582,867open jobs
25,570companies
81,102added this week
Browse all
Salary
$133k – $256k per year (Estimated)
Location
Remote/Hybrid (Canada)
Seniority
Staff · 6+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match

About the Role

We are creating a new Azure cloud platform to serve as the foundation for a multi-year cloud modernization program. We need a Lead Azure Cloud Engineer who can walk in, take design ownership, and start building in week one. This is a hands-on, individual-contributor role: you will write the code yourself, stand up the pipelines yourself, and set the technical bar the rest of the teams build against.

You are the senior-most and dedicated cloud engineering voice on this program. You need to be well-rounded: as comfortable troubleshooting a firewall rule or a network route as you are writing a Terraform module or designing the pipeline that deploys it. You will need to work with the firm's existing IT, security, and network teams to land on shared standards, and then you're the one who codifies them into automation.

Tools and Stack You'll Work In

Azure (landing zone, networking, Entra ID) - Terraform + Terraform Cloud - Azure Verified Modules - GitHub Actions - Microsoft Defender for Cloud - Azure Policy - Azure Monitor / Log Analytics - GitHub Copilot / Anthropic Claude (AI-assisted delivery). Our policy-as-code and shift-left scanning has not been finalized; helping evaluate and select this tooling is part of the role.

An internal developer platform pattern for self-service application delivery (e.g. HashiCorp HCP Waypoint, which integrates with HCP Terraform).

As the Staff Azure Cloud Engineer, you will be responsible for, but not limited to, the following:

  • Design and build the Azure landing zone, aligned to Microsoft's Cloud Adoption Framework design areas (identity, network topology, resource organization, governance, management, security) and reviewed against the Well-Architected Framework's five pillars at each milestone.
  • Build with Azure Verified Modules (AVM) as the base layer, composing right-sized custom Terraform modules on top rather than hand-rolling every resource or adopting the full CAF Enterprise-Scale module wholesale.
  • Own the Terraform Cloud (TFC) setup end to end: workspace structure (one state file per workload per environment), variable sets, run triggers, and remote state strategy.
  • Own hands-on networking and firewall configuration: hub-spoke topology, NSGs, Azure Firewall, WAF rules, private endpoints, and DNS. There is no separate network architect on this program; you need to be able to design, configure, and troubleshoot these yourself, informed by the firm's existing network/security teams.
  • Work with internal teams to define our to-be cloud native software engineering practice and process, then codify it. Coding standards, module and repo conventions, branching and review workflow, policy-as-code approach, and the shift-left tooling chain (scanning, testing, gating) are not yet decided. You will work with the firm's existing security and engineering teams to land on a standard, and then turns that into working Terraform, pipelines, and documentation.
  • Establish policy-as-code guardrails (approach and tooling still to be decided, e.g. HashiCorp Sentinel, OPA, or another option you recommend and help evaluate) so that governance is enforced automatically on every plan
  • Build the CI/CD pipeline for infrastructure changes: automatic plan on every pull request, mandatory human review, manual apply gate
  • Help stand up our shift-left scanning practice: the goal is that IaC, code, and dependency issues are caught early in the engineering cycle.
  • Set up the security and observability baseline: Microsoft Defender for Cloud, centralized Log Analytics, Azure Policy at the management-group scope, hub-spoke network segmentation, and private endpoints.
  • Coordinate with the firm's identity/security and network teams on Entra ID architecture (app registrations, Conditional Access, PIM) and network/firewall standards.
  • Set the technical example for module structure, versioning, documentation, and code review standards that future hires on this program will follow as the team grows.
  • Extend the paved path from infrastructure to application delivery. Define a golden, self-service deployment pattern so Backend and Frontend engineers can ship application code onto the landing zone without hand-rolling their own pipelines.

