We are looking for a **Lead Cloud Engineer** to join our innovative team.
We are delivering a Unified Automation Platform (Internal Developer Platform) to standardize secure, repeatable infrastructure delivery across Azure and on-premises VMware using templates and golden paths. You will lead Azure automation and AKS operations and strengthen IaC/CaC engineering practices. Apply to help teams ship faster with consistent, compliant deployments.
### Responsibilities
* Implement and maintain Terraform/OpenTofu modules for Azure App Services, Container Apps, Function Apps, Azure SQL, Cosmos DB, and Postgres, following designs defined by the Azure Architect
* Build and operate the Azure Kubernetes Service (AKS) platform day-to-day: cluster/node-pool provisioning, add-on configuration (ingress, cert-manager, external-dns, monitoring, policy), and namespace/tenant onboarding
* Implement identity wiring (managed identities, SPN/app registrations) and secrets integration (Azure Key Vault, OpenBao) for Azure workloads
* Build and maintain Image Factory pipelines for VM and container golden images (Linux and Windows/cloudbase-init baselines, CIS hardening, image scanning)
* Execute Configuration as Code (Ansible) playbooks for VM post-provisioning and golden-image handoff
* Support Backstage golden-path template integration for Azure provisioning, testing generated infrastructure end-to-end
* Troubleshoot and remediate production issues across Azure automation modules during Implementation and Adoption
* Contribute to module testing, drift detection, and documentation per the platform's Infrastructure as Code Engine standards
### Requirements
* 5+ years of hands-on experience building and operating Azure infrastructure via Terraform/OpenTofu, including CI/CD-driven deployment (Azure DevOps)
* At least 1 year of relevant leadership experience
* Experience operating Azure Kubernetes Service (AKS) clusters in production, including networking, policy, and namespace management
* Experience with Azure identity constructs (managed identities, SPN/app registrations) and secrets integration (Key Vault, dynamic secrets)
* Experience with Configuration as Code (Ansible) for VM post-provisioning and golden-image pipelines
* Working knowledge of Azure networking constructs (VNets, private endpoints, NSGs) sufficient to integrate with the network foundation owned by the Network Architect
* Combined proficiency as a Terraform (IaC) and Ansible (CaC) developer, working AI-assisted using GitHub Copilot (provided project-wide) as standard practice
* Excellent command of written and spoken English (B2+ level)
### Nice to have
* Experience with Azure VMware Solution (AVS) private cloud provisioning
* Familiarity with image hardening/scanning tooling and Shared Image Gallery publishing