> Markdown version of [/jobs/ext/1973602-staff-azure-cloud-engineer-automation](https://www.wearedevelopers.com/jobs/ext/1973602-staff-azure-cloud-engineer-automation). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff Azure Cloud Engineer, Automation - **Company:** Holthouse Carlin & Van Trigt LLP - **Location:** Irvine, CA, United States - **Contract:** Permanent contract - **Skills:** Microsoft Azure, Bash Shell, Cloud Computing, Cloud Engineering, Code Review, Domain Name System (DNS), Python (Programming Language), Log Analysis, Windows PowerShell, Software Engineering, Management of Software Versions, Policy as Code, Scripting, Cloud Platform System, Firewalls (Computer Science), Build Management, Terraform - **Published:** August 7, 2026 - **Apply:** https://us.experteer.com/career/view-jobs/staff-azure-cloud-engineer-automation-irvine-ca-usa-58834635 ## About the Role Experteer Overview In this role you will lead the design and build of a new Azure landing zone to enable a multi-year cloud modernization program. You will own hands-on engineering, from Terraform modules to CI/CD pipelines, and shape the cloud platform standards with security and network teams. You'll establish policy-as-code guardrails, drive shift-left security, and set a self-service deployment pattern for developers. This is a rare opportunity to set the technical direction and deliver a scalable, compliant cloud foundation for the firm. Compensation / Benefits * Design and build the Azure landing zone aligned with CAF and Well-Architected Framework * Own Terraform Cloud setup including state management and variable strategy * Configure and troubleshoot networking and firewall components (hub-spoke, NSGs, Azure Firewall, WAF, private endpoints, DNS) * Codify to-be cloud-native software engineering practices and standards * Establish policy-as-code guardrails and governance aE _ all plans * Develop CI/CD pipelines for infrastructure changes with gating and reviews * Enable shift-left scanning for IaC, code, and dependencies * Set up security and observability baseline (Defender for Cloud, Log Analytics, Azure Policy) * Coordinate Entra ID architecture with identity/security and network teams * Define a golden path for self-service deployment of applications onto the landing zone * Lead by example in module structure, versioning, documentation, and code review standards * Extend the paved path from infrastructure to application delivery Tasks * 6+ years in cloud infrastructure/platform engineering with production ownership * Well-rounded Azure Cloud generalist across Terraform/IaC, networking, and security * Deep hands-on Terraform experience (modules, remote state, environment strategy) * Strong Azure networking and security expertise (hub-spoke, NSGs, firewall, WAF, DNS, private endpoints) * Knowledge of SOC 2 control families related to design of landing a aaM_ * Experience building CI/CD pipelines for infrastructure changes * Familiarity with policy-as-code approaches (Sentinel, OPA) and IaC security scanning * Scripting ability (PowerShell, Bash, Python) for tooling and automation * Ability to operate as the first cloud engineer on a program and make decisions autonomously * Prefer experience with Terraform Cloud/Enterprise and Azure Verified Modules * Mentoring experience and familiarity with internal developer platforms (IDP) would be a plus Key requirements * ## Description Experteer Overview In this role you will lead the design and build of a new Azure landing zone to enable a multi-year cloud modernization program. You will own hands-on engineering, from Terraform modules to CI/CD pipelines, and shape the cloud platform standards with security and network teams. You'll establish policy-as-code guardrails, drive shift-left security, and set a self-service deployment pattern for developers. This is a rare opportunity to set the technical direction and deliver a scalable, compliant cloud foundation for the firm. Compensation / Benefits * Design and build the Azure landing zone aligned with CAF and Well-Architected Framework * Own Terraform Cloud setup including state management and variable strategy * Configure and troubleshoot networking and firewall components (hub-spoke, NSGs, Azure Firewall, WAF, private endpoints, DNS) * Codify to-be cloud-native software engineering practices and standards * Establish policy-as-code guardrails and governance for all plans * Develop CI/CD pipelines for infrastructure changes with gating and reviews * Enable shift-left scanning for IaC, code, and dependencies * Set up security and observability baseline (Defender for Cloud, Log Analytics, Azure Policy) * Coordinate Entra ID architecture with identity/security and network teams * Define a golden path for self-service deployment of applications onto the landing zone * Lead by example in module structure, versioning, documentation, and code review standards * Extend the paved path from infrastructure to application delivery Tasks * 6+ years in cloud infrastructure/platform engineering with production ownership * Well-rounded Azure Cloud generalist across Terraform/IaC, networking, and security * Deep hands-on Terraform experience (modules, remote state, environment strategy) * Strong Azure networking and security expertise (hub-spoke, NSGs, firewall, WAF, DNS, private endpoints) * Knowledge of SOC 2 control families related to design of landing zones * Experience building CI/CD pipelines for infrastructure changes * Familiarity with policy-as-code approaches (Sentinel, OPA) and IaC security scanning * Scripting ability (PowerShell, Bash, Python) for tooling and automation * Ability to operate as the first cloud engineer on a program and make decisions autonomously * Prefer experience with Terraform Cloud/Enterprise and Azure Verified Modules * Mentoring experience and familiarity with internal developer platforms (IDP) would be a plus Key requirements * ## Related Videos - [Building Applications with Infrastructure as Code](https://www.wearedevelopers.com/videos/887-building-applications-with-infrastructure-as-code) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Old tools, new tricks](https://www.wearedevelopers.com/videos/1916-old-tools-new-tricks) - [Terraform for Developers](https://www.wearedevelopers.com/videos/3-terraform-for-developers) - [Implementing Feature Environments with AWS and Terraform](https://www.wearedevelopers.com/videos/531-implementing-feature-environments-with-aws-and-terraform) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [What Makes WeAreDevelopers World Congress Different From Every Other Tech Event?](https://www.wearedevelopers.com/magazine/701-what-makes-wearedevelopers-world-congress-different-from-every-other-tech-event)