
Senior Azure Cloud Engineer
Posted Aug 5

Posted Aug 5
This is a fully remote position, open to applicants in United States.
• Act as the primary technical authority and subject matter expert for Azure cloud infrastructure and architecture.
• Establish cloud engineering standards, architectural frameworks, and governance protocols.
• Oversee cloud infrastructure initiatives from conception and planning through execution, delivery, and ongoing operations.
• Assist in shaping cloud strategy, architecture roadmap, and investment decisions for the platform.
• Mentor and guide Systems Administration and Information Security teams.
• Assess and recruit new talent for cloud engineering roles.
• Collaborate with Development teams to design and implement application infrastructure on Azure.
• Provide Tier 2/3 escalation support for intricate infrastructure and cloud-related challenges.
• Enforce and document compliance controls for HITRUST 11.3r2 and SOC2.
• Design, deploy, and manage secure Azure environments, encompassing hub-spoke networks, Virtual Networks, NSGs, Azure Firewall, Application Gateway, API Management, and Private Endpoints.
• Establish and enforce cloud governance, subscription oversight, Azure Policy, resource organization, tagging, and cost management.
• Implement Infrastructure as Code practices utilizing Terraform and/or Azure Bicep.
• Develop and manage CI/CD pipelines featuring automated security scanning, testing, and progressive delivery.
• Set up change management and release governance protocols.
• Direct cloud migrations, including workload evaluations, strategy formulation, cutover processes, validation, and legacy decommissioning.
• Create reusable Azure infrastructure patterns and templates for onboarding applications.
• Manage hybrid connectivity through ExpressRoute, VPN Gateway, and site-to-site connections.
• Design and maintain observability solutions for metrics, logs, alerting, and SLOs.
• Establish incident response protocols and oversee disaster recovery and business continuity planning.
• Manage Azure identity and access architecture, including Entra ID, RBAC, PIM, Key Vault, and Managed Identities.
• Implement cloud security measures, audit logging, evidence generation, and access review processes for HITRUST, SOC2, and HIPAA.
• Oversee DNS, certificate lifecycle, and network connectivity for healthcare data exchanges.
• Develop automation solutions using PowerShell, Python, or Bash.
• Define engineering standards, runbooks, documentation, vendor relationships, and SLAs.
• Maintain architecture diagrams, runbooks, standard operating procedures, and how-to guides.
• Provide after-hours support and on-call response for critical infrastructure incidents.
• Perform additional responsibilities as assigned.
• 7–10 years of experience in infrastructure, systems, or cloud engineering.
• 5 years of experience at a senior or principal level in Microsoft Azure.
• Proven experience in building or establishing a cloud engineering practice or function.
• In-depth knowledge of Azure networking, including hub-spoke topology, Virtual Networks, NSGs, Azure Firewall, Application Gateway, ExpressRoute, Private Endpoints, and DNS.
• Capability to independently architect Azure environments with a focus on governance, security, and operational frameworks.
• Expert-level experience with Infrastructure as Code using Terraform or Azure Bicep, covering module design, state management, CI/CD integration, and no-manual-change disciplines.
• Familiarity with CI/CD tools such as Azure DevOps, GitLab, or GitHub Actions, including automated security scanning and progressive delivery.
• Experience in leading cloud migration initiatives and legacy decommissioning efforts.
• Strong project leadership abilities to drive multiple complex initiatives with minimal supervision.
• Experience in mentoring and developing technical personnel across diverse teams.
• Proven experience in establishing incident response, disaster recovery, and business continuity practices with defined and tested RPO/RTO targets.
• Expert knowledge of Azure identity and security services, including Entra ID, RBAC, PIM, Key Vault, and Defender for Cloud.
• Strong fundamentals in networking and security, including network segmentation, secrets management, least-privilege access, and certificate lifecycle management.
• Proficient in PowerShell, Python, or Bash.
• Working knowledge of HITRUST, SOC2, and HIPAA compliance frameworks, with experience in building audit evidence processes.
• Excellent written communication skills and sound judgment under production pressure.
• Experience with Zero Trust Network Access solutions is preferred.
• Familiarity with Azure AI and platform services is preferred.
• Knowledge of healthcare data exchange standards such as EDI, HL7, or SFTP-based interfaces is preferred.
• Bachelor's degree in Information Technology, Computer Science, Information Systems, or a related field, or equivalent professional experience.
• AZ-104 (Azure Administrator Associate) certification is required — must be currently held.
• AZ-700 (Azure Network Engineer Associate) certification is required — must be currently held.
• AZ-305 (Azure Solutions Architect Expert) certification is required — must be currently held.
• AZ-400 (DevOps Engineer Expert) certification is strongly preferred.
• Ability to work at a desk and utilize a computer, telephone, and basic office equipment.
• Must pass a background check prior to employment.
• Must complete a drug screening after hire.
• Must agree to necessary compliance regulations on the first day of employment.
• Must adhere to applicable HIPAA regulations and company confidentiality, privacy, and security policies.
• A competitive salary package.
• Healthcare insurance coverage.
• Vision insurance benefits.
• Dental insurance plans.
• Generous 401(k) matching contributions.
• Paid vacation days.
• Personal time off.
• Paid holidays.
• Opportunities for growth and training.
• Award-winning remote work environment.
SPD Technology
Totara
Vesta Software Group
Elfonze Technologies
Get handpicked remote jobs straight to your inbox weekly.