Staff Azure Cloud Engineer, Automation
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+5 more
Job description
Experteer Overview In this role you will lead the design and build of a new Azure landing zone to enable a multi-year cloud modernization program. You will own hands-on engineering, from Terraform modules to CI/CD pipelines, and shape the cloud platform standards with security and network teams. You’ll establish policy-as-code guardrails, drive shift-left security, and set a self-service deployment pattern for developers. This is a rare opportunity to set the technical direction and deliver a scalable, compliant cloud foundation for the firm. Compensation / Benefits * Design and build the Azure landing zone aligned with CAF and Well-Architected Framework * Own Terraform Cloud setup including state management and variable strategy * Configure and troubleshoot networking and firewall components (hub-spoke, NSGs, Azure Firewall, WAF, private endpoints, DNS) * Codify to-be cloud-native software engineering practices and standards * Establish policy-as-code guardrails and governance for all plans * Develop CI/CD pipelines for infrastructure changes with gating and reviews * Enable shift-left scanning for IaC, code, and dependencies * Set up security and observability baseline (Defender for Cloud, Log Analytics, Azure Policy) * Coordinate Entra ID architecture with identity/security and network teams * Define a golden path for self-service deployment of applications onto the landing zone * Lead by example in module structure, versioning, documentation, and code review standards * Extend the paved path from infrastructure to application delivery Tasks * 6+ years in cloud infrastructure/platform engineering with production ownership * Well-rounded Azure Cloud generalist across Terraform/IaC, networking, and security * Deep hands-on Terraform experience (modules, remote state, environment strategy) * Strong Azure networking and security expertise (hub-spoke, NSGs, firewall, WAF, DNS, private endpoints) * Knowledge of SOC 2 control families related to design of landing zones * Experience building CI/CD pipelines for infrastructure changes * Familiarity with policy-as-code approaches (Sentinel, OPA) and IaC security scanning * Scripting ability (PowerShell, Bash, Python) for tooling and automation * Ability to operate as the first cloud engineer on a program and make decisions autonomously * Prefer experience with Terraform Cloud/Enterprise and Azure Verified Modules * Mentoring experience and familiarity with internal developer platforms (IDP) would be a plus Key requirements *
Requirements
Experteer Overview In this role you will lead the design and build of a new Azure landing zone to enable a multi-year cloud modernization program. You will own hands-on engineering, from Terraform modules to CI/CD pipelines, and shape the cloud platform standards with security and network teams. You’ll establish policy-as-code guardrails, drive shift-left security, and set a self-service deployment pattern for developers. This is a rare opportunity to set the technical direction and deliver a scalable, compliant cloud foundation for the firm. Compensation / Benefits * Design and build the Azure landing zone aligned with CAF and Well-Architected Framework * Own Terraform Cloud setup including state management and variable strategy * Configure and troubleshoot networking and firewall components (hub-spoke, NSGs, Azure Firewall, WAF, private endpoints, DNS) * Codify to-be cloud-native software engineering practices and standards * Establish policy-as-code guardrails and governance aE _ all plans * Develop CI/CD pipelines for infrastructure changes with gating and reviews * Enable shift-left scanning for IaC, code, and dependencies * Set up security and observability baseline (Defender for Cloud, Log Analytics, Azure Policy) * Coordinate Entra ID architecture with identity/security and network teams * Define a golden path for self-service deployment of applications onto the landing zone * Lead by example in module structure, versioning, documentation, and code review standards * Extend the paved path from infrastructure to application delivery Tasks * 6+ years in cloud infrastructure/platform engineering with production ownership * Well-rounded Azure Cloud generalist across Terraform/IaC, networking, and security * Deep hands-on Terraform experience (modules, remote state, environment strategy) * Strong Azure networking and security expertise (hub-spoke, NSGs, firewall, WAF, DNS, private endpoints) * Knowledge of SOC 2 control families related to design of landing a aaM_ * Experience building CI/CD pipelines for infrastructure changes * Familiarity with policy-as-code approaches (Sentinel, OPA) and IaC security scanning * Scripting ability (PowerShell, Bash, Python) for tooling and automation * Ability to operate as the first cloud engineer on a program and make decisions autonomously * Prefer experience with Terraform Cloud/Enterprise and Azure Verified Modules * Mentoring experience and familiarity with internal developer platforms (IDP) would be a plus Key requirements *
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on us.experteer.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence
Dev Digest 120 - Apple and peers
Dev Digest 121 - AI goes offline
Fully Remote Software Engineer Jobs