freehire launches on Product Hunt on 26 August.

Follow →

Azure Infrastructure Engineer (Bicep/laC)

Summary

Designs and deploys Azure cloud infrastructure using Bicep IaC, focusing on networking, security, governance, and scalability for enterprise workloads.

We are looking for an experienced Azure Infrastructure Engineer with strong expertise in Azure cloud architecture and Infrastructure-as-Code (IaC). The role will focus on designing, provisioning, securing, and governing Azure infrastructure using Bicep as the primary template language for defining and deploying Azure Resource Manager (ARM) resources.

The ideal candidate will have strong hands-on experience with Azure networking, identity, governance, security, high availability, and infrastructure automation, with the ability to translate business and application requirements into scalable and maintainable cloud infrastructure.

Responsibilities

Azure Infrastructure & IaC

  • Design and develop Bicep templates and reusable modules for Azure infrastructure provisioning.

  • Provision and manage Azure resources including:

    • Virtual Machines

    • App Services

    • AKS

    • VNets, Subnets, NSGs

    • Private Endpoints and VNet Peering

    • Azure Storage, Blob, Files, and Managed Disks

    • Azure SQL and Cosmos DB

  • Maintain a modular and parameterized Bicep template library supporting development, staging, and production environments.

  • Ensure infrastructure is consistent, scalable, secure, and aligned with enterprise standards.

Azure Networking & Architecture

  • Design enterprise-grade Azure network architectures, including Hub-and-Spoke VNet models.

  • Configure and manage:

    • VNets and Subnets

    • NSGs and Route Tables

    • Private Link/Private Endpoints

    • Azure DNS

    • VNet Peering

    • ExpressRoute

    • VPN Gateway

  • Design traffic segmentation and secure connectivity across environments and workloads.

  • Support hybrid and enterprise cloud connectivity requirements.

Identity & Security

  • Define and implement Azure identity and access controls using Microsoft Entra ID, Azure RBAC, and Managed Identities.

  • Support Conditional Access and least-privilege access models.

  • Manage Azure Key Vault for secrets, certificates, and encryption keys.

  • Ensure infrastructure follows security and compliance best practices.

Azure Governance

  • Establish and maintain governance using:

    • Azure Policy

    • Management Groups

    • Subscription hierarchy

    • Resource Groups

    • Template Specs / governance frameworks

  • Enforce tagging, cost management, security, and compliance standards.

  • Support Azure Landing Zone design and subscription management.

High Availability & Disaster Recovery

  • Design highly available and resilient Azure architectures using Availability Zones and region-pairing strategies.

  • Define backup, recovery, failover, and disaster recovery approaches.

  • Support capacity planning and scalability assessments as workloads grow.

Monitoring & Cost Optimization

  • Configure Azure Monitor and Log Analytics for infrastructure monitoring and visibility.

  • Define infrastructure-level alerts and operational monitoring.

  • Monitor and optimize Azure infrastructure costs through:

    • Resource right-sizing

    • Reserved Instances / Savings Plans

    • Resource lifecycle management

    • Azure Cost Management

Documentation & Collaboration

  • Create and maintain network diagrams, architecture decision records (ADRs), infrastructure specifications, and operational runbooks.

  • Work with application, security, DevOps, and architecture teams to translate requirements into infrastructure solutions.

  • Collaborate with distributed international teams and stakeholders.

  • Participate in Agile ceremonies while independently owning infrastructure design and delivery.

Required Skills & Experience

  • 3+ years of hands-on experience designing and deploying Azure infrastructure.

  • Strong hands-on experience with Bicep and ARM JSON for Azure resource provisioning.

  • Strong understanding of Azure Landing Zones, subscription vending, and resource hierarchy.

  • Deep knowledge of Azure networking, including:

    • VNets and Subnets

    • NSGs

    • Route Tables

    • Private Link/Endpoints

    • DNS

    • ExpressRoute

    • VPN Gateway

    • VNet Peering

  • Strong knowledge of Microsoft Entra ID, RBAC, Managed Identities, and Key Vault.

  • Experience with Azure Policy and Management Groups.

  • Knowledge of Azure Storage services, including LRS, ZRS, and GRS redundancy models.

  • Experience with Azure SQL and Cosmos DB infrastructure.

  • Experience configuring Azure Monitor, Log Analytics, and infrastructure alerting.

  • Strong understanding of cloud security, scalability, availability, and infrastructure governance.

InnoWave gives equal opportunity in employment regardless of gender, gender identity, sexual orientation, marital status, race, nationality, religion, age, disability, political beliefs, or any other factor. InnoWave will not pay fees to any third-party agency or company that does not have a signed agreement, do not submit resumes/CV's directly.

By answering to this job post, you consent the use of your data by InnoWave Group, for as long as necessary. We conduct regular data-cleansing and updating exercises to make sure the information we have is relevant and accurate. If you have any doubt or request to make relatively to your personal data, please send an e-mail.

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available