24 Sep
|
NexGen Tech Solutions
|
Bengaluru
24 Sep
NexGen Tech Solutions
Bengaluru
Position: Azure Infra Engineer
Location – Bangalore
What you'll do
- Design and maintain Azure infrastructure as code (Terraform and/or Bicep) across multiple environments, including module structure, state management, and CI/CD pipelines for infrastructure changes.
- Design and operate Azure networking: hub-spoke topologies, VNet peering, NSGs/ASGs, route tables, Private Link/Private Endpoints, DNS, and hybrid connectivity (ExpressRoute/VPN Gateway).
- Own the edge and WAF layer for public-facing services using Azure Front Door — routing, origin health, caching, and WAF policy tuning (detection vs. prevention rollout, custom and managed rule sets).
- Build security into the infrastructure itself: least-privilege RBAC, Managed Identity over static credentials, Azure Policy guardrails, and network-level isolation for anything holding sensitive data.
- Troubleshoot production networking and connectivity issues — from a Front Door 502 to a broken Private Endpoint DNS resolution — methodically and under time pressure.
- Partner with application and security teams on design reviews, translating requirements into concrete, reviewable infrastructure changes.
- Improve how the team works: catching configuration drift, reducing copy-pasted infrastructure in favor of shared modules, and raising the bar on what gets automated versus done by hand in the portal.
What you'll need
- 5–6+ years in an infrastructure/platform/DevOps engineering role, with much of that time on Microsoft Azure specifically.
- Production experience with Terraform, Bicep, or ARM — including state management, module design, and running infrastructure changes through CI/CD (not just applying from a laptop).
- Solid,
hands-on Azure networking experience: VNets and subnetting, NSGs, route tables/UDRs, VNet peering and hub-spoke design, Private Link/Private Endpoints, and Azure DNS — able to explain why a topology is shaped the way it is, not just draw it.
- Direct experience configuring and operating Azure Front Door (or comparable global edge/CDN + WAF platform) for a production, public-facing service — routing rules, origin health, and WAF policy tuning.
- Strong security fundamentals in an Azure context: RBAC vs.
Azure
Policy, Managed Identity, Key Vault, and designing network isolation for sensitive workloads.
- A track record of owning production incidents involving networking or security misconfiguration — comfortable being the person diagnosing the issue, not just the one who gets paged.
- Clear written and verbal communication — you'll be documenting designs and explaining trade-offs to both engineers and non-infrastructure stakeholders.
Nice to have
- Azure certifications such as AZ-700 (Networking), AZ-500 (Security), or AZ-104/AZ-305.
- Experience with Azure Virtual WAN, Azure Firewall, or DDoS Protection at scale (multiple regions or a large hub-spoke estate).
- Exposure to compliance-driven environments (SOC 2, PCI-DSS, HIPAA, or similar) and translating those requirements into concrete network/security controls.
- Scripting ability (PowerShell, Python, or Go) for tooling, drift-detection automation, or custom Terraform providers/modules.
- Experience with a second major cloud (AWS/GCP) — not required, but practical shorthand for how well networking/security concepts transfer across providers.
- Prior experience mentoring or reviewing IaC changes from less experienced engineers.
📌 Azure Infra Engineer (Bengaluru)
🏢 NexGen Tech Solutions
📍 Bengaluru