Role Overview
We are looking for a Senior Cloud Infrastructure Engineer to design, build, automate, and maintain secure and reliable cloud infrastructure on Microsoft Azure. The role has a strong focus on Infrastructure as Code and Terraform-driven automation across multiple environments.
The engineer will act as a hands-on Terraform subject matter expert, translating infrastructure requirements into reusable, scalable, and supportable automation. This is an individual contributor role for a strong cloud and automation practitioner who is comfortable executing complex infrastructure changes, improving engineering standards, and reducing manual operational effort.
Key Responsibilities
· Design, build, and maintain Infrastructure as Code using Terraform across multiple Azure environments.
· Serve as a Terraform subject matter expert for module design, code quality, reusable patterns, state management, and infrastructure automation practices.
· Develop and enhance reusable Terraform modules, templates, and automation frameworks to standardize cloud provisioning.
· Automate provisioning, deployment, configuration, and operational workflows to reduce manual effort and improve consistency.
· Manage and support Azure cloud infrastructure, including networking, identity, security, subscriptions, and shared platform services.
· Build and automate CI/CD pipelines using Azure DevOps and/or GitLab for infrastructure deployment and validation.
· Implement secure-by-default infrastructure patterns and embed validation, policy, and quality checks into automation workflows.
· Troubleshoot complex Azure and Terraform issues across development, pre-production, and production environments.
· Implement monitoring, alerting, and operational controls to support reliable cloud services.
· Partner with cloud, security, platform, and application teams to translate technical requirements into automated infrastructure solutions.
· Contribute to continuous improvement of cloud engineering standards, documentation, and operational processes.
· Participate in Agile delivery and support production readiness, change implementation, and operational support activities.
· Design Azure network topology using a hub-and-spoke model, with shared platform services centralized in the hub, workload-specific spokes, and swimlane-based setting segregation.
· Define and enforce CIS benchmark-aligned security baselines and policies for Azure infrastructure hardening and compliance.
· Configure and manage VPN Gateway connectivity (Point-to-Site, Site-to-Site, and VNet-to-VNet),
including subnet sizing and IP address range planning for hybrid network architectures.
· Configure Azure Bastion and other secure remote access mechanisms for infrastructure administration, and define VM-level and resource-level IAM/RBAC role assignments.
· Configure and manage service connections and managed identities (system-assigned and user-assigned) for secure authentication between CI/CD pipelines and Azure resources.
· Apply Terraform security best practices, including secure handling of sensitive variables, outputs, and state files, and remediate infrastructure vulnerabilities identified during provisioning.
· Configure and support networking for containerized workloads on Azure Kubernetes Service (AKS), integrated with the broader Azure network topology.
Technical Focus
· Microsoft Azure cloud infrastructure and platform services
· Terraform and Infrastructure as Code (IaC)
· Terraform modules, reusable patterns, remote state, workspaces, and lifecycle management
· Azure DevOps and GitLab CI/CD pipelines
· Infrastructure provisioning and operational automation
· Azure networking, identity, security, and subscription management
· Scripting and automation using Python, Bash, and PowerShell
· Monitoring, alerting, and reliability practices
· Version control and collaborative engineering workflows
· Hub-and-spoke network architecture and swimlane-based environment design
· CIS benchmark alignment and security policy definition for infrastructure hardening
· VPN Gateway connectivity (P2S, S2S, VNet-to-VNet) and subnet/IP address planning
· Managed identities (system-assigned and user-assigned), service connections, and VM/resource-specific IAM roles
· Azure Bastion and secure administrative access
· Terraform security practices, including sensitive data handling and state file protection
· Container orchestration (AKS) networking
Experience & Required Qualifications
· 7–9+ years of overall experience in Cloud Engineering, DevOps, Infrastructure Engineering, Platform Engineering, or related technical roles.
· Strong hands-on Microsoft Azure experience in enterprise environments.
· Deep practical expertise with Terraform,
including design and implementation of reusable modules and automation patterns.
· Proven track record of automating cloud infrastructure provisioning and operational processes.
· Hands-on experience building and maintaining CI/CD pipelines using Azure DevOps and/or GitLab.
· Strong scripting proficiency in Python, Bash, and/or PowerShell.
· Solid understanding of cloud networking, identity, security, and operational reliability.
· Experience troubleshooting infrastructure and automation issues in large-scale environments.
· Ability to work as a senior individual contributor with strong ownership and hands-on execution.
· Practical experience designing hub-and-spoke Azure network architectures, including shared services in the hub, workload isolation across spokes, and swimlane-based environment segregation.
· Working knowledge of CIS benchmarks and experience defining security policies for cloud infrastructure hardening and compliance.
· Hands-on experience configuring VPN Gateway connectivity (Point-to-Site, Site-to-Site, and VNet-to-VNet) and subnet/IP address planning for hybrid network architectures.
· Strong understanding of Azure IAM, including RBAC, system-assigned and user-assigned managed identities, service connections, and VM/resource-specific role assignments.
· Experience with Azure Bastion and other secure administrative access patterns.
· Understanding of Terraform security considerations, including sensitive variable and state file handling, and experience identifying and remediating common cloud infrastructure vulnerabilities.
· Familiarity with container orchestration platforms (e.g., AKS) and associated networking configuration.
Preferred Qualifications
· Terraform Associate certification.
· Microsoft Azure certifications such as Azure Administrator, Azure Solutions Architect, or AZ-400.
· Experience creating and governing enterprise Terraform standards and reusable module libraries.
· Experience with policy-as-code, automated validation, or secure cloud provisioning practices.
· Experience working in large enterprise or regulated environments.
Key Competencies
· Strong hands-on engineering and automation mindset
· Deep problem-solving and troubleshooting capability
· Ownership-driven approach with attention to quality and reliability
· Ability to convert infrastructure requirements into scalable automation
· Clear communication and effective cross-team collaboration
· Self-starter with a continuous improvement mindset
📌 Senior Cloud Infrastructure Engineer (Terraform) (Pune)
🏢 NewVison
📍 Pune