Skip to content

Open nowPosted 68 days ago

Senior Azure Cloud/Platform Engineer - MF

DVT21 open roles

Where
Midrand, Gauteng, South Africa
Work mode
Hybrid
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Azure Cloud/Platform Engineer - MFDVT · Midrand, Gauteng, South Africa
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on DVT's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.7% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.4%1 day
  2. 3.5%3 days
  3. 7.7%7 days
  4. 13.4%14 days
  5. 34.5%30 days
This job: posted 68 days ago

The posting

DVT is one of the top software development companies on the continent. Our software engineers are consulting on cutting edge applications at top companies in South Africa, as well as consulting globally. You will have the opportunity to work alongside some of the most established developers in the country and globally with the latest technologies.

DVT is seeking a Senior Azure Cloud/Platform Engineer to design and build a fully private Azure environment. This is a greenfield platform buildout, not application deployment into an existing environment. The engineer will establish the Azure networking foundation, configure all PaaS and managed services behind Private Endpoints, deploy private AKS clusters, and ensure end-to-end hybrid DNS resolution across an existing site-to-site VPN. All infrastructure must be codified for repeatable deployment across Production and Test environments.

DUTIES AND RESPONSIBILITIES

Azure Private Networking

  • Design and implement the VNet topology with appropriately segmented subnets for AKS, Private Endpoints, Application Gateway, and management
  • Deploy and configure Private Endpoints for Azure Container Registry, Azure SQL, Azure Storage (Blob and Table), Azure Key Vault, Azure Service Bus, and Azure App Configuration
  • Configure Private DNS Zones for all services
  • Configure Network Security Groups (NSGs) and User-Defined Routes (UDRs) to enforce least-privilege network access
  • Disable public access on all PaaS services once private connectivity is confirmed

Hybrid Connectivity and DNS

  • Work with infrastructure team to validate and optimise the existing site-to-site VPN
  • Deploy Azure DNS Private Resolver or DNS forwarder infrastructure to enable on-premises resolution of Azure Private DNS Zones
  • Conditional DNS forwarding on on-premises DNS servers
  • Ensure end-to-end name resolution works for all services across the VPN boundary — including validating that the VPN does not block cloud endpoints when both environments are active

AKS Private Cluster Deployment

  • Deploy AKS with a private API server endpoint (no public Kubernetes API exposure)
  • Configure Azure CNI networking with IP address planning to avoid conflicts with on-premises ranges
  • Set up node pool autoscaling for Production and scale-to-minimum/zero for the Test environment
  • Integrate AKS with Azure Container Registry via Private Endpoint and managed identity
  • Configure workload identity for secure access to Azure PaaS services from pods
  • Enable the Dapr extension for AKS as an Azure-managed cluster extension

Azure Application Gateway and Ingress

  • Deploy Azure Application Gateway with WAF v2 as the ingress point into the AKS cluster
  • Configure backend pools, health probes, and routing rules for the application workloads
  • Configure ingress routing to support traffic switching between on-premises and cloud based on availability and response time
  • Integrate TLS termination with certificates managed in Azure Key Vault

Security and Identity

  • Configure Azure Key Vault with private access for secrets, certificates, and encryption keys
  • Set up managed identities across all services to eliminate credential-based authentication
  • Implement RBAC across all deployed resources
  • Integrate with Entra ID (Azure AD) configure the foundational app registrations, tenant configuration, and identity infrastructure

Observability Infrastructure

  • Configure Azure Monitor, Container Insights, and Log Analytics workspace for the AKS cluster
  • Set up Application Insights resources for the .NET workloads
  • Configure Dapr's telemetry pipeline to flow into the same Application Insights and Log Analytics infrastructure
  • Establish alert rules and Azure Monitor workbooks for cluster health, node scaling, and Private Endpoint connectivity

Infrastructure as Code

  • Codify all infrastructure in Terraform or Bicep using a modular structure that supports environment-level parameterisation
  • Ensure the same codebase can deploy both Production (zone-redundant) and Test (cost-optimised, scale-to-zero) environments
  • Implement CI/CD pipelines for infrastructure deployment via Azure DevOps
  • Establish drift detection and automated compliance checks

Required Experience and Skills

Must-have

  • 5+ years in Cloud Engineering, Platform Engineering, or Infrastructure Engineering roles, with at least 3 years focused on Azure
  • Proven hands-on experience designing and deploying Azure Virtual Networks, subnets, NSGs, UDRs, and network peering
  • Deep experience with Azure Private Endpoints and Private DNS Zones across multiple PaaS services (SQL, Storage, Key Vault, ACR, Service Bus)
  • Experience deploying and operating AKS private clusters, including Azure CNI networking, node pool management, and workload identity
  • Strong experience with Azure Application Gateway (WAF v2) configuration and backend integration
  • Experience with hybrid connectivity: site-to-site VPN, DNS resolution across cloud/on-premises boundaries, Azure DNS Private Resolver or forwarder VM
  • On-premises infrastructure experience; understanding of how cloud and on-prem coexist in hybrid architectures, including firewalls, VPN gateways, and on-prem networking
  • Proficiency in Terraform or Bicep for infrastructure as code, with experience building multi-environment deployable modules
  • Experience with Azure Key Vault, managed identities, and Entra ID integration
  • Strong understanding of Kubernetes internals: networking (CNI), RBAC, Helm, ingress controllers, pod identity
  • Experience building CI/CD pipelines for infrastructure deployment (Azure DevOps preferred)
  • Experience configuring Azure Monitor, Container Insights, and Log Analytics for AKS clusters
  • Excellent documentation skills and experience with technical handover

Advantageous

  • Microsoft Azure certifications: AZ-305 (Solutions Architect), AZ-104 (Administrator), or AZ-400 (DevOps Engineer)
  • Certified Kubernetes Administrator (CKA)
  • Experience with Dapr on AKS cluster extension deployment, component configuration, and integration with Azure-backed state stores and pub/sub
  • Experience with Azure Service Bus (Private Endpoint configuration, topic/subscription topology)
  • Experience with Azure App Configuration for multi-environment feature and configuration management
  • Experience with Azure Database Migration Service and Data Migration Assistant
  • Experience with Azure landing zone frameworks (Cloud Adoption Framework, Enterprise-Scale)
  • Experience with Application Insights and OpenTelemetry instrumentation pipelines
  • Experience with cost optimisation patterns: AKS scale-to-zero, Azure SQL auto-pause, reserved instances
  • Familiarity with MassTransit over Azure Service Bus
  • Experience in telecommunications or ISP environments
  • Knowledge of GitOps tools such as ArgoCD or Flux

Who we are:

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against DVT's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on DVT's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    DVT's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.