Richmond, United States
- Actual Job Title 812168 - VDOT Azure Cloud Engineer
- Job Type FT Contract
- Country United States
- Number of Positions 1
Job Description
VDOT ITD Tolling is seeking an Azure Cloud Engineer to join the Eng and Ops team. The role includes engineering, application support, and rotational help-desk support within the Tolling group. Includes API Gateways, AVD, App Insights, & Office 365.
Primary Responsibilities
Cloud Operations and Engineering
- Maintain and implement cloud resources in theTolling Azure environment.
- Ensure compliance with Virginia governmentpolicies regarding security, IAM, network controls, and cost governance.
- Maintain and improve infrastructuredocumentation, naming conventions, tagging standards, and cloud governanceartifacts.
- Assist with access reviews, role assignments,and least-privacy IAM evaluations.
- Manage vendor-required updates and ensurecompatibility.
- Implement fault-tolerant and highly available Azure solutions.
Monitoring, Troubleshooting, and Diagnostics
- Monitor Azure services and application workloads to ensure uptime and availability.
- Troubleshoot issues related to connectivity,access, security, application performance, and service degradation.
- Perform diagnostic deep-dives using logs,metrics, traces, Azure Monitor, and Log Analytics.
- Analyze and tune system/application performance.
Operational Support
- Participate in daily/weekly operational cycles including pattern monitoring, incident reviews, and maintenance readiness checks.
- Triage production issues, ensure timelyresolution, and document root-cause findings.
- Execute and support off-hours work as needed.
- Define change requests, detailed implementationplans, and roll-back procedures.
Technical Development and Compliance
- Understand end-to-end data flows across tollingsystems, roadways data, financial transactions, and reporting tools.
- Support optimization of integrations and datamovement.
- Apply PCI or other regulatory compliancerequirements when evaluating system behavior and logging patterns.
- Manage key vaults, passwords, certificates, andsecure credential storage.
Collaboration and Communication
- Work directly with architects, engineers,managers, and cross-functional teams to use Azure services effectively.
- Provide best-practice guidance related to SaaS,PaaS, and IaaS.
- Communicate clearly in written and verbal formwith internal and external stakeholders.
- Support multiple concurrent projects of complextechnical scope.
Qualifications
- Minimum 3 years of experience with MicrosoftAzure services.
- Minimum 3 years experience supporting VDOT /E-ZPass Virginia tolling applications, infrastructure, and cloud workloads, including hands-on diagnostic work with transaction flows, roadway sensor data ingestion, and tolling application performance tuning.
- Bachelor’s degree in computer science,information systems, or equivalent experience.
- Demonstrated ability to communicate requirementsand design concepts clearly.
- Experience working in Windows environments.
- Implementing Rubrik backup & recovery for Azure IaaS/PaaS, including policy sets, snapshot lifecycle tuning, and DRvalidation.
- Experience with Office 365 services andadministering Single Sign-On (SSO) including Entra ID.
- Experience administering SecretServer privileged access vaults including credential rotation, vault workflow troubleshooting, and integration with Azure workloads.
- Solid scripting experience (PowerShell and/orPython).
- Ability to create network and system topologydocumentation.
- Experience with Azure Virtual Desktops.
- Office 365 services and Power Apps.
Special Instructions
- Position requires a fingerprint-based backgroundcheck.
- Continued education is expected at the contractor’s own expense to stay current with VDOT technologies.
Requirements
- Microsoft Azure administration/engineering Required 3 Years
- Microsoft Windows environments (2019+) Required 5 Years
- Server infrastructure, protocols, firewalls, certificates, load balancers Required 2 Years
- Support of VDOT / E-ZPass Virginia tolling applications, infrastructure, and cloud workloads Required 3 Years
- Networking, server administration (Windows/Linux), databases, cloud environments Required 2 Years
- Implementing Rubrik backup & recovery for Azure IaaS/PaaS Required 2 Years
- Scripting with PowerShell/Python Required 2 Years
- Continuous integration tools (Azure DevOps, Jenkins, Git, TFS) Desired 1 Years
- Administration of SecretServer privileged access vaults. Required 2 Years
- Office 365 and Power Apps platforms Required 1 Years
- Infrastructure as Code (Terraform or equivalent) Desired 1 Years
- Containerization (Docker, Kubernetes) Desired 1 Years
- Experience with PCI or similar compliance frameworks Required 1 Years
- Key Vault, secrets and certificate management Desired 1 YearsSingle Sign On and identity administration (Entra ID) Required 1 Years
- Azure certification (AZ 104, AZ 305, or similar) Desired 1 Years
- Experience with enterprise governance models Required 1 Years