30 days ago
Fort Worth, TX, USAStaff+
Responsibilities
- Design and build an Azure landing zone aligned with the Cloud Adoption Framework and Well-Architected Framework.
- Develop Azure Verified Module-based infrastructure and custom Terraform modules.
- Own Terraform Cloud workspaces, variable sets, run triggers, and remote state strategy.
- Design, configure, and troubleshoot hub-spoke networking, NSGs, Azure Firewall, WAF rules, private endpoints, DNS, and related connectivity.
- Define and codify cloud-native engineering standards, repository conventions, review workflows, policy-as-code practices, and scanning and testing gates.
- Establish policy-as-code guardrails and evaluate tools such as Sentinel and OPA.
- Build infrastructure CI/CD pipelines with pull-request planning, human review, and gated applies.
- Implement security and observability baselines using Microsoft Defender for Cloud, Log Analytics, Azure Policy, and network segmentation.
- Coordinate with identity, security, network, and IT teams on Entra ID, Conditional Access, PIM, and network standards.
- Define a self-service application deployment or golden-path pattern for backend and frontend engineers.
- Set technical standards for module structure, versioning, documentation, and code review.
- Use PowerShell, Bash, or Python for tooling and automation.
Requirements
- 6+ years of cloud infrastructure or platform engineering experience with production ownership.
- Strong Azure cloud infrastructure, networking, firewall, identity, security, and governance experience.
- Deep hands-on Terraform experience, including module authorship, remote state, workspace and environment strategy, and version pinning.
- Experience with hub-spoke topology, NSGs, Azure Firewall, WAF rules, private endpoints, DNS, hybrid connectivity, Entra ID, RBAC, managed identities, management groups, and Azure Policy.
- Working knowledge of SOC 2 control families and designing compliant cloud landing zones.
- Experience building infrastructure CI/CD pipelines with GitHub Actions, Azure DevOps, or an equivalent tool.
- Working knowledge of policy-as-code and infrastructure or security scanning practices.
- Ability to independently make and defend technical decisions as the first cloud engineer on the program.
- Strong scripting ability in PowerShell, Bash, or Python.
- Experience defining self-service application deployment patterns for other engineers.
- Preferred: Terraform Cloud or Enterprise experience, landing-zone-from-zero experience, Azure Verified Modules experience, compliance or audit-cycle experience, infrastructure/platform mentoring experience, and HashiCorp HCP Waypoint or similar internal developer platform experience.
- Preferred certifications include Terraform Associate or Professional and Microsoft AZ-305, AZ-400, or AZ-500.
Benefits
- Hybrid work model with eligible employees working remotely and in the office based on business needs and team coordination; the arrangement is subject to change.
- HCVT provides a variety of benefits and perks supporting a healthy work environment.
- Training investments and opportunities for professional growth are provided.
