Senior Terraform Infrastructure Engineer, Azure Migration
About the Role
Blueprint is hiring a Senior Terraform Infrastructure Engineer to help modernize a business-critical application currently running on Azure Kubernetes Service and virtual machines. The project will move suitable APIs, web applications, background workers, and databases to Azure Container Apps and Azure SQL, introducing a more efficient serverless architecture with capabilities such as event-driven scaling and scale-to-zero.
You’ll take ownership of the infrastructure that makes this migration possible, translating the target architecture into secure, reusable Terraform and helping guide key platform decisions along the way. This includes evaluating complex AKS and VM workloads, identifying what can be modernized, and determining what should remain on its current platform because of networking, storage, operating system, or Kubernetes-specific dependencies. You’ll collaborate closely with engineering, security, data, and operations teams throughout assessment, design, testing, cutover, and rollback.
What You'll Do
Lead the Terraform architecture for migration landing zones, networking, identity, security, application platforms, databases, monitoring, and environment promotion.
Build reusable Terraform modules and environments for Azure Virtual Networks, Private DNS, Private Endpoints, Network Security Groups, Azure Container Registry, Azure Container Apps, Azure SQL, Key Vault, managed identities, monitoring, and access controls.
Manage Terraform providers, remote state, locking, environment separation, module versioning, drift detection, policy checks, plan reviews, and approved CI/CD promotion.
Evaluate AKS workloads and troubleshoot control-plane interactions, node pools, scheduling, taints, affinity, probes, Services, Ingress, DNS, network policies, CNI, storage, StatefulSets, DaemonSets, operators, custom resource definitions, admission controls, and workload identity.
Assess containerized APIs and web applications for runtime dependencies, state management, configuration, database connections, health endpoints, startup behavior, scaling, ingress, egress, and external service dependencies.
Assess Windows- and Linux-based applications hosted on Azure virtual machines, including scheduled tasks, local file dependencies, operating system integrations, certificates, ports, service accounts, and legacy deployment processes.
Design Azure Container Apps environments for APIs, web applications, workers, jobs, and event-driven services using revisions, readiness checks, traffic splitting, rollback, KEDA, and scale-to-zero capabilities where appropriate.
Containerize VM-hosted applications using secure OCI images, multi-stage builds, non-root execution, vulnerability scanning, structured logging, and reliable health probes.
Determine when workloads must remain on AKS or virtual machines because of node dependencies, privileged access, operators, custom networking, persistent volumes, or operating system requirements.
Plan migrations from SQL Server or Azure SQL hosted on virtual machines to Azure SQL Database, Elastic Pools, SQL Managed Instance, or a retained virtual machine.
Manage database connections, validation, backups, cutover planning, rollback procedures, and measured capacity and performance sizing.
Establish observability, alerts, operational runbooks, security evidence, load testing, failure testing, and rollback procedures.
Partner with engineering, security, data, and operations stakeholders to document decisions and deliver a controlled migration.
What You'll Bring
At least eight years of experience in infrastructure engineering, platform engineering, cloud engineering, DevOps, or solution architecture.
At least five years of experience delivering production Azure environments with Terraform.
Expert knowledge of Terraform architecture and infrastructure as code, supported by at least seven years of relevant experience.
Expert knowledge of AKS internals and Kubernetes troubleshooting, supported by at least seven years of relevant experience.
Expert experience supporting containerized APIs and web applications, with at least seven years of relevant experience.
At least six years of experience with Azure migration architecture and platform selection.
At least five years of experience modernizing and migrating applications hosted on Azure virtual machines.
At least five years of experience with Docker or OCI images and container security.
At least four years of experience designing or supporting solutions using Azure Container Apps.
At least five years of experience with Azure networking and private connectivity.
At least four years of experience with managed identities, Microsoft Entra ID, Azure Key Vault, and role-based access control.
At least five years of experience with SQL Server or Azure SQL hosted on virtual machines, including migration and performance planning.
At least five years of experience with CI/CD, release automation, and rollback procedures.
At least four years of experience with Azure Monitor, Log Analytics, and production operations.
Demonstrated ownership of Terraform delivery for at least two VM- or AKS-based application and database migrations, including testing, security review, cutover, and rollback.
Ability to read application code and Kubernetes manifests to diagnose API, web runtime, networking, identity, database, and scaling issues.
Strong technical writing and communication skills, with the ability to work across engineering, security, data, and operations teams.
Preferred Qualifications
Microsoft Certified: Azure Solutions Architect Expert.
Microsoft Certified: DevOps Engineer Expert.
Certified Kubernetes Administrator.
Compensation
At Blueprint, we strive to offer competitive pay that reflects the value of our team members. Compensation for this role is influenced by a variety of factors, including skills, education, responsibilities, experience, and geographic market.
For candidates based in Washington State, the anticipated compensation range is $143,400 to $172,100 USD annually, with a midpoint of $157,600. Please note that we typically do not hire new employees at the top of the posted range. Actual starting pay will be determined based on experience, skills, and internal equity. The final compensation and job title may vary depending on the selected candidate’s qualifications.
Location and Employment Structure
This role is open exclusively to candidates in the Seattle metropolitan area. The selected candidate must work onsite at the client’s Bellevue, Washington location five days per week.
This is a full-time engagement expected to last at least six months, with the potential for extension.