> Markdown version of [/jobs/ext/2005094-staff-azure-cloud-engineer-automation](https://www.wearedevelopers.com/jobs/ext/2005094-staff-azure-cloud-engineer-automation). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff Azure Cloud Engineer, Automation - **Company:** Holthouse Carlin & Van Trigt LLP - **Location:** Denver, CO, United States - **Contract:** Permanent contract - **Skills:** Microsoft Azure, Bash Shell, Cloud Computing, Cloud Engineering, Code Review, Domain Name System (DNS), Python (Programming Language), Log Analysis, Windows PowerShell, Management of Software Versions, Policy as Code, Scripting, Delivery Pipeline, Firewalls (Computer Science), Build Management, Firewall Services Module, Terraform - **Published:** August 9, 2026 - **Apply:** https://us.experteer.com/career/view-jobs/staff-azure-cloud-engineer-automation-denver-co-usa-58861325 ## About the Role Experteer Overview In this role you will lead the design and build of a new Azure landing zone as part of a multi-year cloud modernization program. You work hands-on as an IC, setting the technical bar and coding the automation that others follow. You collaborate with IT, security, and network teams to codify standards, build pipelines, and enable self-service deployment at scale. This is a chance to shape secure, automated infrastructure for a growing firm with a strong focus on excellence. Compensation / Benefits * Design and build the Azure landing zone aligned with CAF and Well-Architected Framework * Develop and compose Terraform modules on AVM; avoid full hand-rolling * Own Terraform Cloud setup: state, variables, run triggers, remote state * Hands-on networking and firewall configuration (hub-spoke, NSGs, Azure Firewall, WAF) * Define and codify to-be cloud-native engineering practices and workflows * Establish policy-as-code guardrails (e.g., Sentinel, OPA) for automatic governance * Build CI/CD pipelines for infrastructure changes with gate and reviews * Set up security and observability baseline (Defender for Cloud, Log Analytics, Azure Policy) * Coordinate Entra ID architecture with security and network teams * Create a golden self-service deployment path for app teams * Define module structure, versioning, and code review standards for future hires * Extend the path from infrastructure to application delivery for faster ship of code Tasks * 6+ years in cloud infrastructure/platform engineering with production ownership * Well-rounded Azure Cloud generalist (Terraform/IaC, networking, security) * Deep, hands-on Terraform experience (modules, remote state, environment strategy) * Strong Azure networking and security experience (hub-spoke, NSGs, Firewall, DNS, private endpoints) * Knowledge of SOC 2 controls relevant to cloud design * Experience building CI/CD pipelines for infrastructure changes * Policy-as-code knowledge (Sentinel, OPA) and IaC aaa Azure scanning * Comfort as the first cloud engineer on a program and independent decision-making * Strong scripting skills (PowerShell, Bash, or Python) * Ability to define a self-service deployment pattern (golden path) for others Key requirements * ## Description Experteer Overview In this role you will lead the design and build of a new Azure landing zone as part of a multi-year cloud modernization program. You work hands-on as an IC, setting the technical bar and coding the automation that others follow. You collaborate with IT, security, and network teams to codify standards, build pipelines, and enable self-service deployment at scale. This is a chance to shape secure, automated infrastructure for a growing firm with a strong focus on excellence. Compensation / Benefits * Design and build the Azure landing zone aligned with CAF and Well-Architected Framework * Develop and compose Terraform modules on AVM; avoid full hand-rolling * Own Terraform Cloud setup: state, variables, run triggers, remote state * Hands-on networking and firewall configuration (hub-spoke, NSGs, Azure Firewall, WAF) * Define and codify to-be cloud-native engineering practices and workflows * Establish policy-as-code guardrails (e.g., Sentinel, OPA) for automatic governance * Build CI/CD pipelines for infrastructure changes with gate and reviews * Set up security and observability baseline (Defender for Cloud, Log Analytics, Azure Policy) * Coordinate Entra ID architecture with security and network teams * Create a golden self-service deployment path for app teams * Define module structure, versioning, and code review standards for future hires * Extend the path from infrastructure to application delivery for faster ship of code Tasks * 6+ years in cloud infrastructure/platform engineering with production ownership * Well-rounded Azure Cloud generalist (Terraform/IaC, networking, security) * Deep, hands-on Terraform experience (modules, remote state, environment strategy) * Strong Azure networking and security experience (hub-spoke, NSGs, Firewall, DNS, private endpoints) * Knowledge of SOC 2 controls relevant to cloud design * Experience building CI/CD pipelines for infrastructure changes * Policy-as-code knowledge (Sentinel, OPA) and IaC security scanning * Comfort as the first cloud engineer on a program and independent decision-making * Strong scripting skills (PowerShell, Bash, or Python) * Ability to define a self-service deployment pattern (golden path) for others Key requirements * ## Related Videos - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Old tools, new tricks](https://www.wearedevelopers.com/videos/1916-old-tools-new-tricks) - [Azure-Well Architected Framework - designing mission critical workloads in practice](https://www.wearedevelopers.com/videos/1529-azure-well-architected-framework-designing-mission-critical-workloads-in-practice) - [Implementing Feature Environments with AWS and Terraform](https://www.wearedevelopers.com/videos/531-implementing-feature-environments-with-aws-and-terraform) - [Terraform for Developers](https://www.wearedevelopers.com/videos/3-terraform-for-developers) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)