Functie:
We are looking for a senior engineer to help clean up the technical depth — fromlanding zone architecture to Terraform Enterprise module engineering, networking
design and enterprise system integrations.This is a medior/senior individual contributor role: you're expected to workindependently on well-defined scopes, but you'll be ramping up within an existingteam structure rather than owning the full platform strategy from day one.
Day-to-Day Responsibilities
- Act as second-line escalation for Azure platform issues (RBAC, DNS,VNET/Private Endpoint connectivity, AD integration, Terraform Enterprise
runs) and write up root cause analyses. - Maintain and incrementally improve landing zones, archetypes, Azure Policyand naming/tagging standards; process governance exception requests.
- Build, version and maintain Terraform modules; review consumer changesand evaluate Azure Verified Modules (AVM) as replacements for custom
modules. - Handle recurring IAM tickets (RBAC assignments, group memberships,access troubleshooting) and contribute to cleanup of legacy/exception-based
access. - Support DNS/connectivity requests and troubleshooting across the hybridenvironment within existing patterns.
- Maintain and troubleshoot existing PowerShell automation scripts used acrossplatform operations.
- Keep governance documentation current and contribute to internal TerraformEnterprise workshops and application team enablement.
Required Technical Expertise
- Azure (hands-on production experience required)
- Governance: management groups, subscriptions, Azure Policy (built-in andcustom), RBAC design and troubleshooting.
- Identity: Microsoft Entra ID — group-based access models, app registrations,managed identities, service principals.
- Networking: VNET peering/hub-spoke, Private Endpoints, Private DNS Zones,Azure Firewall, Application Gateway, Azure Front Door, hybrid/on-prem DNS
integration. - Landing zone concepts aligned with Microsoft Cloud Adoption Framework(CAF) archetypes.
- Exposure to Azure Databricks networking (VNet injection) is a plus.
- Infrastructure as Code
- Solid production-level Terraform authoring — designing, versioning andpublishing modules, not just consuming them.
- Terraform Enterprise or Terraform Cloud experience specifically: workspaces,private module registry, VCS-driven workflows, policy checks (Sentinel/OPA).
- Familiarity with Azure Verified Modules (AVM) and module lifecycle/versioningpractices.
- DevOps & Automation
- CI/CD pipeline experience (Azure DevOps preferred): build/release pipelines,YAML pipelines, service connections.
- Scripting for automation and troubleshooting (PowerShell, Bash or Python).
- Comfortable working with KQL/Log Analytics for diagnostics is a plus.
- Identity & Access Management
- Practical RBAC design and troubleshooting at enterprise scale (roleassignments, group nesting, inheritance issues, propagation delays).
- Experience managing access for both human users and service/application identities.
- Understanding of access governance concepts (ownership, periodic reviews, exception handling).
- Networking
- Solid understanding of enterprise DNS architecture, including hybrid on-prem/cloud scenarios.
- Experience troubleshooting connectivity issues across VNETs, firewalls, andhybrid links.
Prior Experience we're Looking For
- 4–7 years in a cloud platform engineering, DevOps or infrastructureengineering role, ideally within a large, governed enterprise (not a
greenfield/startup environment). - Demonstrated experience operating (not just building) an Azure landing zoneplatform at scale — supporting real application teams with real tickets.
- Prior role involving Terraform Enterprise/Cloud in a production capacity, ideally including module authorship and CI/CD integration.
- Experience working across team boundaries (IAM, Networking, Security, external partners/vendors) to resolve platform issues.
- Microsoft certifications (AZ-104, AZ-204, AZ-305, or Terraform Associate) are a strong plus but not a substitute for demonstrable hands-on experience.
Personal Characteristics
- Can operate independently on a well-scoped task from day one — this is a "plug in and go"; role, not a ramp-up position.
- Comfortable working in a live, legacy-entangled environment where noteverything is fully standardized yet.
- Detail-oriented, especially around governance, documentation andnaming/tagging consistency.
- Good communicator — able to support application teams directly withoutneeding everything translated by the platform lead.
- Takes ownership of tickets/incidents end-to-end rather than escalatingprematurely.
Important
we are looking for 2 resources for a temporary 6 month assignment. The place of work can be Belgium or Czech Republic.