Functie
Required Technical Expertise
Azure (hands-on production experience required)
• Governance: management groups, subscriptions, Azure Policy (built-in and custom), RBAC
design and troubleshooting.
• Identity: Microsoft Entra ID — group-based access models, app registrations, managed
identities, service principals.
• Networking: VNET peering/hub-spoke, Private Endpoints, Private DNS Zones, Azure Firewall,
Application Gateway, Azure Front Door, hybrid/on-prem DNS
integration.
• Landing zone concepts aligned with Microsoft Cloud Adoption Framework (CAF) archetypes.
• Exposure to Azure Databricks networking (VNet injection) is a plus.
Infrastructure as Code
• Solid production-level Terraform authoring — designing, versioning and publishing modules,
not just consuming them.
• Terraform Enterprise or Terraform Cloud experience specifically: workspaces, private module
registry, VCS-driven workflows, policy checks (Sentinel/OPA).
• Familiarity with Azure Verified Modules (AVM) and module lifecycle/versioning practices.
DevOps & Automation
• CI/CD pipeline experience (Azure DevOps preferred): build/release pipelines, YAML pipelines,
service connections.
• Scripting for automation and troubleshooting (PowerShell, Bash or Python).
• Comfortable working with KQL/Log Analytics for diagnostics is a plus.
Identity & Access Management
• Practical RBAC design and troubleshooting at enterprise scale (role assignments, group
nesting, inheritance issues, propagation delays).
• Experience managing access for both human users and service/application identities.
• Understanding of access governance concepts (ownership, periodic reviews, exception
handling).
Networking
• Solid understanding of enterprise DNS architecture, including hybrid on- prem/cloud
scenarios.
• Experience troubleshooting connectivity issues across VNETs, firewalls, and hybrid links.
Prior Experience we’re Looking For
• 4–7 years in a cloud platform engineering, DevOps or infrastructure engineering role, ideally
within a large, governed enterprise (not a greenfield/startup environment).
• Demonstrated experience operating (not just building) an Azure landing zone platform at
scale — supporting real application teams with real tickets.
• Prior role involving Terraform Enterprise/Cloud in a production capacity, ideally including
module authorship and CI/CD integration.
• Experience working across team boundaries (IAM, Networking, Security, external
partners/vendors) to resolve platform issues.
• Microsoft certifications (AZ-104, AZ-204, AZ-305, or Terraform Associate) are a strong plus
but not a substitute for demonstrable hands-on experience.