AF Group
Cloud Infrastructure Engineer III
AF Group, Kalamazoo, Michigan, United States, 49006
This individual will primarily focus on implementing Azure-based cloud solutions, using Infrastructure-as-Code (IaC) tools like Terraform, while also serving as an escalation point for troubleshooting and resolving complex infrastructure-related issues. The ideal candidate will have deep expertise in Azure cloud networking, virtualization, DevOps practices, and Identity and Access Management (IAM). You will work closely with DevOps teams to implement Terraform modules for Azure, assist in cloud migrations to Azure, and manage Role-Based Access Control (RBAC) to secure Azure resources. This role provides an opportunity to play a critical part in building scalable, secure, and automated cloud solutions on Microsoft Azure. RESPONSIBILITIES Cloud Infrastructure Implementation: Design, deploy, and manage infrastructure on Azure, focusing on scalability, security, and automation. Use Terraform and other Infrastructure-as-Code (IaC) tools to implement and manage Azure cloud resources, ensuring modularity, reusability, and ease of consumption by other teams. Assist in cloud migration projects from on-premises and other cloud platforms to Microsoft Azure. Collaborate with DevOps teams to develop and maintain Terraform modules that can be used by development teams for Azure resource provisioning. Cloud Networking & Platform Services: Implement and manage Azure networking solutions, including Virtual Networks, ExpressRoute, VPN Gateways, and network security. Work with Azure's Platform-as-a-Service (PaaS) offerings, including Azure SQL, Azure Files, Azure Functions, Azure Logic Apps, and Azure Data Factory. Configure and manage Virtual Machines (VMs), scaling, and performance optimization within Azure Access Management and Security: Implement Role-Based Access Control (RBAC) policies and ensure proper Identity and Access Management (IAM) practices across Azure resources. Configure and manage Azure AD roles, Custom RBAC roles, Azure AD Groups, and Conditional Access policies to enforce least-privilege access control for users and applications. Collaborate with security teams to enforce access control policies for sensitive resources and align with organizational security and compliance requirements. Automate identity provisioning and de-provisioning through integration with Azure AD, Azure AD B2B, and Azure AD B2C where applicable. Continuously monitor and audit Azure IAM practices to ensure compliance with internal policies and external regulations. Escalation & Troubleshooting: Serve as an escalation point for complex cloud infrastructure issues and troubleshoot problems related to Azure resources, networking, VM performance, and PaaS offerings. Work closely with support and operations teams to resolve incidents and service disruptions related to Azure infrastructure. Provide root cause analysis and post-mortem documentation for major incidents and failures. Collaboration & DevOps Integration: Partner with DevOps teams to integrate Azure infrastructure into CI/CD pipelines, ensuring automation and efficient provisioning of resources using IaC. Assist in implementing Azure DevOps or GitHub Actions to automate infrastructure provisioning, deployments, and monitoring. Continuously evaluate and improve deployment processes to enhance speed, reliability, and security. On-Premises Systems & VMware Experience: Leverage your experience with Windows Server administration, including Active Directory, Group Policy Objects (GPO), DNS, and DHCP. Manage the integration of VMware and ESXi environments hybrid cloud scenarios EDUCATION Bachelor's degree in computer science, information technology, or related field required. Certification or progress toward certification of, industry-recognized professional designation preferred and encouraged. Combinations of relevant education and work experience may be considered in lieu of a degree. Continuous learning, as defined by Company's learning philosophy, is