Quick Overview
Job Description
Senior Azure Cloud Engineer / Architect
Department: Information Technology - Infrastructure & Cloud Services
Job Level: Senior / Lead Individual Contributor
Reports To: Director of IT Infrastructure & Cloud Services
Environment: Global / Multi-Region Enterprise
Location: If near Richardson, TX, can come into office 3 days a week. If not, remote is fine.
Start/Length: ASAP and 6 months engagement, possibly more.
Position Summary
We are seeking a highly experienced Senior Azure Cloud Engineer / Architect to design, build, secure, operate, and continuously improve Microsoft Azure infrastructure supporting a global, multi-site organization.
This is a senior-level, hands-on technical role requiring broad expertise across the entire Azure cloud stack, including networking, compute, identity and access management, security, storage, backup and disaster recovery, monitoring, governance, automation, and cost optimization.
The successful candidate will serve as a senior technical authority for Microsoft Azure, capable of both designing enterprise cloud architecture and directly implementing, configuring, troubleshooting, securing, and supporting Azure infrastructure while also being able to mentor junior cloud engineers. The role will collaborate with Network, Security, Server, Application, Database, and IT teams across multiple countries and regions/
Key Responsibilities
Azure Architecture & Infrastructure
- Design, implement, and support enterprise-scale Azure environments across multiple geographic regions.
- Develop and maintain Azure Landing Zones, management groups, subscriptions, resource groups, naming standards, tagging, and governance models.
- Architect highly available, resilient, secure, and scalable cloud infrastructure aligned with Microsoft best practices.
- Build and administer Windows and Linux Azure Virtual Machines, managed disks, images, snapshots, Availability Zones, Availability Sets, and VM Scale Sets.
- Establish standardized deployment patterns for production, development, test, and disaster recovery environments.
- Serve as a senior escalation point for complex Azure infrastructure and architecture issues.
Azure Networking
Design, implement, and troubleshoot enterprise Azure networking technologies, including:
- Virtual Networks (VNets), subnets, VNet peering, and global peering
- Hub-and-spoke architectures and Azure Virtual WAN
- Network Security Groups (NSGs) and User Defined Routes (UDRs)
- Azure Firewall, Application Gateway, and Web Application Firewall (WAF)
- Azure Front Door, Load Balancers, NAT Gateway, and Traffic Manager
- Private Link, Private Endpoints, and Service Endpoints
- Azure DNS and Private DNS Zones
- ExpressRoute, Site-to-Site VPN, and Point-to-Site VPN
- Hybrid cloud, global WAN, and SD-WAN connectivity
- Network segmentation and Zero Trust architecture
Troubleshoot complex routing, DNS, firewall, VPN, peering, private endpoint, and application connectivity issues across Azure and on-premises environments.
Identity, IAM & Security
- Design and administer Microsoft Entra ID, Azure RBAC, Conditional Access, Privileged Identity Management (PIM), Managed Identities, Service Principals, and Application Registrations.
- Implement least-privilege and Zero Trust access models.
- Design and maintain security controls using Microsoft Defender for Cloud, Azure Firewall, WAF, DDoS Protection, Key Vault, Azure Policy, encryption, private endpoints, and security monitoring.
- Partner with Cybersecurity teams to remediate vulnerabilities, configuration issues, security recommendations, and audit findings.
- Ensure Azure environments comply with corporate security standards and applicable regulatory requirements.
Governance & Resource Management
- Manage Azure management groups, subscriptions, resource groups, policies, resource locks, tagging, and RBAC.
- Establish enterprise cloud governance standards and deployment guardrails.
- Maintain appropriate separation of duties and administrative boundaries.
- Implement Azure Policy and standardized security and configuration baselines.
- Ensure consistent resource ownership, lifecycle management, and operational standards across the global Azure environment.
Storage, Backup & Disaster Recovery
- Design and support Azure Storage Accounts, Blob Storage, Azure Files, Managed Disks, Azure NetApp Files, File Sync, encryption, and storage replication.
- Architect and administer Azure Backup, Recovery Services Vaults, and Azure Site Recovery.
- Design multi-region disaster recovery solutions based on defined RTO and RPO requirements.
- Conduct periodic recovery testing and ensure critical workloads can recover from regional or infrastructure failures.
Monitoring, Automation & Infrastructure as Code
- Design monitoring and alerting using Azure Monitor, Log Analytics, Application Insights, Network Watcher, Azure Service Health, Alerts, Action Groups, and Workbooks.
