Senior Cloud Infrastructure Engineer (Terraform)
Job Summary
Role Overview
We are looking for a Senior Cloud Infrastructure Engineer to design build automate and maintain secure and reliable cloud infrastructure on Microsoft Azure. The role has a strong focus on Infrastructure as Code and Terraform-driven automation across multiple environments.
The engineer will act as a hands-on Terraform subject matter expert translating infrastructure requirements into reusable scalable and supportable automation. This is an individual contributor role for a strong cloud and automation practitioner who is comfortable executing complex infrastructure changes improving engineering standards and reducing manual operational effort.
Key Responsibilities
Design build and maintain Infrastructure as Code using Terraform across multiple Azure environments.
Serve as a Terraform subject matter expert for module design code quality reusable patterns state management and infrastructure automation practices.
Develop and enhance reusable Terraform modules templates and automation frameworks to standardize cloud provisioning.
Automate provisioning deployment configuration and operational workflows to reduce manual effort and improve consistency.
Manage and support Azure cloud infrastructure including networking identity security subscriptions and shared platform services.
Build and automate CI/CD pipelines using Azure DevOps and/or GitLab for infrastructure deployment and validation.
Implement secure-by-default infrastructure patterns and embed validation policy and quality checks into automation workflows.
Troubleshoot complex Azure and Terraform issues across development pre-production and production environments.
Implement monitoring alerting and operational controls to support reliable cloud services.
Partner with cloud security platform and application teams to translate technical requirements into automated infrastructure solutions.
Contribute to continuous improvement of cloud engineering standards documentation and operational processes.
Participate in Agile delivery and support production readiness change implementation and operational support activities.
Design Azure network topology using a hub-and-spoke model with shared platform services centralized in the hub workload-specific spokes and swimlane-based environment segregation.
Define and enforce CIS benchmark-aligned security baselines and policies for Azure infrastructure hardening and compliance.
Configure and manage VPN Gateway connectivity (Point-to-Site Site-to-Site and VNet-to-VNet) including subnet sizing and IP address range planning for hybrid network architectures.
Configure Azure Bastion and other secure remote access mechanisms for infrastructure administration and define VM-level and resource-level IAM/RBAC role assignments.
Configure and manage service connections and managed identities (system-assigned and user-assigned) for secure authentication between CI/CD pipelines and Azure resources.
Apply Terraform security best practices including secure handling of sensitive variables outputs and state files and remediate infrastructure vulnerabilities identified during provisioning.
Configure and support networking for containerized workloads on Azure Kubernetes Service (AKS) integrated with the broader Azure network topology.
Technical Focus
Microsoft Azure cloud infrastructure and platform services
Terraform and Infrastructure as Code (IaC)
Terraform modules reusable patterns remote state workspaces and lifecycle management
Azure DevOps and GitLab CI/CD pipelines
Infrastructure provisioning and operational automation
Azure networking identity security and subscription management
Scripting and automation using Python Bash and PowerShell
Monitoring alerting and reliability practices
Version control and collaborative engineering workflows
Hub-and-spoke network architecture and swimlane-based environment design
CIS benchmark alignment and security policy definition for infrastructure hardening
VPN Gateway connectivity (P2S S2S VNet-to-VNet) and subnet/IP address planning
Managed identities (system-assigned and user-assigned) service connections and VM/resource-specific IAM roles
Azure Bastion and secure administrative access
Terraform security practices including sensitive data handling and state file protection
Container orchestration (AKS) networking
Experience & Required Qualifications
79 years of overall experience in Cloud Engineering DevOps Infrastructure Engineering Platform Engineering or related technical roles.
Strong hands-on Microsoft Azure experience in enterprise environments.
Deep practical expertise with Terraform including design and implementation of reusable modules and automation patterns.
Proven track record of automating cloud infrastructure provisioning and operational processes.
Hands-on experience building and maintaining CI/CD pipelines using Azure DevOps and/or GitLab.
Strong scripting proficiency in Python Bash and/or PowerShell.
Solid understanding of cloud networking identity security and operational reliability.
Experience troubleshooting infrastructure and automation issues in large-scale environments.
Ability to work as a senior individual contributor with strong ownership and hands-on execution.
Practical experience designing hub-and-spoke Azure network architectures including shared services in the hub workload isolation across spokes and swimlane-based environment segregation.
Working knowledge of CIS benchmarks and experience defining security policies for cloud infrastructure hardening and compliance.
Hands-on experience configuring VPN Gateway connectivity (Point-to-Site Site-to-Site and VNet-to-VNet) and subnet/IP address planning for hybrid network architectures.
Strong understanding of Azure IAM including RBAC system-assigned and user-assigned managed identities service connections and VM/resource-specific role assignments.
Experience with Azure Bastion and other secure administrative access patterns.
Understanding of Terraform security considerations including sensitive variable and state file handling and experience identifying and remediating common cloud infrastructure vulnerabilities.
Familiarity with container orchestration platforms (e.g. AKS) and associated networking configuration.
Preferred Qualifications
Terraform Associate certification.
Microsoft Azure certifications such as Azure Administrator Azure Solutions Architect or AZ-400.
Experience creating and governing enterprise Terraform standards and reusable module libraries.
Experience with policy-as-code automated validation or secure cloud provisioning practices.
Experience working in large enterprise or regulated environments.
Key Competencies
Strong hands-on engineering and automation mindset
Deep problem-solving and troubleshooting capability
Ownership-driven approach with attention to quality and reliability
Ability to convert infrastructure requirements into scalable automation
Clear communication and effective cross-team collaboration
Self-starter with a continuous improvement mindset
Required Experience:
Senior IC