- Assess the existing Azure environment, including subscriptions, networking, identity, security, governance, and operational processes.
- Design and implement Azure Landing Zones aligned with the Microsoft Cloud Adoption Framework and Azure Well-Architected Framework.
- Define and implement:
- Management Group and subscription structures
- Resource organization, tagging, and naming standards
- RBAC and access models
- Azure Policy and governance frameworks
- Network architecture
- Logging, monitoring, and operational standards
- Establish repeatable and automated patterns for onboarding new workloads and services.
Design, implement, automate, and operate Azure infrastructure and shared platform services, including:
- Windows Server workloads hosted on Azure Virtual Machines
- VNets and subnets
- Routing and DNS
- Network Security Groups (NSGs)
- Private Link and Private Endpoints
- Storage and related Azure platform services
- Azure Monitor, Log Analytics, alerting, and diagnostics
- Identity, access management, and security controls
- Linux-based workloads and Azure Kubernetes Service (AKS), where required as part of the wider platform landscape
- Support the infrastructure and platform requirements of Microsoft Fabric and other Azure-based data services.
- Establish secure networking, identity, governance, and connectivity patterns for cloud data platforms.
- Collaborate with data engineering and analytics teams to integrate data platforms into the wider Azure architecture.
- Support platform-level capacity planning, monitoring, security, operational readiness, and cost management.
Infrastracture as Code & Automation
- Develop and maintain Infrastructure as Code for repeatable Azure deployments.
- Integrate Infrastructure as Code into GitLab CI/CD pipelines.
- Establish code review, testing, versioning, and deployment practices for infrastructure.
- Automate infrastructure provisioning and operational tasks using:
- PowerShell
- Azure CLI
- Terraform, where applicable
DevOps & Operations
- Promote DevOps and Infrastructure as Code practices across the infrastructure team.
- Establish and maintain Git-based infrastructure workflows.
- Improve observability, monitoring, alerting, and operational readiness.
- Define and maintain technical documentation, standards, and operational runbooks.
- Troubleshoot complex infrastructure, networking, identity, and platform issues.
- Mentor infrastructure engineers and actively share knowledge across the wider team.
WHAT SKILLS WILL BE APPRECIATED?
Strong hands-on experience with:
- Microsoft Azure architecture and infrastructure
- Azure Landing Zones and the Microsoft Cloud Adoption Framework
- Azure governance, including Management Groups, subscriptions, RBAC, and Azure Policy
- Azure networking, including VNets, DNS, routing, Azure Firewall, NSGs, Private Link, and Private Endpoints
- Azure Monitor and Log Analytics
- Infrastructure as Code principles and implementation
- Git-based infrastructure workflows
- PowerShell
- DevOps practices for cloud infrastructure
Experience with Linux administration and Kubernetes/AKS is advantageous. The successful candidate should be willing to broaden their skills and contribute to cloud-native platform initiatives as the Azure platform evolves.
Experience in some of the following areas would be beneficial:
- Microsoft Fabric platform infrastructure and administration
- Terraform
- Azure Key Vault and Managed Identities
- Azure cost management and FinOps practices
OUR OFFER FOR YOU
This is a hands-on senior engineering role combining architecture, platform engineering, automation, and operational excellence. The engineer will assess the current Azure environment, define target architectures and standards, establish Azure Landing Zones, and lead their implementation while remaining closely involved in engineering and operations.
As the wider platform evolves, the role will also provide opportunities to contribute to Linux-based workloads, Azure Kubernetes Service (AKS), and other cloud-native technologies.
No dress code - you can just be yourself here
Medical, sport and life insurance packages at preferential terms
Access to our products and services at preferential terms
Employment contract-based cooperation
Know Talent - receive training or financial bonus for recommending new employees
WHAT WILL YOUR RECRUITMENT PROCESS BE LIKE?
A fair approach to all people who want to join T Hub means that:
- The recruitment process is transparent;
- Our recruitment decision is based solely on an assessment of your skills (your race, skin color, sexual orientation, gender identity, origin, disability, political view, appearance, or religion will not have any influence on the outcome of the process):
- Regardless of the outcome of the process, you will get detailed feedback.
Let’s meet to better understand each other's expectations.
Our screening meeting will last about 20-30 minutes. We will ask you about our areas of interest and will be happy to field any questions you may have.
Hiring Manager will receive a recommendation for your application.
There’s nothing for you to do at this stage — we’ll take care of everything. During this time we process all the information we've gathered during the screening process and dig deeper into your CV.
Technical meetings with the Hiring Manager and/or team members.
We will invite you to one or two project meetings to confirm that we have a ‘perfect match'. The meetings may last between 30 minutes and 90 minutes, during which time we will talk to you about mutual expectations and the vision for our collaboration. You will also most likely meet your future supervisor and your teammate during this time.
At this stage, we will have decided that you are the person we want to develop our projects with. We will then come back to you with an offer of collaboration, hoping for your "yes". If for some reason, we are unable to offer you a position in our team, you will certainly receive feedback from us explaining our decision.