Staff Azure Cloud Engineer, Automation

Holthouse Carlin & Van Trigt LLP
Denver, CO, United States
3 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Microsoft Azure Bash Shell Cloud Computing Cloud Engineering Code Review Domain Name System (DNS) Python (Programming Language) Log Analysis Windows PowerShell Management of Software Versions Policy as Code Scripting
+5 more
Delivery Pipeline Firewalls (Computer Science) Build Management Firewall Services Module Terraform

Job description

Experteer Overview In this role you will lead the design and build of a new Azure landing zone as part of a multi-year cloud modernization program. You work hands-on as an IC, setting the technical bar and coding the automation that others follow. You collaborate with IT, security, and network teams to codify standards, build pipelines, and enable self-service deployment at scale. This is a chance to shape secure, automated infrastructure for a growing firm with a strong focus on excellence. Compensation / Benefits * Design and build the Azure landing zone aligned with CAF and Well-Architected Framework * Develop and compose Terraform modules on AVM; avoid full hand-rolling * Own Terraform Cloud setup: state, variables, run triggers, remote state * Hands-on networking and firewall configuration (hub-spoke, NSGs, Azure Firewall, WAF) * Define and codify to-be cloud-native engineering practices and workflows * Establish policy-as-code guardrails (e.g., Sentinel, OPA) for automatic governance * Build CI/CD pipelines for infrastructure changes with gate and reviews * Set up security and observability baseline (Defender for Cloud, Log Analytics, Azure Policy) * Coordinate Entra ID architecture with security and network teams * Create a golden self-service deployment path for app teams * Define module structure, versioning, and code review standards for future hires * Extend the path from infrastructure to application delivery for faster ship of code Tasks * 6+ years in cloud infrastructure/platform engineering with production ownership * Well-rounded Azure Cloud generalist (Terraform/IaC, networking, security) * Deep, hands-on Terraform experience (modules, remote state, environment strategy) * Strong Azure networking and security experience (hub-spoke, NSGs, Firewall, DNS, private endpoints) * Knowledge of SOC 2 controls relevant to cloud design * Experience building CI/CD pipelines for infrastructure changes * Policy-as-code knowledge (Sentinel, OPA) and IaC security scanning * Comfort as the first cloud engineer on a program and independent decision-making * Strong scripting skills (PowerShell, Bash, or Python) * Ability to define a self-service deployment pattern (golden path) for others Key requirements *

Requirements

Experteer Overview In this role you will lead the design and build of a new Azure landing zone as part of a multi-year cloud modernization program. You work hands-on as an IC, setting the technical bar and coding the automation that others follow. You collaborate with IT, security, and network teams to codify standards, build pipelines, and enable self-service deployment at scale. This is a chance to shape secure, automated infrastructure for a growing firm with a strong focus on excellence. Compensation / Benefits * Design and build the Azure landing zone aligned with CAF and Well-Architected Framework * Develop and compose Terraform modules on AVM; avoid full hand-rolling * Own Terraform Cloud setup: state, variables, run triggers, remote state * Hands-on networking and firewall configuration (hub-spoke, NSGs, Azure Firewall, WAF) * Define and codify to-be cloud-native engineering practices and workflows * Establish policy-as-code guardrails (e.g., Sentinel, OPA) for automatic governance * Build CI/CD pipelines for infrastructure changes with gate and reviews * Set up security and observability baseline (Defender for Cloud, Log Analytics, Azure Policy) * Coordinate Entra ID architecture with security and network teams * Create a golden self-service deployment path for app teams * Define module structure, versioning, and code review standards for future hires * Extend the path from infrastructure to application delivery for faster ship of code Tasks * 6+ years in cloud infrastructure/platform engineering with production ownership * Well-rounded Azure Cloud generalist (Terraform/IaC, networking, security) * Deep, hands-on Terraform experience (modules, remote state, environment strategy) * Strong Azure networking and security experience (hub-spoke, NSGs, Firewall, DNS, private endpoints) * Knowledge of SOC 2 controls relevant to cloud design * Experience building CI/CD pipelines for infrastructure changes * Policy-as-code knowledge (Sentinel, OPA) and IaC aaa Azure scanning * Comfort as the first cloud engineer on a program and independent decision-making * Strong scripting skills (PowerShell, Bash, or Python) * Ability to define a self-service deployment pattern (golden path) for others Key requirements *

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on us.experteer.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:17 min

Validating and applying Terraform templates via DevOps agents

Marcel Scherenberg Marcel Scherenberg · WWC 2025

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

3:52 min

Avoiding remote code execution from unsanitized inputs

Alexander Pirker · WWC 2022

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

2:32 min

Overview of Terraform and Terraform Cloud features

Devlin Duldulao · LIVE

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

Videos

See all

Related articles

See all