Tech Stack
AnsibleAzureCloudDockerGrafanaPythonSQLTerraformVault
About the role
- Build and operate secure, reliable and scalable platforms on Microsoft Azure
- Design, modularize and maintain Azure landing zones and workloads with Bicep
- Build and maintain YAML pipelines in Azure DevOps or GitHub Actions; integrate quality gates and approvals
- Run and optimize AKS, Azure App Service, Functions, ACR, Storage, VMSS, Azure SQL/Cosmos DB
- Configure networking and security: VNets, peering, NSGs/ASGs, Private Endpoints, Application Gateway/Front Door, Key Vault, RBAC, Azure Policy
- Implement observability: Azure Monitor, Log Analytics, Application Insights and KQL dashboards/alerts (optionally Managed Grafana)
- Improve resilience and optimize costs via tagging, budgets and recommendations
- Investigate infra/deployment/performance issues and automate fixes to prevent regressions
- Apply Microsoft Entra ID best practices, Defender for Cloud recommendations and pipeline hardening
Requirements
- Solid, hands‑on Bicep (authoring, modules, parameterization, deployments at subscription/resource‑group scope)
- 3+ years in DevOps/SRE or cloud engineering, with practical Azure experience
- Scripting: PowerShell and/or Bash (Python welcome)
- Containers: Docker; orchestration with AKS (Helm/KEDA nice to have)
- CI/CD: Azure DevOps (YAML) and/or GitHub Actions
- Core Azure services: Compute, Networking (VNet, NSG, Load Balancing), Storage, Key Vault, ACR, App Service/Functions
- Observability: Azure Monitor, Log Analytics, Application Insights (KQL)
- Git proficiency, code reviews, and good collaboration/communication in English (B2+)
- (Optional) Terraform or Ansible
- (Optional) Security: Defender for Cloud, PIM, RBAC advanced, Secrets rotation
- (Optional) Data/Integration: APIM, Event Hub, Service Bus, SQL/Cosmos DB ops
- (Optional) Networking: App Gateway, Front Door, WAF, ExpressRoute/S2S VPN basics
- (Optional) Certifications: AZ‑104, AZ‑204, AZ‑400