Cloud Engineer
Summary
Cloud Engineer at Waverly Advisors building and operating a modern Azure platform for a regulated financial services organization. Key responsibilities include infrastructure as code, networking, identity management, and governance using technologies like Terraform, Databricks, and Azure services.
Waverly Advisors’ primary goal is to serve our clients, one another, and our communities. We aren’t your typical wealth management firm. Our intense client focus is at the center of everything we do. We go far beyond just managing our clients’ investments, offering truly in-depth financial planning. We set ourselves apart by actually living and acting on our guiding principle, ‘Serve.’ It is the reason we go to work every day.
In this role, you’ll be challenged to take on work that upholds our guiding principle and drives Waverly Advisors forward. We hope you’ll grow as a person and leader in your field and transform those around you as well.
We are building a modern Azure platform to support the firm's growth, innovation, and operational needs. Our cloud environment powers a diverse set of services, from data and AI solutions to business applications and enterprise productivity platforms. Everything is deployed through infrastructure as code and governed to meet the security, compliance, and operational standards expected of a regulated financial services organization.
We are looking to add a Cloud Engineer to our team in our Birmingham, AL location. The Cloud Engineer is an essential part of the Waverly Advisors team. You will help build and operate the Azure foundation that every workload depends on, including landing zones, networking, identity, infrastructure as code, and deployment pipelines. Internal applications, AI services, automation solutions, virtual machines, Microsoft 365 integrations, and the data platform all run on this shared foundation.
This is a hands-on engineering role for someone who can build, troubleshoot, automate, and govern cloud infrastructure in production. We need someone who can reason through complex Azure challenges, clearly communicate tradeoffs, and design systems that other users can safely and confidently consume.
Responsibilities:
- Build and operate Azure landing zones, Virtual WAN networking, private connectivity, identity integration, and shared platform services.
- Enhance and expand our Terraform platform, including module design, state management, environment strategy, drift detection, governance automation, and remaining platform capabilities such as private serverless connectivity.
- Build secure CI/CD patterns using federated identity, managed identities, RBAC, and least-privilege access.
- Administer and govern Databricks workspaces, Unity Catalog, account-level identity, and network isolation for serverless compute.
- Design and operate secure storage: private endpoints, Azure firewalls, encryption with customer-managed keys, and lifecycle policies.
- Implement Azure Policy, logging, monitoring, and operational guardrails appropriate for a regulated financial services environment.
- Troubleshoot production platform issues across networking, identity, DNS, private endpoints, data services, and deployment pipelines.
- Document patterns, standards, and decision records so the platform can scale beyond one person or one team.
Required Qualifications and Experience:
- Production-depth Terraform experience, including state, modules, environment structure, drift, and long-term maintainability, not just writing HCL.
- Strong Azure networking experience. We run Virtual WAN with a secured hub (routing intent, hub route tables, Azure Firewall) plus private endpoints and private DNS across spokes. You should be able to reason through that class of design and troubleshoot it in production.
- Azure Storage at production depth: ADLS or blob with private endpoints, network rules, access control, and lifecycle management.
- Azure Key Vault and encryption key management, including customer-managed keys, rotation, and identity-based access to keys and secrets.
- Databricks administration: workspaces, Unity Catalog, account-level identity, and network isolation for serverless compute.
- GitHub Enterprise and Actions as a deployment path: OIDC federation with environment-scoped credentials, environment gates, rulesets and CODEOWNERS. Equivalent depth in Azure DevOps pipelines with workload identity federation transfers; what matters is that you have run gated, secretless deployments.
- Hands-on experience with Microsoft Entra ID, managed identities, Azure RBAC, and least-privilege access design.
- Azure governance and observability: Azure Policy at scale, diagnostic settings, and centralized logging through Log Analytics.
- PowerShell for automation and operational tooling: Azure and Microsoft Graph modules, scripting against tenant and platform APIs, and packaging work so it runs unattended rather than from someone's laptop.
- Ability to balance speed, security, governance, and operational simplicity in a growing cloud platform.
Required Qualifications and Experience:
- Azure Landing Zones or Microsoft Cloud Adoption Framework.
- Microsoft Sentinel, detection content, or security monitoring.
- Application delivery on Azure: App Service, Container Apps, or Functions, and edge services such as Front Door, Application Gateway, or API Management for public-facing workloads.
- Databricks Asset Bundles or other deployment approaches for data platform workloads.
- Experience in financial services
- Python for validation, tooling, or working alongside the data platform.
Travel:
- Minimal travel is required.
Physical Requirements:
- Prolonged periods of sitting at a desk and working on a computer.
- Must be able to lift 15 pounds at times.
- Must be able to access and navigate each department at the organization’s facilities.
Benefits:
- Comprehensive Health, Dental, and Vision coverage to support your overall well‑being.
- 401(k) retirement plan with match and profit sharing to help you invest in your future.
- Twelve paid holidays each year.
- An extra vacation day during your birthday week—so you can celebrate you!
- Responsible Time Off Policy giving flexibility without annual PTO limits, while balancing team responsibilities and business needs.
- Paid sabbatical program: Enjoy four consecutive weeks of paid time off after seven years of service.
- Compensation commensurate with experience.
Legal:
Waverly Advisors, LLC. is an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to race, color, creed, religion, sex, gender, genetic information, national origin, disability, uniform service, veteran status, age, or any other classification protected by federal, state, or local law.