- Drive an Infrastructure-as-Code-first approach to improve deployment consistency, security, repeatability, and recoverability.
Hybrid, Global Infrastructure & Cloud Operations
- Integrate Azure with global data centers, corporate offices, manufacturing facilities, warehouses, and other enterprise locations.
- Support ExpressRoute, IPSec VPN, SD-WAN, hybrid DNS, Active Directory/Entra ID, and global routing architectures.
- Understand multi-region architectures, data residency requirements, and global disaster recovery considerations.
- Monitor Azure consumption and optimize cloud costs through right-sizing, Reservations, Savings Plans, resource cleanup, budgets, alerts, and Azure Advisor recommendations.
- Create and maintain architecture diagrams, network diagrams, build documentation, operational procedures, disaster recovery documentation, and cloud standards.
Required Qualifications
- 8+ years of enterprise infrastructure, cloud engineering, systems engineering, or related experience.
- 5+ years of hands-on Microsoft Azure experience supporting enterprise environments.
- Advanced knowledge of Azure networking, including VNets, peering, routing, firewalls, load balancing, private endpoints, VPNs, DNS, and ExpressRoute.
- Advanced knowledge of Azure Virtual Machines, compute, storage, availability, and performance optimization.
- Strong knowledge of Microsoft Entra ID, IAM, RBAC, PIM, Conditional Access, Managed Identities, and Service Principals.
- Strong understanding of Azure security architecture, including Defender for Cloud, Azure Firewall, WAF, Key Vault, Azure Policy, and Zero Trust principles.
- Experience with Azure Landing Zones, management groups, subscriptions, resource groups, governance, and enterprise cloud standards.
- Experience with Azure Backup, Site Recovery, Azure Monitor, and Log Analytics.
- Strong understanding of enterprise networking technologies, including TCP/IP, routing, DNS, DHCP, firewalls, VPNs, and load balancing.
- Strong Windows Server knowledge and working knowledge of Linux.
- Demonstrated experience troubleshooting complex, business-critical production environments.
- Strong communication skills and experience working with globally distributed technical teams.
Preferred Qualifications
- Microsoft Certified: Azure Solutions Architect Expert
- Microsoft Certified: Azure Administrator Associate
- Microsoft Certified: Azure Network Engineer Associate
- Microsoft Certified: Azure Security Engineer Associate
- Terraform Associate or equivalent Infrastructure as Code experience
- Experience with Azure DevOps, Azure SQL, Azure Virtual Desktop, and CI/CD.
- Experience supporting large multinational organizations, manufacturing environments, global data centers, and hybrid cloud architectures.
Key Success Characteristics
The ideal candidate is a hands-on senior cloud technologist capable of moving seamlessly between architecture and engineering. This individual can design an enterprise Azure solution at the architectural level and then work directly within Azure to build, secure, troubleshoot, automate, and optimize it.
The successful candidate will demonstrate strong technical ownership, exceptional troubleshooting skills, a security-first mindset, and the ability to lead technical design discussions and mentor other engineers. They must be comfortable working across networking, compute, identity, security, storage, automation, and traditional infrastructure while communicating effectively with technical teams and IT leadership.
The primary objective of this role is to ensure the organization's Microsoft Azure environment is secure, scalable, resilient, standardized, automated, cost-effective, and capable of supporting a 247 global enterprise.
Similar jobs
- IS
Cloud Engineer – Google Cloud Platform
NewInfo Services LLC
Dearborn, MI🇺🇸Hybrid21 hours agoGCPSQLLoad Balancing+8Technology - LT
Salesforce Revenue Cloud Advanced (RCA) Architect. @ TRAVEL AS NEEDED.
NewLTM
United States🇺🇸Hybrid21 hours agoSalesforceAgileSAFe+1Technology - TH
Guidewire PolicyCenter Cloud Architect
NewThinkNorth LLC
United States🇺🇸On-site21 hours agoSOAPSQLSpring+7Technology - RT
Cloud Security Architect in NC
NewRedSalsa Technologies, Inc.
Raleigh, NC🇺🇸On-site21 hours agoPCI DSSAzureCloudflare+5Technology - SJ
Cloud Infra Architect
Select Jarvis.com
United States🇺🇸Hybrid2 weeks agoAWSAzureCompliance+8 - SG
Cloud / DevSecOps Engineer
SSN Group LLC
Rockville, MD🇺🇸Hybrid5 days agoAWSBashCDK+2