Senior Cloud Center of Excellence Azure Platform Engineer
Il y a 2 heures
Antwerp, Flanders, Belgique
XQUISIT
Temps plein
Gratuit avec email ou Google
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
Gratuit avec email ou Google
We are looking for a senior engineer to help clean up the technical depth — from landing zone architecture to Terraform Enterprise module engineering, networking
design and enterprise system integrations. This is a medior/senior individual contributor role: you're expected to work independently on well-defined scopes, but you'll be ramping up within an existing team structure rather than owning the full platform strategy from day one.
Day-to-Day Responsibilities
- Act as second-line escalation for Azure platform issues (RBAC, DNS, VNET/Private Endpoint connectivity, AD integration, Terraform Enterprise
- runs) and write up root cause analyses.
- Maintain and incrementally improve landing zones, archetypes, Azure Policy and naming/tagging standards; process governance exception requests.
- Build, version and maintain Terraform modules; review consumer changes and evaluate Azure Verified Modules (AVM) as replacements for custom
- modules.
- Handle recurring IAM tickets (RBAC assignments, group memberships, access troubleshooting) and contribute to cleanup of legacy/exception-based
- access.
- Support DNS/connectivity requests and troubleshooting across the hybrid environment within existing patterns.
- Maintain and troubleshoot existing PowerShell automation scripts used across platform operations.
- Keep governance documentation current and contribute to internal Terraform Enterprise workshops and application team enablement. Required Technical Expertise Azure (hands-on production experience required)
- Governance: management groups, subscriptions, Azure Policy (built-in and custom), RBAC design and troubleshooting.
- Identity: Microsoft Entra ID — group-based access models, app registrations, managed identities, service principals.
- Networking: VNET peering/hub-spoke, Private Endpoints, Private DNS Zones, Azure Firewall, Application Gateway, Azure Front Door, hybrid/on-prem DNS
- integration.
- Landing zone concepts aligned with Microsoft Cloud Adoption Framework (CAF) archetypes.
- Exposure to Azure Databricks networking (VNet injection) is a plus. Infrastructure as Code
- Solid production-level Terraform authoring — designing, versioning and publishing modules, not just consuming them.
- Terraform Enterprise or Terraform Cloud experience specifically: workspaces, private module registry, VCS-driven workflows, policy checks (Sentinel/OPA).
- Familiarity with Azure Verified Modules (AVM) and module lifecycle/versioning practices. DevOps & Automation
- CI/CD pipeline experience (Azure DevOps preferred): build/release pipelines, YAML pipelines, service connections.
- Scripting for automation and troubleshooting (PowerShell, Bash or Python).
- Comfortable working with KQL/Log Analytics for diagnostics is a plus. Identity & Access Management
- Practical RBAC design and troubleshooting at enterprise scale (role assignments, group nesting, inheritance issues, propagation delays).
- Experience managing access for both human users and service/application identities.
- Understanding of access governance concepts (ownership, periodic reviews, exception handling). Networking
- Solid understanding of enterprise DNS architecture, including hybrid on
- prem/cloud scenarios.
- Experience troubleshooting connectivity issues across VNETs, firewalls, and hybrid links. Prior Experience we're Looking For
- 4–7 years in a cloud platform engineering, DevOps or infrastructure engineering role, ideally within a large, governed enterprise (not a
- greenfield/startup environment).
- Demonstrated experience operating (not just building) an Azure landing zone platform at scale — supporting real application teams with real tickets.
- Prior role involving Terraform Enterprise/Cloud in a production capacity, ideally including module authorship and CI/CD integration.
- Experience working across team boundaries (IAM, Networking, Security, external partners/vendors) to resolve platform issues.
- Microsoft certifications (AZ-104, AZ-204, AZ-305, or Terraform Associate) are a strong plus but not a substitute for demonstrable hands-on experience. Personal Characteristics
- Can operate independently on a well-scoped task from day one — this is a "plug in and go"; role, not a ramp-up position.
- Comfortable working in a live, legacy-entangled environment where not everything is fully standardized yet.
- Detail-oriented, especially around governance, documentation and naming/tagging consistency.
