Senior Azure Cloud Engineer Architect
Richardson, TX - USA
Job Summary
Senior Azure Cloud Engineer / Architect
Department:Information Technology - Infrastructure & Cloud Services
Job Level:Senior / Lead Individual Contributor
Reports To:Director of IT Infrastructure & Cloud Services
Environment:Global / Multi-Region Enterprise
Location: If near Richardson TX can come into office 3 days a week. If not remote is fine.
Start/Length: ASAP and 6 months engagement possibly more.
Position Summary
We are seeking a highly experiencedSenior Azure Cloud Engineer / Architectto design build secure operate and continuously improve Microsoft Azure infrastructure supporting a global multi-site organization.
This is asenior-level hands-on technical rolerequiring broad expertise across the entire Azure cloud stack including networking compute identity and access management security storage backup and disaster recovery monitoring governance automation and cost optimization.
The successful candidate will serve as asenior technical authority for Microsoft Azure capable of both designing enterprise cloud architecture and directly implementing configuring troubleshooting securing and supporting Azure infrastructure while also being able to mentor junior cloud engineers. The role will collaborate with Network Security Server Application Database and IT teams across multiple countries and regions/
Key Responsibilities
Azure Architecture & Infrastructure
- Design implement and support enterprise-scale Azure environments across multiple geographic regions.
- Develop and maintainAzure Landing Zones management groups subscriptions resource groups naming standards tagging and governance models.
- Architect highly available resilient secure and scalable cloud infrastructure aligned with Microsoft best practices.
- Build and administer Windows and LinuxAzure Virtual Machines managed disks images snapshots Availability Zones Availability Sets and VM Scale Sets.
- Establish standardized deployment patterns for production development test and disaster recovery environments.
- Serve as a senior escalation point for complex Azure infrastructure and architecture issues.
Azure Networking
Design implement and troubleshoot enterprise Azure networking technologies including:
- Virtual Networks (VNets) subnets VNet peering and global peering
- Hub-and-spoke architectures and Azure Virtual WAN
- Network Security Groups (NSGs) and User Defined Routes (UDRs)
- Azure Firewall Application Gateway and Web Application Firewall (WAF)
- Azure Front Door Load Balancers NAT Gateway and Traffic Manager
- Private Link Private Endpoints and Service Endpoints
- Azure DNS and Private DNS Zones
- ExpressRoute Site-to-Site VPN and Point-to-Site VPN
- Hybrid cloud global WAN and SD-WAN connectivity
- Network segmentation and Zero Trust architecture
Troubleshoot complex routing DNS firewall VPN peering private endpoint and application connectivity issues across Azure and on-premises environments.
Identity IAM & Security
- Design and administerMicrosoft Entra ID Azure RBAC Conditional Access Privileged Identity Management (PIM) Managed Identities Service Principals and Application Registrations.
- Implement least-privilege and Zero Trust access models.
- Design and maintain security controls usingMicrosoft Defender for Cloud Azure Firewall WAF DDoS Protection Key Vault Azure Policy encryption private endpoints and security monitoring.
- Partner with Cybersecurity teams to remediate vulnerabilities configuration issues security recommendations and audit findings.
- Ensure Azure environments comply with corporate security standards and applicable regulatory requirements.
Governance & Resource Management
- Manage Azure management groups subscriptions resource groups policies resource locks tagging and RBAC.
- Establish enterprise cloud governance standards and deployment guardrails.
- Maintain appropriate separation of duties and administrative boundaries.
- Implement Azure Policy and standardized security and configuration baselines.
- Ensure consistent resource ownership lifecycle management and operational standards across the global Azure environment.
Storage Backup & Disaster Recovery
- Design and support Azure Storage Accounts Blob Storage Azure Files Managed Disks Azure NetApp Files File Sync encryption and storage replication.
- Architect and administerAzure Backup Recovery Services Vaults and Azure Site Recovery.
- Design multi-region disaster recovery solutions based on defined RTO and RPO requirements.
- Conduct periodic recovery testing and ensure critical workloads can recover from regional or infrastructure failures.
Monitoring Automation & Infrastructure as Code
- Design monitoring and alerting usingAzure Monitor Log Analytics Application Insights Network Watcher Azure Service Health Alerts Action Groups and Workbooks.
- Drive anInfrastructure-as-Code-first approachto improve deployment consistency security repeatability and recoverability.
Hybrid Global Infrastructure & Cloud Operations
- Integrate Azure with global data centers corporate offices manufacturing facilities warehouses and other enterprise locations.
- Support ExpressRoute IPSec VPN SD-WAN hybrid DNS Active Directory/Entra ID and global routing architectures.
- Understand multi-region architectures data residency requirements and global disaster recovery considerations.
- Monitor Azure consumption and optimize cloud costs through right-sizing Reservations Savings Plans resource cleanup budgets alerts and Azure Advisor recommendations.
- Create and maintain architecture diagrams network diagrams build documentation operational procedures disaster recovery documentation and cloud standards.
Required Qualifications
- 8 yearsof enterprise infrastructure cloud engineering systems engineering or related experience.
- 5 years of hands-on Microsoft Azure experiencesupporting enterprise environments.
- Advanced knowledge ofAzure networking including VNets peering routing firewalls load balancing private endpoints VPNs DNS and ExpressRoute.
- Advanced knowledge ofAzure Virtual Machines compute storage availability and performance optimization.
- Strong knowledge ofMicrosoft Entra ID IAM RBAC PIM Conditional Access Managed Identities and Service Principals.
- Strong understanding of Azure security architecture including Defender for Cloud Azure Firewall WAF Key Vault Azure Policy and Zero Trust principles.
- Experience withAzure Landing Zones management groups subscriptions resource groups governance and enterprise cloud standards.
- Experience with Azure Backup Site Recovery Azure Monitor and Log Analytics.
- Strong understanding of enterprise networking technologies including TCP/IP routing DNS DHCP firewalls VPNs and load balancing.
- Strong Windows Server knowledge and working knowledge of Linux.
- Demonstrated experience troubleshooting complex business-critical production environments.
- Strong communication skills and experience working with globally distributed technical teams.
Preferred Qualifications
- Microsoft Certified:Azure Solutions Architect Expert
- Microsoft Certified:Azure Administrator Associate
- Microsoft Certified:Azure Network Engineer Associate
- Microsoft Certified:Azure Security Engineer Associate
- Terraform Associate or equivalent Infrastructure as Code experience
- Experience with Azure DevOps Azure SQL Azure Virtual Desktop and CI/CD.
- Experience supporting large multinational organizations manufacturing environments global data centers and hybrid cloud architectures.
Key Success Characteristics
The ideal candidate is ahands-on senior cloud technologistcapable of moving seamlessly between architecture and engineering. This individual can design an enterprise Azure solution at the architectural level and then work directly within Azure to build secure troubleshoot automate and optimize it.
The successful candidate will demonstrate strong technical ownership exceptional troubleshooting skills a security-first mindset and the ability to lead technical design discussions and mentor other engineers. They must be comfortable working across networking compute identity security storage automation and traditional infrastructure while communicating effectively with technical teams and IT leadership.
The primary objective of this role is to ensure the organizations Microsoft Azure environment is secure scalable resilient standardized automated cost-effective and capable of supporting a 247 global enterprise.
Required Skills:
azure