Summary
What you’ll impact
The role is a Lead/Staff Azure Cloud Engineer responsible for designing and building an Azure landing zone and associated automation for a multi-year cloud modernization program. The engineer will own Terraform Cloud setup, networking, security, CI/CD pipelines, policy-as-code, and establish self‑service deployment patterns while collaborating with internal IT, security, and network teams.
Responsibilities
What you'll do
- We need a Lead Azure Cloud Engineer who can walk in, take design ownership, and start building in week one.
- This is a hands-on, individual-contributor role: you will write the code yourself, stand up the pipelines yourself, and set the technical bar the rest of the teams build against.
- You are the senior-most and dedicated cloud engineering voice on this program.
- You need to be well-rounded: as comfortable troubleshooting a firewall rule or a network route as you are writing a Terraform module or designing the pipeline that deploys it.
- You will need to work with the firm's existing IT, security, and network teams to land on shared standards, and then you're the one who codifies them into automation.
- Design and build the Azure landing zone, aligned to Microsoft's Cloud Adoption Framework design areas (identity, network topology, resource organization, governance, management, security) and reviewed against the Well-Architected Framework's five pillars at each milestone.
- Build with Azure Verified Modules (AVM) as the base layer, composing right-sized custom Terraform modules on top rather than hand-rolling every resource or adopting the full CAF Enterprise-Scale module wholesale.
- Own the Terraform Cloud (TFC) setup end to end: workspace structure (one state file per workload per environment), variable sets, run triggers, and remote state strategy.
- Own hands-on networking and firewall configuration: hub-spoke topology, NSGs, Azure Firewall, WAF rules, private endpoints, and DNS. There is no separate network architect on this program; you need to be able to design, configure, and troubleshoot these yourself, informed by the firm's existing network/security teams.
- Work with internal teams to define our to-be cloud native software engineering practice and process, then codify it. Coding standards, module and repo conventions, branching and review workflow, policy-as-code approach, and the shift-left tooling chain (scanning, testing, gating) are not yet decided. You will work with the firm's existing security and engineering teams to land on a standard, and then turns that into working Terraform, pipelines, and documentation.
- Establish policy-as-code guardrails (approach and tooling still to be decided, e.g. HashiCorp Sentinel, OPA, or another option you recommend and help evaluate) so that governance is enforced automatically on every plan
- Build the CI/CD pipeline for infrastructure changes: automatic plan on every pull request, mandatory human review, manual apply gate
- Help stand up our shift-left scanning practice: the goal is that IaC, code, and dependency issues are caught early in the engineering cycle.
- Set up the security and observability baseline: Microsoft Defender for Cloud, centralized Log Analytics, Azure Policy at the management-group scope, hub-spoke network segmentation, and private endpoints.
- Coordinate with the firm's identity/security and network teams on Entra ID architecture (app registrations, Conditional Access, PIM) and network/firewall standards.
- Set the technical example for module structure, versioning, documentation, and code review standards that future hires on this program will follow as the team grows.
- Extend the paved path from infrastructure to application delivery. Define a golden, self-service deployment pattern so Backend and Frontend engineers can ship application code onto the landing zone without hand-rolling their own pipelines.
Requirements
What you’ll bring
- 6+ years in cloud infrastructure/platform engineering, with real production ownership, not just POCs.
- A well-rounded Azure Cloud generalist, comfortable across Terraform/IaC, Azure networking, and firewalls/network security,
- Deep, hands-on Terraform experience: module authorship, remote state, workspace/environment strategy, version pinning, and awareness of the tradeoffs in monorepo vs. per-module repo structures.
- Strong, hands-on Azure networking and security: hub-spoke topology, NSGs, Azure Firewall, WAF rules, private endpoints, DNS, and hybrid/legacy connectivity patterns, plus identity (Entra ID, RBAC, managed identity) and governance (management groups, Azure Policy).
- Working knowledge of SOC 2 control families (access control, change management, logging/monitoring, network security) well enough to design a landing zone that satisfies them by default, even without prior formal audit experience.
- Able to work effectively with the firm's existing security, network, and IT teams
- Direct experience building CI/CD pipelines for infrastructure changes (GitHub Actions, Azure DevOps, or equivalent), including plan/apply gating patterns.
- Working knowledge of policy-as-code approaches (e.g. Sentinel, OPA) and IaC/security scanning practices.
- Comfortable being the first cloud engineer on the program: able to make and defend decisions yourself.
- Strong scripting ability (PowerShell, Bash, or Python) for tooling and automation glue.
- Comfortable defining a self-service application deployment pattern (a “golden path”) that other engineers can use to ship application code without needing deep Terraform expertise themselves.
- Direct experience with Terraform Cloud/Enterprise specifically (not just open-source Terraform CLI).
- Prior experience building a landing zone from zero, versus inheriting and extending one.
- Experience consuming (or ideally contributing to) Azure Verified Modules.
- Direct experience operating in a compliance-driven environment (SOC 2, HIPAA, or similar) through an actual audit cycle, where controls needed to be demonstrable, not just implemented.
- Experience mentoring other infrastructure/platform engineers.
- Experience with HashiCorp HCP Waypoint, or a similar internal developer platform (IDP) approach, for standardizing self-service application deployment.
- HashiCorp Terraform Associate or Professional certification.
- Microsoft certifications: AZ-305 (Solutions Architect) and/or AZ-400 (DevOps Engineer); AZ-500 (Security) is a plus.