- Implement Azure Landing Zones following Microsoft CAF (Cloud Adoption Framework) and WAF (Well Architected Framework) best practices Defne and enforce Management Group hierarchy subscription design and governance policies using Azure Policy and Blueprints Design hub spoke or Virtual WAN topologies with ExpressRoute or VPN gateway integration
- Establish identity and access management strategy using Azure Active Directory PIM RBAC and Conditional Access policies Implement network segmentation NSGs Azure Firewall Private Endpoints UDRs and DNS architecture Drive adoption of enterprise grade security controls Microsoft Defender for Cloud Sentinel integration and security baselines (CIS NIST) Terraform Infrastructure as Code Write maintain and review production grade Terraform modules for all Azure Landing Zone components Develop reusable composable
- Terraform modules with explicit interfaces variable validation and semantic versioning Manage remote state in Azure Blob Storage with state locking and workspace strategies for multi environment deployments Implement Terraform testing frameworks (Terratest checkov tfsec) for policy as code compliance Define and maintain provider version constraints dependency graphs and upgrade runbooks CI or CD & Automation Build and maintain GitOps based CI or CD pipelines (Azure DevOps or GitHub Actions) for automated Landing Zone provisioning Implement pipeline stages for plan policy validation security scanning and apply with drift detection Automate compliance enforcement using Azure Policy initiatives and custom policy definitions in Terraform Develop operational runbooks and self service automation for common platform tasks Platform Engineering & Reliability
- Establish observability stack Azure Monitor Log Analytics Application Insights and alerting frameworks Design and implement cost governance guardrails budgets tagging policies and resource lifecycle management Lead disaster recovery design backup strategies and cross region failover planning Collaborate with security compliance and product teams to translate requirements into platform controls Mentor junior engineers and conduct architecture or code reviews across the team
REQUIRED QUALIFICATIONS
- 7+ years of hands on DevOps or Cloud Infrastructure engineering experience 3+ years designing and implementing Azure Landing Zones at enterprise scale Expert level Terraform skills modules workspaces backends providers and testing Strong understanding of Azure networking VNet NSG Azure Firewall Private Link DNS ExpressRoute Proficiency in Azure governance services Management Groups Azure Policy Blueprints and RBAC Experience with CI or CD platforms Azure DevOps Pipelines and or or GitHub Actions Scripting proficiency in Python PowerShell and or or Bash for automation tasks Deep knowledge of identity management Azure AD Service Principals Managed Identities PIM Strong security mindset with experience implementing CSPM SIEM or SOC integrations (Defender for Cloud Sentinel) Familiarity with container platforms AKS Azure Container Apps or equivalent NICE TO HAVE Experience with Azure Landing Zone Accelerator or Enterprise Scale reference implementations Knowledge of Bicep or ARM templates as a complement to Terraform Experience with policy as code tools OPA or Gatekeeper Checkov or Azure Policy as Code workflows Exposure to FinOps practices and tooling (Azure Cost Management Apptio Cloudability) Contributions to open source Terraform modules or Azure community projects Experience with multi cloud environments (AWS GCP) and cloud agnostic tooling Background in regulated industries banking healthcare or government cloud deployments