About the Role
Our client is seeking an Infrastructure Engineer to serve as a subject matter expert for its Azure and hybrid cloud environment. This is a hands-on engineering role with a strong focus on Azure infrastructure, enterprise networking, hybrid connectivity, automation, and infrastructure modernization.
The Azure Infrastructure Engineer will partner closely with IT leadership, internal engineering teams, Cybersecurity, and a managed service provider (MSP) to design, maintain, troubleshoot, and continuously improve the environment. The role will also support emerging enterprise AI initiatives, including Microsoft Copilot technologies and Azure AI services, with an emphasis on secure infrastructure and data access.
Responsibilities
- Serve as the Azure infrastructure and networking SME, managing core Azure architecture including subscriptions, RBAC, Azure Policy, virtual machines, storage, Key Vault, Backup, Site Recovery, Azure Monitor, and Log Analytics.
- Design, operate, and troubleshoot Azure and hybrid networking, including VNets, peering, routing, VPN/ExpressRoute, BGP, Azure Firewall or NVAs, NSGs, Private Endpoints, Private DNS, and hybrid connectivity.
- Lead infrastructure modernization, workload migrations, disaster recovery planning, and continuous improvement initiatives using Azure landing zone and Cloud Adoption Framework principles.
- Partner with Cybersecurity to incorporate Zero Trust principles, identity controls, vulnerability remediation, Microsoft Defender recommendations, logging, and security requirements into infrastructure solutions.
- Build and automate infrastructure using Infrastructure-as-Code and scripting while supporting Microsoft cloud, automation, and AI platforms such as PowerShell, Azure CLI, Terraform/Bicep, Power Automate, Microsoft Fabric, Copilot Studio, and Azure AI services.
Requirements
- Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, or a related discipline, or equivalent professional experience, with 5+ years of infrastructure engineering experience and 3+ years supporting production Azure environments.
- Advanced Azure networking expertise, including VNets, peering, UDRs, VPN/ExpressRoute, BGP, firewalls/NVAs, NSGs, Private Endpoints, DNS, TCP/IP, routing, and subnetting.
- Strong experience with Windows Server, Active Directory, Microsoft Entra ID, hybrid identity, RBAC, Conditional Access, and enterprise hybrid cloud environments.
- Proficiency with PowerShell and Infrastructure-as-Code technologies such as Terraform, Bicep, or ARM templates, along with experience automating and troubleshooting complex cloud infrastructure.
- Working knowledge of Zero Trust, Microsoft Defender technologies, and enterprise AI platforms such as Microsoft 365 Copilot, Copilot Studio, or Azure AI services, plus strong communication skills and experience collaborating with MSPs or third-party engineering partners.
- Experience with Azure Virtual WAN, Azure Virtual Desktop, Microsoft Sentinel, Defender XDR, Microsoft Purview, Intune, Microsoft Fabric, Power BI, Azure AI Search/RAG, Git-based CI/CD workflows, and cloud cost optimization is a plus. Relevant Microsoft Azure certifications such as AZ-104, AZ-700, AZ-500, or AZ-305 are also highly valued.