Staff Azure Cloud Engineer, Automation

Holthouse Carlin & Van Trigt LLP
Irvine, CA, United States
5 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Microsoft Azure Bash Shell Cloud Computing Cloud Engineering Code Review Domain Name System (DNS) Python (Programming Language) Log Analysis Windows PowerShell Software Engineering Management of Software Versions Policy as Code
+5 more
Scripting Cloud Platform System Firewalls (Computer Science) Build Management Terraform

Job description

Experteer Overview In this role you will lead the design and build of a new Azure landing zone to enable a multi-year cloud modernization program. You will own hands-on engineering, from Terraform modules to CI/CD pipelines, and shape the cloud platform standards with security and network teams. You’ll establish policy-as-code guardrails, drive shift-left security, and set a self-service deployment pattern for developers. This is a rare opportunity to set the technical direction and deliver a scalable, compliant cloud foundation for the firm. Compensation / Benefits * Design and build the Azure landing zone aligned with CAF and Well-Architected Framework * Own Terraform Cloud setup including state management and variable strategy * Configure and troubleshoot networking and firewall components (hub-spoke, NSGs, Azure Firewall, WAF, private endpoints, DNS) * Codify to-be cloud-native software engineering practices and standards * Establish policy-as-code guardrails and governance for all plans * Develop CI/CD pipelines for infrastructure changes with gating and reviews * Enable shift-left scanning for IaC, code, and dependencies * Set up security and observability baseline (Defender for Cloud, Log Analytics, Azure Policy) * Coordinate Entra ID architecture with identity/security and network teams * Define a golden path for self-service deployment of applications onto the landing zone * Lead by example in module structure, versioning, documentation, and code review standards * Extend the paved path from infrastructure to application delivery Tasks * 6+ years in cloud infrastructure/platform engineering with production ownership * Well-rounded Azure Cloud generalist across Terraform/IaC, networking, and security * Deep hands-on Terraform experience (modules, remote state, environment strategy) * Strong Azure networking and security expertise (hub-spoke, NSGs, firewall, WAF, DNS, private endpoints) * Knowledge of SOC 2 control families related to design of landing zones * Experience building CI/CD pipelines for infrastructure changes * Familiarity with policy-as-code approaches (Sentinel, OPA) and IaC security scanning * Scripting ability (PowerShell, Bash, Python) for tooling and automation * Ability to operate as the first cloud engineer on a program and make decisions autonomously * Prefer experience with Terraform Cloud/Enterprise and Azure Verified Modules * Mentoring experience and familiarity with internal developer platforms (IDP) would be a plus Key requirements *

Requirements

Experteer Overview In this role you will lead the design and build of a new Azure landing zone to enable a multi-year cloud modernization program. You will own hands-on engineering, from Terraform modules to CI/CD pipelines, and shape the cloud platform standards with security and network teams. You’ll establish policy-as-code guardrails, drive shift-left security, and set a self-service deployment pattern for developers. This is a rare opportunity to set the technical direction and deliver a scalable, compliant cloud foundation for the firm. Compensation / Benefits * Design and build the Azure landing zone aligned with CAF and Well-Architected Framework * Own Terraform Cloud setup including state management and variable strategy * Configure and troubleshoot networking and firewall components (hub-spoke, NSGs, Azure Firewall, WAF, private endpoints, DNS) * Codify to-be cloud-native software engineering practices and standards * Establish policy-as-code guardrails and governance aE _ all plans * Develop CI/CD pipelines for infrastructure changes with gating and reviews * Enable shift-left scanning for IaC, code, and dependencies * Set up security and observability baseline (Defender for Cloud, Log Analytics, Azure Policy) * Coordinate Entra ID architecture with identity/security and network teams * Define a golden path for self-service deployment of applications onto the landing zone * Lead by example in module structure, versioning, documentation, and code review standards * Extend the paved path from infrastructure to application delivery Tasks * 6+ years in cloud infrastructure/platform engineering with production ownership * Well-rounded Azure Cloud generalist across Terraform/IaC, networking, and security * Deep hands-on Terraform experience (modules, remote state, environment strategy) * Strong Azure networking and security expertise (hub-spoke, NSGs, firewall, WAF, DNS, private endpoints) * Knowledge of SOC 2 control families related to design of landing a aaM_ * Experience building CI/CD pipelines for infrastructure changes * Familiarity with policy-as-code approaches (Sentinel, OPA) and IaC security scanning * Scripting ability (PowerShell, Bash, Python) for tooling and automation * Ability to operate as the first cloud engineer on a program and make decisions autonomously * Prefer experience with Terraform Cloud/Enterprise and Azure Verified Modules * Mentoring experience and familiarity with internal developer platforms (IDP) would be a plus Key requirements *

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on us.experteer.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:17 min

Validating and applying Terraform templates via DevOps agents

Marcel Scherenberg Marcel Scherenberg · WWC 2025

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

3:52 min

Avoiding remote code execution from unsanitized inputs

Alexander Pirker · WWC 2022

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

2:32 min

Overview of Terraform and Terraform Cloud features

Devlin Duldulao · LIVE

3:46 min

Navigating a career in cloud transformation consulting

Piet Van Dongen · LIVE

Videos

See all

Related articles

See all