Staff Azure Cloud Engineer, Automation

Holthouse Carlin & Van Trigt LLP
Westlake Village, CA, United States
5 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Adobe InDesign Microsoft Azure Bash Shell Cloud Computing Cloud Engineering Code Review Continuous Integration Domain Name System (DNS) Github Python (Programming Language) Log Analysis Windows PowerShell
+8 more
Policy as Code Scripting Cloud Platform System Firewalls (Computer Science) Build Management Hashicorp Firewall Services Module Terraform

Job description

Experteer Overview In this role you lead the Azure cloud modernization initiative, owning design, automation, and deployment for a new Azure landing zone. You translate security, networking, and governance requirements into scalable IaC pipelines and self-service patterns. You work closely with security and IT teams to codify standards and drive the cloud program forward. This position offers hands-on ownership, fast impact, and a path to shaping the firm’s cloud platform and development practices. Compensation / Benefits * Design and build the Azure landing zone aligned with CAF and Well-Architected Framework * Own Terraform Cloud setup, including workspace structure and state strategy * Hands-on networking and firewall configuration (hub-spoke, NSGs, Azure Firewall, WAF, private endpoints, DNS) * Define and codify cloud-native engineering practices; establish standards for modules, repos, and reviews * Implement policy-as-code guardrails and shift-left security/testing tooling * Build and maintain CI/CD pipelines for infrastructure changes with gating and approvals * Set up security and observability baselines (Defender for Cloud, Log Analytics, Azure Policy) * Coordinate Entra ID architecture with identity/security and network teams * Create a self-service deployment pattern (“golden path”) for application delivery * Set the standard for module structure, documentation, and code review for future hires Tasks * 6+ years in cloud infrastructure/platform engineering with production ownership * Strong Terraform/IaC experience including module authorship and state management * Deep Azure networking and security expertise (hub-spoke, NSGs, Azure Firewall, DNS, private endpoints) * Experience building CI/CD for infrastructure changes (GitHub Actions, Azure DevOps) * Knowledge of policy-as-code approaches (Sentinel, OPA) and IaC security scanning * Scripting skills (PowerShell, Bash, Python) for tooling and automation * Ability to make and defend decisions as the first cloud engineer on the program * Preferred:Terraform Cloud/Enterprise, Azure Verified Modules, experience in compliance-driven environments * Preferred: HashiCorp HCP Waypoint or internal developer platform * Preferred: SOC 2/HIPAA awareness in design * Certifications: Azure-related (AZ-305, AZ-400) and Terraform Associate/Professional Key requirements *

Requirements

aav_ and maintain CI/CD pipelines for infrastructure changes with gating and approvals * Set up security and observability baselines (Defender for Cloud, Log Analytics, Azure Policy) * Coordinate Entra ID architecture with identity/security and network teams * Create a self-service deployment pattern (“golden path”) for application delivery * Set the standard for module structure, documentation, and code review for future hires Tasks * 6+ years in cloud infrastructure/platform engineering with production ownership * Strong Terraform/IaC experience including module authorship and state management * Deep Azure networking and security expertise (hub-spoke, NSGs, Azure Firewall, DNS, private endpoints) * Experience building CI/CD for infrastructure changes (GitHub Actions, Azure DevOps) * Knowledge of policy-as-code approaches (Sentinel, OPA) and IaC security scanning * Scripting skills (PowerShell, Bash, Python) for tooling and automation * Ability to make and defend decisions as the first cloud engineer on the program * Preferred:Terraform Cloud/Enterprise, Azure Verified Modules, experience in compliance-driven environments * Preferred: HashiCorp HCP Waypoint or internal developer platform * Preferred: SOC 2/HIPAA awareness in design * Certifications: Azure-related (AZ-305, AZ-400) and Terraform Associate/Professional Key requirements *

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on us.experteer.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · WWC 2023

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

5:24 min

Demonstrating database encryption at rest with HashiCorp Vault

Alex Soto Alex Soto · LIVE

2:17 min

Validating and applying Terraform templates via DevOps agents

Marcel Scherenberg Marcel Scherenberg · WWC 2025

2:32 min

Overview of Terraform and Terraform Cloud features

Devlin Duldulao · LIVE

4:44 min

Core features of Terraform and HashiCorp Configuration Language

Hennie Francis · LIVE

Videos

See all

Related articles

See all