Title: Senior Cloud Infrastructure Engineer
Duration: FTE/Permanent
Location: Hybrid in NYC
Salary: 170k-200k +bonus
A direct client is seeking a Senior Cloud Infrastructure Engineer / Senior Infrastructure Engineer – Cloud & Hybrid to join our team at the Associate Director (or Director) level. The ideal candidate started their career as an Infrastructure Engineer and has since transitioned into a strong Cloud Engineer, with core/fundamental Windows background still intact.
This candidate should be strongest in Azure infrastructure, networking, identity, automation, security, and cloud operations — while retaining enough Windows, VMware, and Active Directory knowledge to troubleshoot across the full hybrid stack. Candidates with less experience but strong cloud fundamentals may be considered at a slightly more junior level.
Approximate scope of role:
- 50% Cloud Infrastructure / Azure
- 20% Automation / IaC / DevOps
- 15% Windows / Microsoft Hybrid Infrastructure
- 10% Cloud Security / Identity / Governance
- 5% VMware / Citrix / Storage / Traditional Infrastructure
This person must understand traditional infrastructure well enough to design and support hybrid solutions.
Responsibilities
- Design, implement, and support Azure infrastructure including Virtual Machines and Storage Accounts
- Architect and manage cloud networking: Virtual Networks, Subnets, NSGs, Route Tables, Private Endpoints, and Private DNS
- Configure and maintain Azure Firewall, VPN/ExpressRoute connectivity, Load Balancers, and Application Gateway
- Manage business continuity and monitoring via Azure Backup, Azure Site Recovery, and Azure Monitor
- Administer identity and access using Entra ID, RBAC, and Managed Identities
- Implement tagging, governance, subscription, and management group structures
- Evaluate application architectures to determine networking, identity, connectivity, monitoring, and recovery requirements
- Work with PaaS services including Function Apps, Logic Apps, Container Apps, AKS/Kubernetes, App Services, managed databases, API Management, and Private Link
- Design and troubleshoot modern authentication scenarios (e.g., Managed Identity → app registration → permissions → token audience → authorization)
- Build and maintain Infrastructure as Code using Terraform, Bicep, ARM, or Pulumi
- Maintain working knowledge of Windows Server, Active Directory, and DNS to support hybrid environments
- Collaborate across teams to troubleshoot issues spanning cloud, Windows, VMware, and networking domains
Required Skills & Qualifications
- Strong, hands-on experience with core Azure services:
- Azure Virtual Machines, Storage Accounts
- Virtual Networks, Subnets, NSGs, Route Tables, Private Endpoints, Private DNS
- Azure Firewall, VPN/ExpressRoute concepts, Load Balancers, Application Gateway
- Azure Backup, Azure Site Recovery, Azure Monitor
- Entra ID, RBAC, Managed Identities
- Tagging, governance, subscriptions/management groups
- Meaningful experience with several PaaS services such as Function Apps, Logic Apps, Container Apps, AKS/Kubernetes, App Services, managed databases, API Management, or Private Link
- Strong understanding of cloud networking concepts and design
- Strong identity knowledge, including modern authentication patterns (Managed Identity, app registrations, token-based auth) versus traditional Windows authentication
- Experience with Infrastructure as Code — Terraform, Bicep, ARM, or Pulumi (Terraform or Bicep preferred)
- Working knowledge of Windows Server, Active Directory, and DNS
- Demonstrated career transition from traditional infrastructure engineering into cloud engineering
Preferred Skills & Qualifications
- Terraform or Bicep specifically (over ARM/Pulumi)
- Broader PaaS/application architecture exposure
- VMware, Citrix, or traditional storage experience
- Background supporting hybrid (on-prem + cloud) environments at scale