- Company Name
- Hatch Pros
- Job Title
- Azure Cloud Engineer
- Job Description
-
**Job Title**
Azure Cloud Engineer
**Role Summary**
Senior Azure specialist focused on stabilizing, optimizing, and maturing a hybrid Azure environment. Responsibilities include establishing governance and security baselines, delivering repeatable IaC patterns, improving operational reliability, reducing cloud costs through FinOps, and integrating on‑prem AD/Entra ID, Azure Stack HCI, and VDI/W365.
**Expectations**
- Lead Azure governance, security, and automation initiatives.
- Provide architecture assessments and roadmap deliverables.
- Mentor Cloud Engineers, ensuring documentation and change control processes are followed.
**Key Responsibilities**
1. **Governance & Security** – implement Landing Zone standards, RBAC, Azure Policies, and initiatives; enforce Entra ID controls (Conditional Access, PIM, JIT); harden Key Vault and network security (NSGs, ASGs, Firewall, Private Endpoints).
2. **IaC & CI/CD** – build Bicep/Terraform baselines for VNets, subnets, routing, Private DNS, AKS/VMSS, Storage, Key Vault, App Services, SQL, Log Analytics; create reusable module libraries; develop Azure DevOps or GitHub Actions pipelines for plan/apply, linting, security scans, and promotions.
3. **Networking & Hybrid Connectivity** – optimize ExpressRoute/VPN topology, hub‑and‑spoke, routing, and segmentation; standardize Private Endpoints/Private Link and Private DNS strategies; validate hybrid identity and logon between Azure, on‑prem AD, and Horizon VDI.
4. **Windows 365/VDI & Azure Stack HCI** – ensure Cloud PC network access, image lifecycle, monitoring, policy baselines; standardize Arc‑enabled server policies, update rings, and monitoring; validate Horizon dependencies.
5. **Deliverables** – produce Current‑State Assessment, Governance & Security Baseline, IaC & Pipeline repositories, Operations Pack (dashboards, alerts, runbooks), Network & Hybrid Design, and executive readouts.
**Required Skills**
- Deep hands‑on Azure expertise (governance, policy, networking, compute, storage, databases).
- IaC proficiency with Bicep or Terraform.
- CI/CD experience using Azure DevOps or GitHub Actions.
- PowerShell scripting.
- Hybrid identity management (Entra ID + on‑prem AD).
- Private Link, DNS, and Private Endpoints configuration.
- Strong technical documentation and mentoring capabilities.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Technology, or related field.
- Azure certifications: Azure Solutions Architect Expert, Azure Administrator Associate, Azure Security Engineer Associate, and/or Azure DevOps Engineer Expert.
---