Equal Plus Consulting has been engaged to search for a Senior Cloud Center of Excellence Azure Platform Engineer to work hybrid 60% on-site in Belgium or Czech Republic.
TITLE Senior Cloud Center of Excellence Azure Platform Engineer (Belgium)
START DATE 5 Oct 2026
END DATE 5 Mar 2027
LOCATION Kontich, Belgium or Czech Republic
hybrid 60% on-site in
About the Role
The Cloud Center of Excellence (CCoE) is responsible for the design, governance and scaling of Azure and self-service platform.
We are looking for a senior engineer to help clean up the technical depth — from landing zone architecture to Terraform Enterprise module engineering, networking design and enterprise system integrations. This is a medior/senior individual contributor role: you're expected to work independently on well-defined scopes, but you'll be ramping up within an existing team structure rather than owning the full platform strategy from day one.
Current Situation
The Azure platform has grown fast — more application teams, more subscriptions, more consumers of our self‑service capabilities every quarter. That
growth has been a success story, but it also means parts of our platform (governance controls, identity and access processes, networking/DNS patterns, and our Terraform Enterprise setup) were built for an earlier stage of adoption and now need to be modernized to keep pace with scale.
We're tackling this step by step: moving toward more standardized, automated and maintainable ways of working across governance, identity, networking and
infrastructure‑as‑code, so the platform can keep scaling without a proportional increase in manual effort.
To do that well, we're expanding the team with senior engineers who can contribute on two fronts: keeping day‑to‑day platform operations running smoothly for the
teams that depend on us, while also helping design and build the more standardized, scalable solutions we're moving toward.
Day-to-Day Responsibilities
- Act as second‑line escalation for Azure platform issues (RBAC, DNS, VNET/Private Endpoint connectivity, AD integration, Terraform Enterprise runs) and write up root cause analyses.
- Maintain and incrementally improve landing zones, archetypes, Azure Policy and naming/tagging standards; process governance exception requests.
- Build, version and maintain Terraform modules; review consumer changes and evaluate Azure Verified Modules (AVM) as replacements for custom modules.
- Handle recurring IAM tickets (RBAC assignments, group memberships, access troubleshooting) and contribute to cleanup of legacy/exception‑based access.
- Support DNS/connectivity requests and troubleshooting across the hybrid environment within existing patterns.
- Maintain and troubleshoot existing PowerShell automation scripts used across platform operations.
- Keep governance documentation current and contribute to internal Terraform Enterprise workshops and application team enablement.
Required Technical Expertise
- Governance: management groups, subscriptions, Azure Policy (built‑in and custom), RBAC design and troubleshooting.
- Identity: Microsoft Entra ID — group‑based access models, app registrations, managed identities, service principals.
- Landing zone concepts aligned with Microsoft Cloud Adoption Framework (CAF) archetypes.
- Exposure to Azure Databricks networking (VNet injection) is a plus.
- Infrastructure as Code
- Solid production‑level Terraform authoring — designing, versioning and publishing modules, not just consuming them.
- Terraform Enterprise or Terraform Cloud experience specifically: workspaces, private module registry, VCS‑driven workflows, policy checks (Sentinel/OPA).
- Familiarity with Azure Verified Modules (AVM) and module lifecycle/versioning practices.
DevOps & Automation
- CI/CD pipeline experience (Azure DevOps preferred): build/release pipelines, YAML pipelines, service connections.
- Scripting for automation and troubleshooting (PowerShell, Bash or Python).
- Comfortable working with KQL/Log Analytics for diagnostics is a plus.
Identity & Access Management
- Practical RBAC design and troubleshooting at enterprise scale (role assignments, group nesting, inheritance issues, propagation delays).
- Experience managing access for both human users and service/application identities.
- Understanding of access governance concepts (ownership, periodic reviews, exception handling).
Networking
- Solid understanding of enterprise DNS architecture, including hybrid on‑prem/cloud scenarios.
- Experience troubleshooting connectivity issues across VNETs, firewalls, and hybrid links.
Prior Experience we're Looking For
- 4–7 years in a cloud platform engineering, DevOps or infrastructure engineering role, ideally within a large, governed enterprise (not a greenfield/startup environment).
- Demonstrated experience operating (not just building) an Azure landing zone platform at scale — supporting real application teams with real tickets.
- Prior role involving Terraform Enterprise/Cloud in a production capacity, ideally including module authorship and CI/CD integration.
- Experience working across team boundaries (IAM, Networking, Security, external partners/vendors) to resolve platform issues.
- Microsoft certifications (AZ-104, AZ-204, AZ-305, or Terraform Associate) are a strong plus but not a substitute for demonstrable hands‑on experience.
- Personal Characteristics
- Can operate independently on a well‑scoped task from day one — this is a "plug in and go"; role, not a ramp‑up position.
- Comfortable working in a live, legacy‑entangled environment where not everything is fully standardized yet.
- Detail‑oriented, especially around governance, documentation and naming/tagging consistency.
- Good communicator — able to support application teams directly without needing everything translated by the platform lead.
- Takes ownership of tickets/incidents end‑to‑end rather than escalating prematurely.