25 ago
|
Hexaware México
|
México
25 ago
Hexaware México
México
This role provisions and manages workload-specific infrastructure resources. Sitting within the Infrastructure Build Pod, the Cloud Engineer translates architecture decisions and workstream team requirements into production-ready Terraform modules — covering compute, storage, PaaS services, and environment scaffolding — shipped through the shared DevSecOps CI/CD pipeline. The role partners closely with the Senior Cloud Network Engineer, application workstream leads, and the Security team to deliver governed, reproducible, and cost-aware infrastructure aligned to Calandra Blueprint and Azure Landing Zone standards.
Key Responsibilities
- Provision workload-specific Azure resources — compute (VMs, AKS), storage, PaaS services (Container Apps, App Services, Azure Functions, Azure SQL, Cosmos DB), and managed identities — per workstream team requirements and architecture-approved patterns.
- Author and maintain Terraform IaC modules for workload resource provisioning, following Infrastructure Build Pod standards, checked into repos, and shipping behind blocking CI gates.
- Scaffold and manage workload landing-zone scaffolding — child subscriptions, resource groups, RBAC assignments, tagging, and Azure Policy — within the Calandra Azure Landing Zone (management groups; dev / stg / prd).
- Integrate workload resources with the shared network layer — private endpoints, VNet integration, and DNS registration
- Maintain environment parity across dev / staging / production, enforcing governance guardrails: policy compliance, cost tagging, quota management, and secure defaults.
- Support DevSecOps toolchain integration: pipeline templates, service connections, and managed-identity federation across Azure DevOps and GitHub.
- Monitor resource health, cost, and compliance; contribute to observability dashboards and alerting baselines aligned to the platform’s Defender / Sentinel stack.
- Contribute reusable provisioning modules to the Infrastructure Build Pod’s core capacity, enabling self-service for downstream workstream teams.
- Document infrastructure designs, architecture decision records (ADRs), and operating procedures; support onboarding of new workstream teams onto the platform.
Required Qualifications
- 4+ years in cloud engineering, with hands-on Azure infrastructure provisioning experience.
- Proven Terraform skills — authoring, testing, and maintaining modules in a team environment with peer review and CI validation.
- Working knowledge of Azure resource hierarchy (management groups, subscriptions, resource groups) and Azure RBAC.
- Hands-on experience with Azure PaaS services: App Service, AKS, Container Apps, Azure SQL, Cosmos DB, Storage, and Key Vault.
- Experience with private endpoints and VNet-integrated connectivity for PaaS workloads.
- CI/CD experience with Azure DevOps and/or GitHub Actions, including pipeline authoring and service-connection management.
- Understanding of cloud security fundamentals — managed identities, service principals, Key Vault integration, and Azure Policy.
- Clear written communication and the ability to work across multiple workstream teams in a multi-vendor program.
Preferred Qualifications
- Experience provisioning Databricks workspaces (VNet injection, cluster configurations, private connectivity) given Skylark’s Databricks-centric data foundation.
- Familiarity with Azure Landing Zone / Calandra-style environment patterns (landing-zone accelerators, policy-as-code).
- Azure certifications: AZ-104 (Azure Administrator) or AZ-204 (Azure Developer), or equivalent.
- Background in regulated industries (insurance, financial services) and associated compliance and data-residency controls.
- Experience with cloud cost management (Azure Cost Management, FinOps practices) in a multi-subscription environment.
📌 Cloud Engineer (México)
🏢 Hexaware México
📍 México