01 Aug
|
Leading
|
Hyderabad
WEâRE HIRING AS A SENIOR CLOUD ENGINEER IN INDIA!
Excis is a global organisation driven by people, innovation and collaboration.
Weâre looking for a hands-on Azure & AWS Cloud Engineer to lead Engineering initiativesâthink greenfield builds, cloud migrations, modernization programs, platform engineering, landing zone setup, and automationâacross enterprise environments. Youâll collaborate with architects, SRE/DevOps, security, and application teams to design, build, automate, and handover robust cloud platforms and workloads, with a heavy focus on Infrastructure as Code (IaC), CI/CD, security by design, and repeatable patterns
Start your journey with Excis and grow with us!
What will you do -
Cloud Platform Build & Landing Zones
- Design and implement multiâaccount/subscription landing zones (AWS Control Tower / Azure Landing Zone), including org hierarchy, account/subscription vending, baseline guardrails, and network segmentation.
- Build shared services (centralized logging, monitoring, DNS, secrets, image galleries/AMIs, patch baselines).
Workload Migrations & Modernization
- Lead rehost/replatform/refactor migrations to Azure and AWS; create migration runbooks, cutover plans, and rollback strategies.
- Containerize apps (Docker), orchestrate with AKS/EKS, implement blue/green or canary deployments.
Infrastructure as Code & Automation
- Author and maintain IaC using Terraform (preferred) and/or Bicep/ARM, CloudFormation.
- Build reusable modules, pipelines, and golden templates; enforce policy as code (Azure Policy, OPA/Conftest).
- Implement CI/CD pipelines (Azure DevOps, GitHub Actions, AWS CodePipeline) for infra and app artifacts.
Networking & Security (Security by Design)
- Design hub-and-spoke/VPC-VPN/Transit Gateway/ExpressRoute/Direct Connect; implement private endpoints and service endpoints.
- Apply identity and access best practices (Azure AD/Entra ID, IAM, roles, SCPs), KMS/Key Vault, secret management, and least privilege.
- Implement guardrails and compliance controls (CIS, NIST, ISO), with drift detection and remediation.
Observability & Reliability
- Configure endâtoâend logging, metrics, traces (CloudWatch, AWS X-Ray, Azure Monitor, Log Analytics, Application Insights).
- Define SLO/SLIs, error budgets, and readiness criteria; conduct performance tests and game days before handover.
Cost, Performance & FinOps
- Rightâsize resources, implement tagging standards, budgets, anomaly detection, and showback/chargeback.
- Provide cost/perf benchmarks and optimization recommendations preâ and postâgoâlive.
Documentation & Handover
- Produce HLD/LLD, runbooks, DR plans, security patterns, and knowledge transfer packages.
- Conduct enablement sessions for operations/BAU teams.
Cloud Automation (Primary Focus)
- Design and implement endâtoâend cloud automation frameworks using Terraform, Bicep/ARM, CloudFormation, PowerShell, Python, and Bash.
- Build reusable Terraform modules, IaC pipelines, guardrail policies, and golden templates for Azure and AWS.
- Automate provisioning of cloud infrastructure, networking, monitoring, cost governance, and storage.
- Implement GitOps-based automation using GitHub Actions, Azure DevOps, Argo CD, or Flux.
- Develop automation for:
- Account/subscription vending
- Network builds (VPC/VNet, TGW, Hubs)
- AKS/EKS cluster deployments
- Policy-as-Code (Azure Policy, SCPs, OPA)
- Secrets rotation and identity automation
- Create automation to support zeroâtouch deployments, selfâservice catalogues, and blueprint-driven cloud adoption.
- 8+ years total IT experience with 5+ years in public cloud engineering across Azure and AWS.
- Demonstrable track record delivering Engineering/nonâBAU initiatives: landing zones, migrations, platform builds, container platforms, or large app modernizations.
- IaC: Strong in Terraform (modules, workspaces, state mgmt), plus Bicep/ARM or CloudFormation.
- CI/CD: Azure DevOps / GitHub Actions / AWS Code* toolchain; artifact mgmt; automated testing gates.
- Compute/Containers: EC2/VMSS, ASG/VMSS, AKS/EKS, Fargate; image registries (ECR/ACR); autoscaling.
- Networking: VNet/VPC design, peering, TGW/VNet Hub, PrivateLink/Private Endpoints, DNS, WAF/ALB/AGW, VPN/ExpressRoute/Direct Connect.
- Security: IAM/RBAC, Azure Policy/SCPs, KMS/Key Vault, secure baselines, secrets mgmt, vulnerability scanning.
- Data & Storage: S3/EBS/FSx/Glacier; Blob/Files/Managed Disks; RDS/Aurora/DynamoDB; Azure SQL/Cosmos DB.
- Observability: CloudWatch, CloudTrail, Azure Monitor/Log Analytics, Prometheus/Grafana; alerting & dashboards.
- Scripting: Python/PowerShell/Bash for automation and tooling.
- Solid documentation, stakeholder communication, and crossâfunctional collaboration skills.