- Good communicator — able to support application teams directly without needing everything translated by the platform lead.
- Takes ownership of tickets/incidents end-to-end rather than escalating prematurely. Important: we are looking for 2 resources for a temporary 6 month assignment. The place of work can be Belgium or Czech Republic.
- Act as second-line escalation for Azure platform issues (RBAC, DNS, VNET/Private Endpoint connectivity, AD integration, Terraform Enterprise
- runs) and write up root cause analyses.
- Maintain and incrementally improve landing zones, archetypes, Azure Policy and naming/tagging standards; process governance exception requests.
- Build, version and maintain Terraform modules; review consumer changes and evaluate Azure Verified Modules (AVM) as replacements for custom
- modules.
- Handle recurring IAM tickets (RBAC assignments, group memberships, access troubleshooting) and contribute to cleanup of legacy/exception-based
- access.
- Support DNS/connectivity requests and troubleshooting across the hybrid environment within existing patterns.
- Maintain and troubleshoot existing PowerShell automation scripts used across platform operations.
- Keep governance documentation current and contribute to internal Terraform Enterprise workshops and application team enablement. Required Technical Expertise Azure (hands-on production experience required)
- Governance: management groups, subscriptions, Azure Policy (built-in and custom), RBAC design and troubleshooting.
- Identity: Microsoft Entra ID — group-based access models, app registrations, managed identities, service principals.
- Networking: VNET peering/hub-spoke, Private Endpoints, Private DNS Zones, Azure Firewall, Application Gateway, Azure Front Door, hybrid/on-prem DNS
- integration.
- Landing zone concepts aligned with Microsoft Cloud Adoption Framework (CAF) archetypes.
- Exposure to Azure Databricks networking (VNet injection) is a plus. Infrastructure as Code
- Solid production-level Terraform authoring — designing, versioning and publishing modules, not just consuming them.
- Terraform Enterprise or Terraform Cloud experience specifically: workspaces, private module registry, VCS-driven workflows, policy checks (Sentinel/OPA).
- Familiarity with Azure Verified Modules (AVM) and module lifecycle/versioning practices. DevOps & Automation
- CI/CD pipeline experience (Azure DevOps preferred): build/release pipelines, YAML pipelines, service connections.
- Scripting for automation and troubleshooting (PowerShell, Bash or Python).
- Comfortable working with KQL/Log Analytics for diagnostics is a plus. Identity & Access Management
- Practical RBAC design and troubleshooting at enterprise scale (role assignments, group nesting, inheritance issues, propagation delays).
- Experience managing access for both human users and service/application identities.
- Understanding of access governance concepts (ownership, periodic reviews, exception handling). Networking
- Solid understanding of enterprise DNS architecture, including hybrid on
- prem/cloud scenarios.
- Experience troubleshooting connectivity issues across VNETs, firewalls, and hybrid links. Prior Experience we're Looking For
- 4–7 years in a cloud platform engineering, DevOps or infrastructure engineering role, ideally within a large, governed enterprise (not a
- greenfield/startup environment).
- Demonstrated experience operating (not just building) an Azure landing zone platform at scale — supporting real application teams with real tickets.
- Prior role involving Terraform Enterprise/Cloud in a production capacity, ideally including module authorship and CI/CD integration.
- Experience working across team boundaries (IAM, Networking, Security, external partners/vendors) to resolve platform issues.
- Microsoft certifications (AZ-104, AZ-204, AZ-305, or Terraform Associate) are a strong plus but not a substitute for demonstrable hands-on experience. Personal Characteristics
- Can operate independently on a well-scoped task from day one — this is a "plug in and go"; role, not a ramp-up position.
- Comfortable working in a live, legacy-entangled environment where not everything is fully standardized yet.
- Detail-oriented, especially around governance, documentation and naming/tagging consistency.
- Good communicator — able to support application teams directly without needing everything translated by the platform lead.
- Takes ownership of tickets/incidents end-to-end rather than escalating prematurely. Important: we are looking for 2 resources for a temporary 6 month assignment. The place of work can be Belgium or Czech Republic.