Cloud Engineer
About the Role
The Cloud Engineer is responsible for designing, implementing, and managing cloud solutions based on Microsoft Azure. This is a hands-on role serving as a key technical contributor to our cloud platform spanning Platform as a Service (PaaS) services, Azure Kubernetes Service (AKS), networking, and ensuring the scalability, reliability, and security of our Azure cloud infrastructure.
This role works closely with cross-functional teams including application development, security, and operations to build resilient cloud environments that meet organizational needs and compliance obligations including SOC 2 and HIPAA.
What You’ll Do
Infrastructure as Code & Automation
Design and deploy Azure cloud solutions including virtual machines, virtual networks, storage accounts, databases, and PaaS services to meet business and technical objectives
Configure and optimize Azure resources for performance, scalability, and cost-efficiency using automation tools, scripting languages, and infrastructure as code (IaC) techniques including Terraform and Bicep
Manage Azure DevOps pipelines and CI/CD workflows to automate software delivery, infrastructure provisioning, and deployment activities
Azure PaaS & Platform Services
Design and operate PaaS workloads using Azure App Service, Azure Functions, Azure SQL, Azure Service Bus, Azure Storage, and Event Hub
Evaluate and onboard new PaaS offerings aligned with workload requirements, cost targets, and compliance obligations
Manage Azure Key Vault, App Configuration, and Managed Identities for secrets and configuration lifecycle
Implement and manage Azure governance policies, security controls, and compliance standards to ensure confidentiality, integrity, and availability of cloud resources
Kubernetes & Container Platform
Administer AKS clusters including node pool scaling, upgrades, and RBAC configuration
Implement and maintain ingress controllers, network policies, workload identity, and pod security standards
Integrate AKS with Azure Container Registry, Key Vault CSI Driver, External Secrets Operator, and monitoring tooling
Collaborate with development teams on Helm chart packaging, GitOps patterns, and service mesh considerations
Networking
Design and manage Azure virtual networks, subnets, NSGs, route tables, VNet peering, and Private Endpoints
Configure and maintain Azure Firewall, Application Gateway, Azure Front Door, and VPN Gateway
Implement and troubleshoot DNS architecture including Azure Private DNS Zones and hybrid DNS resolution
Support hub-and-spoke or Virtual WAN topologies across production, staging, and development environments
Security & Compliance
Apply zero-trust networking principles, least-privilege IAM, and conditional access policies across the Azure tenant
Configure and tune Microsoft Defender for Cloud, Microsoft Sentinel integration, and Azure Security Center recommendations
Support SOC 2 and HIPAA compliance obligations through evidence collection, control implementation, and audit readiness
Participate in vulnerability management, patch lifecycle governance, and security incident response
Monitoring, Documentation & Operations
Build and maintain monitoring, alerting, and dashboards using Azure Monitor, Log Analytics, and Application Insights
Monitor and troubleshoot Azure cloud environments, proactively identifying and resolving performance issues, availability disruptions, and security vulnerabilities
Participate in cloud migration projects, workload migrations, and hybrid cloud integrations, ensuring seamless transitions and minimal disruption to business operations
Document Azure cloud configurations, procedures, and troubleshooting steps, maintaining accurate records and knowledge base articles to facilitate knowledge sharing
What You’ll Need
Bachelor's degree in Computer Science, Information Technology, or a related field, or equivalent experience or relevant industry certifications.
3+ years of experience in a cloud engineering role with demonstrated proficiency in implementing, designing, and managing Microsoft Azure solutions
Deep understanding of Azure cloud services including Azure Virtual Machines, Azure Networking, Azure Storage, Azure Databases, Azure Security, and Azure DevOps
Proficiency in Azure infrastructure as code tools including Terraform (required) and Bicep or ARM templates
Demonstrated knowledge of cloud security best practices, identity and access management (IAM), encryption, network security, and compliance standards (HIPAA, SOC 2)
Experience operating AKS or self-managed Kubernetes in production environments
Solid Azure networking fundamentals including VNets, NSGs, Private Endpoints, DNS, and load balancing
Familiarity with Azure Entra ID, RBAC, Managed Identities, and service principals
Experience building CI/CD pipelines with Azure DevOps (or equivalent, e.g., GitLab CI)
Scripting proficiency in Bash and/or Python for automation and tooling
Strong communication and collaboration skills with the ability to interact effectively with cross-functional teams, stakeholders, and vendors
Nice to Have
Healthcare, SaaS, or regulated industry experience
Azure certifications such as AZ-104, AZ-305, AZ-500, AZ-700, or CKA/CKAD
Experience with GitOps tooling such as Flux or ArgoCD
Familiarity with policy-as-code tools including Checkov, OPA/Gatekeeper, and Azure Policy
Exposure to secrets management platforms such as HashiCorp Vault, Azure Key Vault, and External Secrets Operator
Experience with FinOps practices and Azure cost optimization tooling
Familiarity with Windows Server, Active Directory, and hybrid identity scenarios
Pay Transparency
Office Ally is committed to fair and equitable compensation practices in alignment with pay transparency laws. Compensation for this position may vary based on individual skills, experience, and location. In addition to base pay, employees may be eligible for performance-based bonuses and a comprehensive benefits package, including medical, dental, and vision coverage, 401(k) with company match, paid time off, and other benefits. Actual compensation will be determined considering the candidate’s qualifications, relevant experience, and internal equity.
Office Ally Pay Transparency
$100,000—$125,000 USD