Staff Azure Cloud Engineer, Automation

Holthouse Carlin & Van Trigt LLP
Phoenix, AZ, United States
5 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
6 years minimum
Working hours
Regular working hours

Tech stack

Microsoft Azure Bash Shell Cloud Computing Cloud Engineering Continuous Integration Domain Name System (DNS) Github Python (Programming Language) Log Analysis Windows PowerShell Policy as Code Firewalls (Computer Science)
+2 more
Build Management Terraform

Job description

Experteer Overview In this role you lead the design and build of a new Azure landing zone as part of a cloud modernization program. You will own the end-to-end Terraform and CI/CD setup, pipelines, and security/governance standards, collaborating across IT, security, and network teams. You codify cloud standards into automation and guide the path toward self-service deployment for developers. This is a hands-on, senior engineering position focused on delivering a scalable, compliant cloud foundation. You will shape the tooling and patterns that future engineers follow. Compensation / Benefits * Design and build the Azure landing zone aligned with CAF design areas and Well-Architected Framework * Own Terraform Cloud setup and state strategy * Configure hub-spoke networking, NSGs, Azure Firewall, WAF, DNS, and private endpoints * Codify cloud engineering practice: standards for modules, repos, branching, and policy-as-code * Establish guardrails for governance and automate plan/apply gating in CI/CD * Implement security and observability baseline with Defender for Cloud, Log Analytics, and Azure Policy * Coordinate Entra ID architecture and network standards with security and IT teams * Define a self-service deployment pattern to enable application teams to ship code without deep Terraform work * Set up shift-left scanning and incident prevention approaches * Guide extension of infrastructure patterns to application delivery Tasks * 6+ years in cloud infrastructure/platform engineering with production ownership * Strong hands-on experience with Azure, Terraform IaC, and networking * Deep Terraform module authorship and state management experience * Knowledge of Azure networking (hub-spoke, NSGs, Firewall, DNS) and Entra ID governance * Experience building CI/CD pipelines for IaC (GitHub Actions, Azure DevOps) * Understanding of policy-as-code (Sentinel, OPA) and IaC security scanning * Proficient scripting (PowerShell, Bash, Python) * Ability to work autonomously as the first cloud engineer on a program * Familiarity with SOC 2 controls and compliance-driven environments * Preferred: Terraform Cloud/Enterprise, Waypoint, Azure Verified Modules, SOC 2/HIPAA exposure * Preferred: Microsoft AZ-305/AZ-400 certifications Key requirements *

Requirements

gating in CI/CD * Implement security and observability baseline with Defender for Cloud, Log Analytics, and Azure Policy * Coordinate Entra ID architecture and network standards with security and IT teams * Define a self-service deployment pattern to enable application teams to ship code without deep Terraform work * Set up shift-left scanning and incident prevention approaches * Guide extension of infrastructure patterns to application delivery Tasks * 6+ years in cloud infrastructure/platform engineering with production ownership * Strong hands-on experience with Azure, Terraform IaC, and networking * Deep Terraform module authorship and state management experience * Knowledge of Azure networking (hub-spoke, NSGs, Firewall, DNS) and Entra ID governance * Experience building CI/CD pipelines for IaC (GitHub Actions, Azure DevOps) * Understanding of policy-as-code (Sentinel, OPA) and IaC security scanning * Proficient scripting (PowerShell, Bash, Python) * Ability to work autonomously as the first cloud engineer on a program * Familiarity with SOC 2 controls and compliance-driven environments * Preferred: Terraform Cloud/Enterprise, Waypoint, Azure Verified Modules, SOC 2/HIPAA exposure * Preferred: Microsoft AZ-305/AZ-400 certifications Key requirements *

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on us.experteer.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · WWC 2023

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

3:52 min

Avoiding remote code execution from unsanitized inputs

Alexander Pirker · WWC 2022

2:17 min

Validating and applying Terraform templates via DevOps agents

Marcel Scherenberg Marcel Scherenberg · WWC 2025

54 sec

Interpreting complex terminal commands safely using external explanation utilities

Dan Cranney +2 · LIVE

2:32 min

Overview of Terraform and Terraform Cloud features

Devlin Duldulao · LIVE

Videos

See all

Related articles

See all