HCVT

Staff Azure Cloud Engineer, Automation

HCVT
Apply
30 days ago
Phoenix, AZ, USAStaff+

Responsibilities

  • Design and build an Azure landing zone aligned with the Cloud Adoption Framework and Well-Architected Framework.
  • Create and maintain Azure Verified Module-based Terraform modules and custom infrastructure modules.
  • Own Terraform Cloud workspaces, variable sets, run triggers, remote state, and environment strategy.
  • Design, configure, and troubleshoot hub-spoke networking, NSGs, Azure Firewall, WAF rules, private endpoints, DNS, and hybrid connectivity.
  • Define cloud-native engineering standards, repository and module conventions, branching and review workflows, policy-as-code, scanning, testing, and gating practices.
  • Establish policy-as-code guardrails and build infrastructure CI/CD pipelines with pull-request plans, human review, and controlled apply gates.
  • Implement Microsoft Defender for Cloud, Azure Policy, centralized Log Analytics, network segmentation, and private endpoints.
  • Coordinate Entra ID, identity, security, and network architecture with internal teams.
  • Set technical standards for module structure, versioning, documentation, and code review.
  • Define a self-service golden path for application deployment onto the Azure landing zone.
  • Evaluate and help select policy-as-code, shift-left scanning, and internal developer platform tooling.

Requirements

  • 6+ years of cloud infrastructure or platform engineering experience with production ownership.
  • Hands-on Azure experience across cloud infrastructure, networking, firewalls, identity, security, and governance.
  • Deep Terraform experience including module authorship, remote state, workspace and environment strategy, version pinning, and repository design.
  • Experience with Azure networking and security, including hub-spoke topology, NSGs, Azure Firewall, WAF rules, private endpoints, DNS, Entra ID, RBAC, managed identities, management groups, and Azure Policy.
  • Working knowledge of SOC 2 control families and designing auditable cloud landing zones.
  • Experience building infrastructure CI/CD pipelines with GitHub Actions, Azure DevOps, or an equivalent tool, including plan and apply gating.
  • Working knowledge of Sentinel, OPA, or other policy-as-code and infrastructure/security scanning approaches.
  • Ability to operate as the first cloud engineer on a program and make and defend technical decisions independently.
  • Strong scripting ability with PowerShell, Bash, or Python.
  • Ability to define self-service application deployment patterns for engineers without deep Terraform expertise.
  • Preferred: Terraform Cloud or Enterprise experience, landing-zone construction from zero, Azure Verified Modules experience, compliance-driven audit-cycle experience, mentoring experience, and HashiCorp HCP Waypoint or similar internal developer platform experience.
  • Preferred: HashiCorp Terraform Associate or Professional certification and Microsoft AZ-305, AZ-400, or AZ-500 certifications.

Benefits

  • Hybrid work model with remote and office work based on business needs and team coordination; the arrangement is subject to change.
  • HCVT provides a variety of benefits and perks, with additional details available in its Benefits section.

Tech Stack

AzureBashGitHub ActionsPowerShellPythonTerraform

Categories

HCVT

About HCVT

501-1,000 employees
Contact me