30 days ago
Denver, CO, USAStaff+
Base Salary
$140k - $185k/yr
Responsibilities
- Design and build an Azure landing zone aligned with the Cloud Adoption Framework and Well-Architected Framework.
- Develop Terraform modules using Azure Verified Modules and own Terraform Cloud workspaces, variable sets, triggers, and remote state.
- Design, configure, and troubleshoot hub-spoke networking, NSGs, Azure Firewall, WAF rules, private endpoints, DNS, and hybrid connectivity.
- Define and codify cloud-native engineering standards, repository conventions, review workflows, policy-as-code, scanning, testing, and gating practices.
- Build infrastructure CI/CD pipelines with pull-request planning, human review, and manual apply gates.
- Establish Azure security and observability baselines using Microsoft Defender for Cloud, Azure Policy, and centralized Log Analytics.
- Coordinate Entra ID, identity, security, network, and firewall standards with internal teams.
- Create self-service application deployment patterns and golden paths for Backend and Frontend engineers.
- Set technical standards for module structure, versioning, documentation, and code reviews while mentoring future infrastructure and platform engineers.
Requirements
- 6+ years of cloud infrastructure or platform engineering experience with production ownership.
- Strong Azure cloud generalist experience across Terraform/IaC, networking, firewalls, identity, security, and governance.
- Deep hands-on Terraform experience including module authorship, remote state, workspace and environment strategy, version pinning, and repository-structure tradeoffs.
- Hands-on experience with Azure networking and security, including hub-spoke topology, NSGs, Azure Firewall, WAF rules, private endpoints, DNS, Entra ID, RBAC, managed identity, management groups, and Azure Policy.
- Working knowledge of SOC 2 control families and designing landing zones that support demonstrable controls.
- Experience building infrastructure CI/CD pipelines with GitHub Actions, Azure DevOps, or an equivalent tool, including plan/apply gating.
- Working knowledge of policy-as-code approaches such as Sentinel or OPA and infrastructure-as-code and security scanning practices.
- Strong scripting ability with PowerShell, Bash, or Python.
- Ability to independently make and defend technical decisions as the first cloud engineer on the program.
- Ability to define self-service application deployment patterns for engineers with limited Terraform expertise.
- Preferred: Terraform Cloud or Terraform Enterprise experience, greenfield landing-zone experience, Azure Verified Modules experience, compliance-driven audit-cycle experience, infrastructure/platform mentoring experience, and HashiCorp HCP Waypoint or similar internal developer platform experience.
- Preferred certifications include HashiCorp Terraform Associate or Professional and Microsoft AZ-305, AZ-400, or AZ-500 certifications.
Benefits
- Hybrid work model with eligible employees working remotely and in the office based on business needs and team coordination; the arrangement is subject to change.
- The employer provides a variety of benefits and perks supporting a healthy work environment.
- The role offers training, professional growth opportunities, and exposure to diverse and intellectually stimulating work.
