Cloud Architect

EPAM Systems

Deutschland

Hybrid

EUR 120.000 - 160.000

Vollzeit

Vor 6 Tagen
Sei unter den ersten Bewerbenden
Bewerbungsgenerator

Eine zielgenaue Bewerbung für diesen Job — ein maßgeschneiderter Lebenslauf und ein Anschreiben, die genau zur Stellenanzeige passen.

Schaffe es an den ATS-Filtern vorbei

Zusammenfassung

EPAM Systems is looking for an experienced Cloud Architect to help deliver a Unified Automation Platform. The role concentrates on architecting Azure-based infrastructure, identity, and Kubernetes foundations that power self-service capabilities across hybrid environments spanning Azure and on-premises VMware.

You will design IaC modules (Terraform/OpenTofu) for App Services, databases, AKS, and networking, define the Azure identity architecture, and partner with security, network, and Backstage

Qualifikationen

  • 10+ years of proven Azure solution/enterprise architecture experience.
  • Deep expertise in Terraform/OpenTofu for Azure infrastructure automation.
  • Background in Azure identity and access architecture (Entra ID, Active Directory, RBAC) and secret management.
  • Hands-on experience with Azure Kubernetes Service (AKS) at production scale.
  • Proficiency in Configuration as Code (Ansible) for VM provisioning and pipelines.
  • Excellent command of English (B2+) for technical communication.
  • Nice to have Experience with Azure VMware Solution (AVS).
  • Familiarity with certificate lifecycle platforms (e.g., Venafi) and their integration with Azure Key Vault.
  • Knowledge of policy-as-code engines (OPA/Conftest, Azure Policy).
  • Experience in large-scale, multi-region Azure landing zones or platform engineering.

Aufgaben

  • Architect Infrastructure as Code modules (Terraform/OpenTofu) for Azure services and databases.
  • Define Azure identity architecture with Entra ID, AD, and RBAC, and secret management.
  • Design AKS platform with cluster/node-pool design and add-ons.
  • Collaborate on connectivity, firewall, DNS, and ExpressRoute with the Network Architect.
  • Define Image Factory for VM and container images with CIS hardening and scanning.
  • Establish IaC engine standards including remote state, modules, and secrets.
  • Partner with Backstage/DevPortal teams to expose provisioning capabilities.
  • Provide architectural governance during implementation and support module lifecycle ownership.

Kenntnisse

English (B2+)
Cloud architecture

Tools

Terraform/OpenTofu
Ansible
Azure DevOps
AKS
Azure Key Vault

Jobbeschreibung

We are seeking an experienced Cloud Architect to join our team and contribute to the delivery of a Unified Automation Platform. This Internal Developer Platform (IDP) will standardize new-project delivery, centralize access to development resources, and enable software creation through templates and golden paths. The role focuses on architecting Azure-based infrastructure, identity, and Kubernetes foundations that power self-service capabilities across hybrid environments spanning Azure and on-premises VMware.

Responsibilities
  • Architect Infrastructure as Code modules (Terraform/OpenTofu) for Azure App Services, Container Apps, and Function Apps, as well as Azure SQL, Azure Cosmos DB, and Azure Postgres, including the Azure VMware Solution (AVS) private cloud module with managed-identity wiring, private endpoints, and diagnostic settings to Log Analytics
  • Define the Azure identity architecture in partnership with the security team, covering Entra ID, Active Directory, and Group Policy Objects, along with M365 groups, SPN/app registrations, and managed identities, ensuring secrets land in OpenBao/Key Vault per platform standards
  • Design the Azure Kubernetes Service (AKS) platform, including cluster and node-pool design, baseline add-on stack (ingress, cert-manager, external-dns, monitoring, policy), namespace/tenant onboarding, and an operations dashboard for cluster management
  • Collaborate with the Network Architect on core connectivity (VNets, Application Gateway, WAF), Azure Firewall, NSGs, and DNS, NetBox IPAM, and ExpressRoute connectivity, ensuring Azure compute, database, and AKS modules integrate cleanly with the network foundation
  • Define the Image Factory architecture for VM and container golden images, covering Linux and Windows/cloudbase-init baselines, CIS hardening, agent injection, and image scanning with Shared Image Gallery publishing/versioning
  • Establish foundational Infrastructure as Code Engine standards (remote state/backend, locking, RBAC), including module registry, testing framework, drift detection, policy hooks, and secrets injection consumed by all other automation modules
  • Partner with the Backstage Architect to expose Azure provisioning capabilities as Backstage golden-path templates, and with Integration Architects on observability, ITSM/CMDB, and security integrations touching Azure resources
  • Provide architectural governance during Implementation, validate production deployments, and support module lifecycle ownership during Adoption
Requirements
  • 10+ years of proven Azure solution/enterprise architecture experience, ideally validated through Microsoft Azure partner-level engagements or equivalent certifications
  • Deep expertise in Terraform/OpenTofu for Azure infrastructure automation, including module design, state management, and CI/CD-driven deployment pipelines (Azure DevOps)
  • Working knowledge of Azure networking constructs (VNets, private endpoints, NSGs) sufficient to integrate compute and data modules with the network foundation owned by the Network Architect
  • Hands-on experience architecting Azure Kubernetes Service (AKS) at production scale, including networking, policy, and multi-tenant namespace design
  • Background in Azure identity and access architecture (Entra ID, Active Directory, managed identities, RBAC) and secrets integration (Azure Key Vault, dynamic secrets)
  • Proficiency in Configuration as Code (Ansible) for VM post-provisioning and golden-image pipelines
  • Excellent command of English (B2+ level), both written and spoken, with a strong emphasis on technical communication skills
  • Nice to have Experience with Azure VMware Solution (AVS) private cloud provisioning
  • Familiarity with certificate lifecycle management platforms (e.g., Venafi) and their integration with Azure Key Vault
  • Skills in integrating Azure infrastructure automation with a Backstage-based (or comparable) developer portal
  • Knowledge of policy-as-code engines (OPA/Conftest, Azure Policy) for automated compliance enforcement
  • Prior experience in large-scale, multi-region Azure landing-zone or platform engineering
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Network Architect
Network Architect

EPAM Systems • Deutschland

Hybrid
EUR 90.000 - 140.000
Azure DevOps Engineer – Temporary Contract
Azure DevOps Engineer – Temporary Contract

Jobtailor • Deutschland

Remote
EUR 85.000 - 120.000
Azure Cloud Engineer
Azure Cloud Engineer

Market Cloud • Eschborn

Vor Ort
Confidential
DevOps Engineer
DevOps Engineer

IQAir AG • Berlin

Vor Ort
EUR 55.000 - 75.000
Azure AI Security Architect
Azure AI Security Architect

Jobtailor • Deutschland

Remote
EUR 120.000 - 160.000
Azure Cloud Engineer
Azure Cloud Engineer

3209 Avanade Deutschland GmbH Company • Kronberg im Taunus

Vor Ort
EUR 70.000 - 100.000
Paid training and certifications
Global alliance partner engagement
International teamwork opportunities
Azure Architect
Azure Architect

Aether Biomedical • Deutschland

Remote
EUR 90.000 - 140.000
Azure Cloud Engineer
Azure Cloud Engineer

Avanade Spain SL • Düsseldorf

Vor Ort
EUR 90.000 - 130.000
Azure Cloud Engineer
Azure Cloud Engineer

Avanade • München

Vor Ort
EUR 70.000 - 100.000
Paid training and certifications
Clear career paths
Competitive compensation
Azure Specialist
Azure Specialist

TrustedTech • Deutschland

Vor Ort
EUR 70.000 - 100.000