Staff Azure Cloud Engineer, Automation

Holthouse Carlin & Van Trigt LLP
Fort Worth, TX, United States
5 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Microsoft Azure Bash Shell Cloud Computing Cloud Engineering Continuous Integration Domain Name System (DNS) Python (Programming Language) Log Analysis Windows PowerShell Software Deployment Software Engineering Policy as Code
+5 more
Firewalls (Computer Science) Build Management Hashicorp Terraform Vulnerability Analysis

Job description

Experteer Overview In this role you will lead the design and build of a new Azure landing zone to underpin a multi-year cloud modernization program. You will own hands-on Terraform-based infrastructure, pipelines, and security guardrails, working as the senior cloud engineering voice with IT, security, and network teams. You will set standards, codify processes, and enable self-service deployment patterns for other engineers. This is a practical, impact-driven role with a strong emphasis on governance, automation, and security. Compensation / Benefits * Design and build the Azure landing zone aligned with CAF and Well-Architected Framework * Develop Terraform modules and manage Terraform Cloud workspace and state strategy * Configure networking and security (hub-spoke, NSGs, Azure Firewall, WAF, private endpoints, DNS) * Codify to-be cloud-native software engineering practices and CI/CD for infrastructure * Establish policy-as-code guardrails and shift-left tooling for IaC * Implement security and observability baseline (Defender for Cloud, Log Analytics, Azure Policy) * Coordinate Entra ID architecture with security and network teams * Define module structure, documentation, and code-review standards for future hires * Create a self-service application deployment pattern and golden path for engineers Tasks * 6+ years in cloud infrastructure/platform engineering with production ownership * Strong Azure generalist with Terraform/IaC, networking, and security expertise * Hands-on Terraform module authorship and state management * Experience with Azure networking, security, and governance (hub-spoke, NSGs, Azure Policy) * Knowledge of SOC 2 control families and designing compliant landing zones * Experience building CI/CD pipelines for infrastructure changes * Familiarity with policy-as-code approaches and IaC security scanning * Strong scripting (PowerShell, Bash, Python) for automation * Ability to work independently and influence decisions on a new program * Experience with HashiCorp HCP Waypoint or similar IDP (preferred) Key requirements *

Requirements

Experteer Overview In this role you will lead the design and build of a new Azure landing zone to underpin a multi-year cloud modernization program. You will own hands-on Terraform-based infrastructure, pipelines, and security guardrails, working as the senior cloud engineering voice with IT, security, and network teams. You will set standards, codify processes, and enable self-service deployment patterns for other engineers. This is a practical, impact-driven role with a strong emphasis on governance, automation, and security. Compensation / Benefits * Design and build the Azure landing zone aligned with CAF and Well-Architected Framework * Develop Terraform modules and manage Terraform Cloud workspace and state strategy * Configure networking and security (hub-spoke, NSGs, Azure Firewall, WAF, private endpoints, DNS) * Codify to-be cloud-native software engineering practices and CI/CD for infrastructure * Establish policy-as-code guardrails and shift-left tooling for IaC * aaaaa with security and observability baseline (Defender for Cloud, Log Analytics, Azure Policy) * Coordinate Entra ID architecture with security and network teams * Define module structure, documentation, and code-review standards for future hires * Create a self-service application deployment pattern and golden path for engineers Tasks * 6+ years in cloud infrastructure/platform engineering with production ownership * Strong Azure generalist with Terraform/IaC, networking, and security expertise * Hands-on Terraform module authorship and state management * Experience with Azure networking, security, and governance (hub-spoke, NSGs, Azure Policy) * Knowledge of SOC 2 control families and designing compliant landing zones * Experience building CI/CD pipelines for infrastructure changes * Familiarity with policy-as-code approaches and IaC security scanning * Strong scripting (PowerShell, Bash, Python) for automation * Ability to work independently and influence decisions on a new program * Experience with HashiCorp HCP Waypoint or similar IDP (preferred) Key requirements *

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on us.experteer.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

5:24 min

Demonstrating database encryption at rest with HashiCorp Vault

Alex Soto Alex Soto · LIVE

3:52 min

Avoiding remote code execution from unsanitized inputs

Alexander Pirker · WWC 2022

2:17 min

Validating and applying Terraform templates via DevOps agents

Marcel Scherenberg Marcel Scherenberg · WWC 2025

2:32 min

Overview of Terraform and Terraform Cloud features

Devlin Duldulao · LIVE

4:44 min

Core features of Terraform and HashiCorp Configuration Language

Hennie Francis · LIVE

Videos

See all

Related articles

See all