Featured Job

Staff Azure Cloud Engineer, Automation

Full-time Hybrid 09/02/2026 Job ID: 000078
Apply Now
Azure Terraform Terraform Cloud Azure Verified Modules GitHub Actions

Summary

What you’ll impact

The role is a Lead/Staff Azure Cloud Engineer responsible for designing and building an Azure landing zone and associated automation for a multi-year cloud modernization program. The engineer will own Terraform Cloud setup, networking, security, CI/CD pipelines, policy-as-code, and establish self‑service deployment patterns while collaborating with internal IT, security, and network teams.

Responsibilities

What you'll do

  • We need a Lead Azure Cloud Engineer who can walk in, take design ownership, and start building in week one.
  • This is a hands-on, individual-contributor role: you will write the code yourself, stand up the pipelines yourself, and set the technical bar the rest of the teams build against.
  • You are the senior-most and dedicated cloud engineering voice on this program.
  • You need to be well-rounded: as comfortable troubleshooting a firewall rule or a network route as you are writing a Terraform module or designing the pipeline that deploys it.
  • You will need to work with the firm's existing IT, security, and network teams to land on shared standards, and then you're the one who codifies them into automation.
  • Design and build the Azure landing zone, aligned to Microsoft's Cloud Adoption Framework design areas (identity, network topology, resource organization, governance, management, security) and reviewed against the Well-Architected Framework's five pillars at each milestone.
  • Build with Azure Verified Modules (AVM) as the base layer, composing right-sized custom Terraform modules on top rather than hand-rolling every resource or adopting the full CAF Enterprise-Scale module wholesale.
  • Own the Terraform Cloud (TFC) setup end to end: workspace structure (one state file per workload per environment), variable sets, run triggers, and remote state strategy.
  • Own hands-on networking and firewall configuration: hub-spoke topology, NSGs, Azure Firewall, WAF rules, private endpoints, and DNS. There is no separate network architect on this program; you need to be able to design, configure, and troubleshoot these yourself, informed by the firm's existing network/security teams.
  • Work with internal teams to define our to-be cloud native software engineering practice and process, then codify it. Coding standards, module and repo conventions, branching and review workflow, policy-as-code approach, and the shift-left tooling chain (scanning, testing, gating) are not yet decided. You will work with the firm's existing security and engineering teams to land on a standard, and then turns that into working Terraform, pipelines, and documentation.
  • Establish policy-as-code guardrails (approach and tooling still to be decided, e.g. HashiCorp Sentinel, OPA, or another option you recommend and help evaluate) so that governance is enforced automatically on every plan
  • Build the CI/CD pipeline for infrastructure changes: automatic plan on every pull request, mandatory human review, manual apply gate
  • Help stand up our shift-left scanning practice: the goal is that IaC, code, and dependency issues are caught early in the engineering cycle.
  • Set up the security and observability baseline: Microsoft Defender for Cloud, centralized Log Analytics, Azure Policy at the management-group scope, hub-spoke network segmentation, and private endpoints.
  • Coordinate with the firm's identity/security and network teams on Entra ID architecture (app registrations, Conditional Access, PIM) and network/firewall standards.
  • Set the technical example for module structure, versioning, documentation, and code review standards that future hires on this program will follow as the team grows.
  • Extend the paved path from infrastructure to application delivery. Define a golden, self-service deployment pattern so Backend and Frontend engineers can ship application code onto the landing zone without hand-rolling their own pipelines.

Requirements

What you’ll bring

  • 6+ years in cloud infrastructure/platform engineering, with real production ownership, not just POCs.
  • A well-rounded Azure Cloud generalist, comfortable across Terraform/IaC, Azure networking, and firewalls/network security,
  • Deep, hands-on Terraform experience: module authorship, remote state, workspace/environment strategy, version pinning, and awareness of the tradeoffs in monorepo vs. per-module repo structures.
  • Strong, hands-on Azure networking and security: hub-spoke topology, NSGs, Azure Firewall, WAF rules, private endpoints, DNS, and hybrid/legacy connectivity patterns, plus identity (Entra ID, RBAC, managed identity) and governance (management groups, Azure Policy).
  • Working knowledge of SOC 2 control families (access control, change management, logging/monitoring, network security) well enough to design a landing zone that satisfies them by default, even without prior formal audit experience.
  • Able to work effectively with the firm's existing security, network, and IT teams
  • Direct experience building CI/CD pipelines for infrastructure changes (GitHub Actions, Azure DevOps, or equivalent), including plan/apply gating patterns.
  • Working knowledge of policy-as-code approaches (e.g. Sentinel, OPA) and IaC/security scanning practices.
  • Comfortable being the first cloud engineer on the program: able to make and defend decisions yourself.
  • Strong scripting ability (PowerShell, Bash, or Python) for tooling and automation glue.
  • Comfortable defining a self-service application deployment pattern (a “golden path”) that other engineers can use to ship application code without needing deep Terraform expertise themselves.
  • Direct experience with Terraform Cloud/Enterprise specifically (not just open-source Terraform CLI).
  • Prior experience building a landing zone from zero, versus inheriting and extending one.
  • Experience consuming (or ideally contributing to) Azure Verified Modules.
  • Direct experience operating in a compliance-driven environment (SOC 2, HIPAA, or similar) through an actual audit cycle, where controls needed to be demonstrable, not just implemented.
  • Experience mentoring other infrastructure/platform engineers.
  • Experience with HashiCorp HCP Waypoint, or a similar internal developer platform (IDP) approach, for standardizing self-service application deployment.
  • HashiCorp Terraform Associate or Professional certification.
  • Microsoft certifications: AZ-305 (Solutions Architect) and/or AZ-400 (DevOps Engineer); AZ-500 (Security) is a plus.

Ready to Move Forward?

Apply now and our recruiting team will reach out with next steps, interview guidance, and client insights tailored to this role.