Job Purpose:
The role is responsible for designing, implementing, and operating secure and scalable Azure cloud infrastructure supporting enterprise platforms and AI workloads. The position follows an end-to-end engineering approach, covering infrastructure-as-code, deployment automation, validation, and ongoing operations, while ensuring platform reliability, security, and continuous improvement.
Job Accountabilities:
Build the landing zone: design and deliver spoke networks, firewall policy, private DNS, ingress (App Gateway/WAF), and shared platform services in Bicep, deployed through Azure DevOps pipelines with deployment stacks and evidence gates.
Execute migrations: plan and run application migration waves — fresh-build targets, SQL Server database moves (backup/restore, log shipping, AlwaysOn AGs on Azure VMs), file-share and data transfers over controlled paths, cutovers with parallel-run and rollback plans.
Engineer identity and access: Entra ID authentication (SSO/SAML for onboarded entities), PIM based just-in-time access models, managed identities everywhere, entitlement management as code.
Keep it observable and operable: diagnostic settings, Log Analytics, Grafana dashboards, alert rules, smoke-test pipelines, and operational runbooks as part of every deliverable — not as an afterthought.
Hold the security line: private-endpoints-only PaaS, forced-tunnel egress through central firewall, zero-trust access from managed Cloud PCs, Azure Policy guardrails — and the discipline to work within them (and improve them) rather than around them.
Operate what you build: triage platform incidents using firewall logs, KQL, and activity logs; participate in change reviews; document designs and procedures in the team's standards structure.
Job Specification:
7+ years in infrastructure or platform engineering, with 3+ years hands on Azure at enterprise scale.
Infrastructure as code as your default working mode — Bicep strongly preferred (Terraform acceptable), Git branching/PR workflows, Azure DevOps or GitHub pipelines. You should be uncomfortable making portal changes.
Deep Azure networking: hub-and-spoke, Azure Firewall rules and policy, UDRs, private endpoints and Private DNS, VPN/ExpressRoute, Application Gateway/WAF.
Identity engineering: Entra ID, SAML/OIDC federation, PIM, RBAC design, managed identities, Microsoft Graph scripting.
Scripting fluency: PowerShell required; Python a plus. Comfortable with REST APIs when the CLI falls short.
Migration experience: at least one substantial datacenter-to-cloud or tenant-to-tenant migration programme, including database moves and cutover planning.
Working SQL Server knowledge (senior roles): backup/restore mechanics, authentication models, availability groups — enough to move and stand up databases confidently, not DBA depth.
Clear written communication: PR descriptions, design docs, and runbooks are first-class deliverables in this team.