Senior Cloud Center of Excellence Azure Platform Engineer

Il y a 2 heures

Antwerp, Flanders, Belgique XQUISIT Temps plein
We are looking for a senior engineer to help clean up the technical depth — from landing zone architecture to Terraform Enterprise module engineering, networking design and enterprise system integrations. This is a medior/senior individual contributor role: you're expected to work independently on well-defined scopes, but you'll be ramping up within an existing team structure rather than owning the full platform strategy from day one. Day-to-Day Responsibilities
- Act as second-line escalation for Azure platform issues (RBAC, DNS, VNET/Private Endpoint connectivity, AD integration, Terraform Enterprise
- runs) and write up root cause analyses.
- Maintain and incrementally improve landing zones, archetypes, Azure Policy and naming/tagging standards; process governance exception requests.
- Build, version and maintain Terraform modules; review consumer changes and evaluate Azure Verified Modules (AVM) as replacements for custom
- modules.
- Handle recurring IAM tickets (RBAC assignments, group memberships, access troubleshooting) and contribute to cleanup of legacy/exception-based
- access.
- Support DNS/connectivity requests and troubleshooting across the hybrid environment within existing patterns.
- Maintain and troubleshoot existing PowerShell automation scripts used across platform operations.
- Keep governance documentation current and contribute to internal Terraform Enterprise workshops and application team enablement. Required Technical Expertise Azure (hands-on production experience required)
- Governance: management groups, subscriptions, Azure Policy (built-in and custom), RBAC design and troubleshooting.
- Identity: Microsoft Entra ID — group-based access models, app registrations, managed identities, service principals.
- Networking: VNET peering/hub-spoke, Private Endpoints, Private DNS Zones, Azure Firewall, Application Gateway, Azure Front Door, hybrid/on-prem DNS
- integration.
- Landing zone concepts aligned with Microsoft Cloud Adoption Framework (CAF) archetypes.
- Exposure to Azure Databricks networking (VNet injection) is a plus. Infrastructure as Code
- Solid production-level Terraform authoring — designing, versioning and publishing modules, not just consuming them.
- Terraform Enterprise or Terraform Cloud experience specifically: workspaces, private module registry, VCS-driven workflows, policy checks (Sentinel/OPA).
- Familiarity with Azure Verified Modules (AVM) and module lifecycle/versioning practices. DevOps & Automation
- CI/CD pipeline experience (Azure DevOps preferred): build/release pipelines, YAML pipelines, service connections.
- Scripting for automation and troubleshooting (PowerShell, Bash or Python).
- Comfortable working with KQL/Log Analytics for diagnostics is a plus. Identity & Access Management
- Practical RBAC design and troubleshooting at enterprise scale (role assignments, group nesting, inheritance issues, propagation delays).
- Experience managing access for both human users and service/application identities.
- Understanding of access governance concepts (ownership, periodic reviews, exception handling). Networking
- Solid understanding of enterprise DNS architecture, including hybrid on
- prem/cloud scenarios.
- Experience troubleshooting connectivity issues across VNETs, firewalls, and hybrid links. Prior Experience we're Looking For
- 4–7 years in a cloud platform engineering, DevOps or infrastructure engineering role, ideally within a large, governed enterprise (not a
- greenfield/startup environment).
- Demonstrated experience operating (not just building) an Azure landing zone platform at scale — supporting real application teams with real tickets.
- Prior role involving Terraform Enterprise/Cloud in a production capacity, ideally including module authorship and CI/CD integration.
- Experience working across team boundaries (IAM, Networking, Security, external partners/vendors) to resolve platform issues.
- Microsoft certifications (AZ-104, AZ-204, AZ-305, or Terraform Associate) are a strong plus but not a substitute for demonstrable hands-on experience. Personal Characteristics
- Can operate independently on a well-scoped task from day one — this is a "plug in and go"; role, not a ramp-up position.
- Comfortable working in a live, legacy-entangled environment where not everything is fully standardized yet.
- Detail-oriented, especially around governance, documentation and naming/tagging consistency.
- Good communicator — able to support application teams directly without needing everything translated by the platform lead.
- Takes ownership of tickets/incidents end-to-end rather than escalating prematurely. Important: we are looking for 2 resources for a temporary 6 month assignment. The place of work can be Belgium or Czech Republic.