The posting
Position Summary
The Cloud Engineer is responsible for deploying, maintaining, securing, troubleshooting, and improving Microsoft Azure infrastructure and related hybrid services.
This is a hands-on, mid-level engineering role requiring production experience with Azure infrastructure, networking, identity, monitoring, automation, and Infrastructure as Code. The engineer will independently manage assigned services and projects while operating under the architectural direction of the Infrastructure Manager.
This position is based in the Westlake office and requires on-site attendance five days per week. It is not a hybrid or remote position.
Primary Responsibilities
- Design, deploy, configure, maintain, and troubleshoot Microsoft Azure infrastructure in accordance with established architecture and security standards.
- Manage Azure virtual machines, managed disks, storage accounts, virtual networks, subnets, network security groups, route tables, private endpoints, load balancers, application gateways, and related infrastructure services.
- Support Microsoft Entra ID, Azure role-based access control, managed identities, service principals, enterprise applications, Privileged Identity Management, and access-governance processes.
- Implement and maintain Infrastructure as Code using Terraform, Bicep, or ARM templates.
- Develop and maintain PowerShell automation for provisioning, reporting, compliance validation, operational support, and remediation.
- Support Azure DevOps or GitHub-based deployment workflows, including source control, pull requests, code reviews, testing, and release approvals.
- Configure and maintain Azure Monitor, Log Analytics, Application Insights, dashboards, alerts, and diagnostic settings.
- Investigate and resolve infrastructure alerts, service degradation, authentication failures, network connectivity problems, application dependencies, and cloud resource issues.
- Support hybrid connectivity between Azure, corporate locations, on-premises environments, and authorized third-party services.
- Assist with Azure Firewall, VPN gateways, ExpressRoute, private DNS, network routing, and secure application connectivity.
- Administer backup, recovery, patching, vulnerability remediation, disaster recovery, and business continuity processes for Azure-hosted workloads.
- Review Azure Advisor, Microsoft Defender for Cloud, cost-management, and security recommendations and coordinate appropriate remediation.
- Apply Azure Policy, naming standards, tagging requirements, resource locks, least-privilege access, and other governance controls.
- Identify unused, oversized, underperforming, or improperly configured resources and recommend cost, reliability, and performance improvements.
- Participate in cloud migrations, infrastructure modernization projects, proof-of-concept deployments, and production implementations.
- Produce and maintain cloud architecture diagrams, build documentation, operational runbooks, inventories, support procedures, and recovery documentation.
- Prepare and execute infrastructure changes through established change-management and approval processes.
- Provide technical guidance and escalation support to systems administrators, service desk personnel, and other technology teams.
- Partner with Cybersecurity to remediate cloud security findings and improve the organization’s Azure security posture.
- Participate in an after-hours support and on-call rotation.
- Perform other cloud and infrastructure responsibilities as assigned.
Minimum Qualifications
- Three to five years of experience in cloud engineering, systems engineering, infrastructure operations, DevOps, or a related technical position.
- At least two years of hands-on experience supporting Microsoft Azure in a production environment.
- Demonstrated experience administering Azure virtual machines, networking, storage, monitoring, identity, and access controls.
- Experience creating and maintaining PowerShell scripts for infrastructure administration and automation.
- Experience with Terraform, Bicep, ARM templates, or another Infrastructure as Code platform.
- Working knowledge of Microsoft Entra ID, Azure RBAC, managed identities, service principals, and least-privilege access.
- Strong understanding of TCP/IP, DNS, routing, subnetting, firewalls, VPNs, load balancing, and network security concepts.
- Experience administering Windows Server or Linux operating systems.
- Experience troubleshooting cloud infrastructure, application connectivity, authentication, performance, and availability issues.
- Experience with monitoring, logging, alerting, backup, recovery, patching, and vulnerability-remediation processes.
- Ability to independently manage assigned work and communicate risks, blockers, and technical recommendations.
- Strong written and verbal communication skills.
- Ability to create clear technical documentation and operational procedures.
- Ability to participate in scheduled maintenance and an after-hours on-call rotation.
- Ability to work on-site at the Westlake office five days per week.
Preferred Qualifications
- Microsoft Certified: Azure Administrator Associate, AZ-104.
- Microsoft Certified: Azure Network Engineer Associate, AZ-700.
- Microsoft Certified: DevOps Engineer Expert, AZ-400.
- HashiCorp Certified: Terraform Associate.
- Experience with Azure Firewall, Application Gateway, Private Link, ExpressRoute, VPN Gateway, Azure DNS, or private DNS zones.
- Experience with Azure Policy, Management Groups, Landing Zones, Defender for Cloud, Microsoft Sentinel, or Azure governance.
- Experience with Azure DevOps, GitHub Actions, Git, or another CI/CD platform.
- Experience with Microsoft 365, Intune, Conditional Access, Privileged Identity Management, or enterprise application integrations.
- Experience supporting Azure Kubernetes Service, Azure App Service, Azure Functions, SQL services, or other Azure platform services.
- Experience with disaster recovery, high availability, backup testing, and infrastructure resiliency.
- Experience managing Azure costs, reservations, resource tagging, budgets, and optimization recommendations.
- Bachelor’s degree in information technology, computer science, cybersecurity, cloud computing, or a related discipline. Equivalent professional experience and certifications may be considered.
Required Competencies
- Strong Azure infrastructure and troubleshooting skills.
- Ability to take ownership of technical issues through resolution.
- Sound judgment when making changes in production environments.
- Security-focused approach to cloud administration.
- Ability to translate technical requirements into reliable infrastructure solutions.
- Strong analytical and problem-solving skills.
- Effective collaboration with infrastructure, cybersecurity, network, and application teams.
- Clear communication with both technical and nontechnical stakeholders.
- Attention to detail in scripting, deployment, documentation, and change management.
- Willingness to accept architectural direction while independently completing assigned work.
- Commitment to continuous technical and professional development.



