Azure Cloud Engineer
Summary
Design, implement, secure, and automate enterprise Microsoft Azure environments including AVD, cloud migrations, and DevOps automation using Terraform, Bicep, ARM templates, and Azure DevOps at a home-services company.
Company Name
ARS-Rescue RooterOverview
The Azure Cloud Engineer designs, implements, secures, automates, and supports enterprise Microsoft Azure environments, including cloud infrastructure, Azure Virtual Desktop (AVD), cloud migrations, and DevOps automation using CI/CD and Infrastructure-as-Code (IaC). The role delivers secure, scalable, resilient hybrid-cloud solutions and partners across Infrastructure, Security, Networking, Database, and Application Development teams on Zero Trust, PCI DSS compliance, SQL/data-platform migrations, and application modernization.
Responsibilities
Key Responsibilities
Cloud Architecture & Azure Virtual Desktop
- Design, deploy, maintain, and optimize secure, highly available Azure IaaS environments, including VMs, storage, backup, monitoring, recovery, landing zones, governance, and operational baselines.
- Design and administer AVD environments, including host pools, session hosts, images, application delivery, scaling, user experience, and FSLogix.
- Secure and automate AVD using Entra ID, Conditional Access, MFA, RBAC, Zero Trust, Terraform, PowerShell, Azure CLI, and Azure DevOps.
Cloud Migration, DevOps & Automation
- Plan and execute on-premises infrastructure and application migrations to Azure, including readiness assessments, modernization, re-platforming, remediation, and hybrid transition support.
- Design and maintain Azure DevOps CI/CD pipelines and IaC using Terraform, Bicep, ARM templates, PowerShell, Azure CLI, and YAML.
- Establish version control, release management, automated validation, repeatable deployment standards, and technical/operational documentation.
- Partner with database teams on Azure infrastructure for SQL Server Always On to Azure SQL Managed Instance and SQL Server to Cosmos DB migrations, including networking, sizing/capacity, backup/recovery, monitoring, and cutover support.
- Support modernization of IIS-hosted applications through containerization, CI/CD, and deployment to Kubernetes/AKS in partnership with application development teams.
Identity, Networking & Security
- Administer Entra ID, Conditional Access, Identity Governance, PIM, RBAC, MFA, access reviews, service identities, and segregation-of-duties controls.
- Design and enforce Zero Trust, least-privilege access, segmentation, and micro segmentation across Azure environments.
- Design and support hybrid connectivity and application delivery using ExpressRoute, VPN Gateway, Virtual WAN, VNets, routing, DNS, Azure Firewall, Front Door, Application Gateway, load balancing, NSGs, ASGs, and private endpoints.
- Partner with network teams to integrate Azure with datacenter, branch, and third-party connectivity.
Compliance, Governance & Operations
- Support Microsoft Defender for Cloud, Microsoft Sentinel, logging, alerting, threat detection, vulnerability remediation, and cloud security monitoring.
- Design and maintain solutions supporting PCI DSS and enterprise security requirements, including access control, encryption, segmentation, monitoring, vulnerability management, and audit evidence.
- Partner with Security, Compliance, and Audit teams on PCI assessments, remediation, evidence collection, and control validation; align practices with PCI DSS, NIST, CIS Controls, and CIS Azure Benchmarks.
- Monitor and optimize Azure performance, availability, resiliency, cost, and security posture.
- Develop platform standards, operational procedures, runbooks, implementation plans, and support documentation.
- Participate in incident response, problem management, root cause analysis, maintenance, and change management while providing technical guidance across technology teams.
Work Details
- Regular business hours with occasional after-hours maintenance, migrations, incidents, or production changes.
- Participation in change management, operational support, and on-call activities as required.
- Occasional travel for meetings, datacenter activities, vendor engagements, or project work.
Qualifications
Required Qualifications
- Bachelor’s degree in IT, Computer Science, Engineering, or related field; equivalent professional experience considered.
- 5+ years of enterprise infrastructure engineering experience, including 3+ years of hands-on Microsoft Azure engineering.
- Hands-on experience with Azure infrastructure, AVD, cloud migrations, hybrid networking, IaC/automation, identity/access management, and cloud security.
- Experience supporting regulated environments using PCI DSS, NIST, CIS, or similar frameworks.
- Working knowledge of SQL Server/Azure SQL Managed Instance, containerization/Kubernetes/AKS, and Azure Cosmos DB.
Technical Skills
- Cloud: Azure IaaS, Landing Zones, VMs, Storage, Backup, Site Recovery, Monitor, AVD, FSLogix, image management, capacity/scaling.
- Identity: Entra ID, Conditional Access, PIM, Identity Governance, RBAC, MFA, SSO, least privilege.
- DevOps: Azure DevOps, CI/CD, Terraform, Bicep, ARM, Git/GitHub, PowerShell, Azure CLI, YAML.
- Network/Security: ExpressRoute, Front Door, Application Gateway, Azure Firewall, Virtual WAN, VPN Gateway, NSGs, ASGs, routing, micro segmentation, Zero Trust.
- Compliance: PCI DSS, NIST, CIS Controls/Benchmarks, policy management, audit evidence, risk assessment, remediation.
- Migration & Modernization: SQL Server Always On Availability Groups, Azure SQL Managed Instance, Docker, Kubernetes/AKS, Azure Cosmos DB.
Preferred Qualifications
- Microsoft Azure Solutions Architect Expert, Azure Security Engineer Associate, Azure Administrator Associate, Azure DevOps Engineer Expert, and/or HashiCorp Terraform Associate certifications preferred.
- Experience with PCI DSS environments and audit evidence; Defender for Cloud, Sentinel, CrowdStrike or similar security platforms; and multi-site hybrid data center/cloud environments also preferred.
- Prior exposure to SQL Server or Cosmos DB migrations, or to containerizing legacy .NET/IIS applications, is a plus.