package. Benefits include healthcare, vision, and dental insurance, a generous 401 (k) match, paid vacation, personal time, and holidays. Growth and training opportunities. An award-winning remote work environment

About the company

Sensitive Personal Info: MRIoA may collect sensitive personal info such as real name, nickname or alias, postal address, telephone number, email address, Social Security number, signature, online identifier, Internet Protocol address, driver’s license number, or state identification card number, and passport number.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:13 min

Defining cloud proficiency by technical role

Piet Van Dongen · LIVE

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

2:56 min

Provisioning a secure container infrastructure with Bicep

Matthias Falkenberg +1 · World Congress 2022

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

2:40 min

Using GitHub primitives for internal documentation and corporate operations

Kyle Daigle · Coffee With Developers

Videos

See all

Related articles

See all