Azure Infrastructure Engineer (Bicep/laC)
Summary
Designs and deploys Azure cloud infrastructure using Bicep IaC, focusing on networking, security, governance, and scalability for enterprise workloads.
We are looking for an experienced Azure Infrastructure Engineer with strong expertise in Azure cloud architecture and Infrastructure-as-Code (IaC). The role will focus on designing, provisioning, securing, and governing Azure infrastructure using Bicep as the primary template language for defining and deploying Azure Resource Manager (ARM) resources.
The ideal candidate will have strong hands-on experience with Azure networking, identity, governance, security, high availability, and infrastructure automation, with the ability to translate business and application requirements into scalable and maintainable cloud infrastructure.
Responsibilities
Azure Infrastructure & IaC
Design and develop Bicep templates and reusable modules for Azure infrastructure provisioning.
Provision and manage Azure resources including:
Virtual Machines
App Services
AKS
VNets, Subnets, NSGs
Private Endpoints and VNet Peering
Azure Storage, Blob, Files, and Managed Disks
Azure SQL and Cosmos DB
Maintain a modular and parameterized Bicep template library supporting development, staging, and production environments.
Ensure infrastructure is consistent, scalable, secure, and aligned with enterprise standards.
Azure Networking & Architecture
Design enterprise-grade Azure network architectures, including Hub-and-Spoke VNet models.
Configure and manage:
VNets and Subnets
NSGs and Route Tables
Private Link/Private Endpoints
Azure DNS
VNet Peering
ExpressRoute
VPN Gateway
Design traffic segmentation and secure connectivity across environments and workloads.
Support hybrid and enterprise cloud connectivity requirements.
Identity & Security
Define and implement Azure identity and access controls using Microsoft Entra ID, Azure RBAC, and Managed Identities.
Support Conditional Access and least-privilege access models.
Manage Azure Key Vault for secrets, certificates, and encryption keys.
Ensure infrastructure follows security and compliance best practices.
Azure Governance
Establish and maintain governance using:
Azure Policy
Management Groups
Subscription hierarchy
Resource Groups
Template Specs / governance frameworks
Enforce tagging, cost management, security, and compliance standards.
Support Azure Landing Zone design and subscription management.
High Availability & Disaster Recovery
Design highly available and resilient Azure architectures using Availability Zones and region-pairing strategies.
Define backup, recovery, failover, and disaster recovery approaches.
Support capacity planning and scalability assessments as workloads grow.
Monitoring & Cost Optimization
Configure Azure Monitor and Log Analytics for infrastructure monitoring and visibility.
Define infrastructure-level alerts and operational monitoring.
Monitor and optimize Azure infrastructure costs through:
Resource right-sizing
Reserved Instances / Savings Plans
Resource lifecycle management
Azure Cost Management
Documentation & Collaboration
Create and maintain network diagrams, architecture decision records (ADRs), infrastructure specifications, and operational runbooks.
Work with application, security, DevOps, and architecture teams to translate requirements into infrastructure solutions.
Collaborate with distributed international teams and stakeholders.
Participate in Agile ceremonies while independently owning infrastructure design and delivery.
Required Skills & Experience
3+ years of hands-on experience designing and deploying Azure infrastructure.
Strong hands-on experience with Bicep and ARM JSON for Azure resource provisioning.
Strong understanding of Azure Landing Zones, subscription vending, and resource hierarchy.
Deep knowledge of Azure networking, including:
VNets and Subnets
NSGs
Route Tables
Private Link/Endpoints
DNS
ExpressRoute
VPN Gateway
VNet Peering
Strong knowledge of Microsoft Entra ID, RBAC, Managed Identities, and Key Vault.
Experience with Azure Policy and Management Groups.
Knowledge of Azure Storage services, including LRS, ZRS, and GRS redundancy models.
Experience with Azure SQL and Cosmos DB infrastructure.
Experience configuring Azure Monitor, Log Analytics, and infrastructure alerting.
Strong understanding of cloud security, scalability, availability, and infrastructure governance.
InnoWave gives equal opportunity in employment regardless of gender, gender identity, sexual orientation, marital status, race, nationality, religion, age, disability, political beliefs, or any other factor. InnoWave will not pay fees to any third-party agency or company that does not have a signed agreement, do not submit resumes/CV's directly.
By answering to this job post, you consent the use of your data by InnoWave Group, for as long as necessary. We conduct regular data-cleansing and updating exercises to make sure the information we have is relevant and accurate. If you have any doubt or request to make relatively to your personal data, please send an e-mail.