We expect that our Staff Azure Cloud Engineer will have the following qualifications:

  • 6+ years in cloud infrastructure/platform engineering, with real production ownership, not just POCs.
  • A well-rounded Azure Cloud generalist, comfortable across Terraform/IaC, Azure networking, and firewalls/network security,
  • Deep, hands-on Terraform experience: module authorship, remote state, workspace/environment strategy, version pinning, and awareness of the tradeoffs in monorepo vs. per-module repo structures.
  • Strong, hands-on Azure networking and security: hub-spoke topology, NSGs, Azure Firewall, WAF rules, private endpoints, DNS, and hybrid/legacy connectivity patterns, plus identity (Entra ID, RBAC, managed identity) and governance (management groups, Azure Policy).
  • Working knowledge of SOC 2 control families (access control, change management, logging/monitoring, network security) well enough to design a landing zone that satisfies them by default, even without prior formal audit experience.
  • Able to work effectively with the firm's existing security, network, and IT teams
  • Direct experience building CI/CD pipelines for infrastructure changes (GitHub Actions, Azure DevOps, or equivalent), including plan/apply gating patterns.
  • Working knowledge of policy-as-code approaches (e.g. Sentinel, OPA) and IaC/security scanning practices.
  • Comfortable being the first cloud engineer on the program: able to make and defend decisions yourself.
  • Strong scripting ability (PowerShell, Bash, or Python) for tooling and automation glue.
  • Comfortable defining a self-service application deployment pattern (a “golden path”) that other engineers can use to ship application code without needing deep Terraform expertise themselves.
  • Preferred Qualifications

  • Direct experience with Terraform Cloud/Enterprise specifically (not just open-source Terraform CLI).
  • Prior experience building a landing zone from zero, versus inheriting and extending one.
  • Experience consuming (or ideally contributing to) Azure Verified Modules.
  • Direct experience operating in a compliance-driven environment (SOC 2, HIPAA, or similar) through an actual audit cycle, where controls needed to be demonstrable, not just implemented.
  • Experience mentoring other infrastructure/platform engineers.
  • Experience with HashiCorp HCP Waypoint, or a similar internal developer platform (IDP) approach, for standardizing self-service application deployment.
  • HashiCorp Terraform Associate or Professional certification.
  • Microsoft certifications: AZ-305 (Solutions Architect) and/or AZ-400 (DevOps Engineer); AZ-500 (Security) is a plus.

You Matter - HCVT provides a variety of benefits and perks that help sustain a healthy and thriving work environment.

  • Visit the Benefits section to learn more.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
582,867 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$123k – $156k per year • Remote • Full-Time • 10+ years exp • United States
Python
PowerShell
C#
Databases
Snowflake
AI/ML
Copilot
Cursor
Claude Code
dbt
AI Agents
DevOps
Terraform
Azure DevOps
Azure
CI/CD
Docker
Kubernetes
Shift-Left
Bicep
Cybersecurity
HIPAA
Shift-Left Security
Management
Agile
QA
Selenium
JMeter
Playwright
Apply
$69k – $82k per year • In office • Full-Time • Chicago • Charlotte • Boston
Python
AI/ML
Hadoop
Apply
$41k – $85k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • Curitiba
Python
JavaScript
C#
Node JS
C#
.NET
Mobile
Twilio
DevOps
Rest API
GCP
Azure
CI/CD
AWS
SLI/SLO/SLA
GitHub
GitLab
Management
WhatsApp
Apply
$104k – $203k per year (Estimated) • In office • Full-Time • 8+ years exp • Bachelor's Degree • Bentonville
Python
SQL
Scala
AI/ML
Spark
Analytics
Tableau
Power BI
Apply
$139k – $283k per year (Estimated) • In office • Full-Time • 6+ years exp • Bachelor's Degree • United States
Python
Java
SQL
Scala
Databases
Apache Kafka
Google BigQuery
BigQuery
AI/ML
Spark
AI Agents
Agentic Workflows
DevOps
GCP
CI/CD
Incident Management
Analytics
ETL/ELT
Apply
$37k – $81k per year (Estimated) • Remote/Hybrid • Full-Time • Associate's Degree • Los Angeles
Management
Outlook
Apply
$64k – $137k per year (Estimated) • Remote/Hybrid • Full-Time • 8+ years exp • Bachelor's Degree • Irvine
Analytics
Microsoft Excel
Apply
$67k – $143k per year (Estimated) • Remote/Hybrid • Full-Time • 8+ years exp • Bachelor's Degree • Long Beach
Analytics
Microsoft Excel
Apply
$67k – $143k per year (Estimated) • Remote/Hybrid • Full-Time • 8+ years exp • Bachelor's Degree
Analytics
Microsoft Excel
Apply
Data Specialist 11 days ago
$89k – $191k per year (Estimated) • Remote/Hybrid • Full-Time • Bachelor's Degree • Fort Worth
Databases
MS SQL
Apply
See all jobs
This is one of many
582,867 more open roles from verified company boards, updated every day.