Point your AI agent at freehire and let it find you a job.

Get the CLI →

Devox Software

NewBe an early applicant

Senior Azure Platform Engineer

Posted 4 views
Discussion

Summary

Senior Azure Platform Engineer who designs and owns a multi-tenant Azure platform for client workloads: landing zones on hub-and-spoke networking, Azure API Management as a façade, and Terraform-based infrastructure as code, with built-in security, observability, and DevOps automation at enterprise scale.

We're looking for a Senior Azure Platform Engineer to design and own the core Azure platform — landing zones, networking, API management, and Infrastructure as Code — that other engineering teams build on top of. You'll work within a platform engineering team responsible for secure, repeatable, and fully observable cloud foundations at enterprise scale.

Project
You'll build and evolve a multi-tenant Azure platform — landing zones, an API façade, and integration services — that underpins several client workloads, with security, observability, and DevOps automation designed in from day one.

Responsibilities
Design and evolve Azure Landing Zones on a strict hub-and-spoke topology (never peer-to-peer), including VNet peering, UDRs, layered network segmentation, NSGs, WAF, private endpoints, and egress control
Own Private DNS, Private Link, and hybrid DNS forwarding across the platform
Build and govern Azure API Management as an architectural façade: products, versioning, revisions, policy expressions, backend abstraction, subscription and OAuth 2.0 enforcement, developer portal governance, and self-hosted gateways for on-premises backends
Drive PaaS-first, Azure-default platform decisions across APIM, Logic Apps Standard, and Functions hosting, and explain the pattern behind every product choice
Design modular, composable Terraform modules (Azure Verified Modules) that let new platform capabilities be added without re-platforming
Build parameterised, multi-region and multi-instance Terraform blueprints, including configuration as code for APIM, Policy, monitoring, and DNS
Own module versioning, release management, and golden-path onboarding templates other engineering teams can consume
Implement automated platform testing, supply chain security for platform artefacts, and drift detection/reconciliation across instances
Define SLOs/SLIs, health models, alerting standards, runbooks, and synthetic testing; build dashboards on Azure Monitor, Log Analytics, and Application Insights
Harden the platform with Defender for Cloud, Entra ID managed identities, Key Vault, availability zones, and IaC-driven disaster recovery
Integrate diagnostic settings and data connectors as code with the shared Sentinel SIEM, and implement policy as code (Azure Policy definitions, initiatives, exemptions) with compliance reporting
Provide the private networking, identity, secrets, and observability foundation that async/event-driven workloads depend on, in partnership with the team owning messaging and event topology
Bring ad hoc scripts and unmanaged integrations under version-controlled, reviewed, and gated DevOps pipelines, eliminating manual or scheduled-task execution outside the platform

Requirements
5+ years of experience in cloud infrastructure/platform engineering, with deep hands-on Azure expertise
Strong knowledge of Azure Landing Zones, VNet peering, UDRs, and defence-in-depth networking (NSGs, WAF, private endpoints, egress control, Private DNS, Private Link, hybrid DNS forwarding)
Hands-on experience with Azure API Management as a façade layer: products, versioning, revisions, policy expressions, OAuth 2.0/subscription enforcement, developer portal governance, self-hosted gateways
Solid understanding of Azure Integration Services (APIM, Logic Apps Standard, Functions hosting) and the ability to justify pattern-driven product choices
Advanced Terraform skills: modular design, Azure Verified Modules, environment promotion, feature-flagged components
Experience building parameterised, multi-region/multi-instance IaC and golden-path onboarding templates for other teams
Practical experience with Azure Monitor, Log Analytics, Application Insights, Defender for Cloud, and Sentinel SIEM integration
Experience with policy as code, Entra ID managed identities, Key Vault, availability zones, and IaC-driven disaster recovery
Strong analytical and communication skills, comfortable working cross-functionally with integration, security, and application teams
Upper-Intermediate English or higher

What We Offer
Transparent strategy and thoughtful management that keep everyone aligned
Space for personal growth and career development without limits
A culture of continuous learning: internal courses, workshops, and English classes twice a week
Skill up events where we share experience and stay on top of trends
Competitive perks: flexible schedule, a strong compensation package, support for professional certifications, and generous vacation policy
Team spirit that thrives through regular events, gatherings, and celebrations

Skills

What Senior DevOps jobs ask for — and how much of it you have →
Apply

See also

DevOps jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available