Senior Azure Cloud/Platform Engineer - MF

DVT

Johannesburg

On-site

ZAR 900,000 - 1,200,000

Full time

6 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

DVT is seeking a Senior Azure Cloud/Platform Engineer to design and build a fully private Azure environment. This greenfield project requires establishing the networking foundation, private endpoints, private AKS clusters, and end-to-end hybrid DNS across VPN boundaries.

All infrastructure must be codified for repeatable deployments in Production and Test. You will work with a team of experienced developers, implement IAM controls with Entra ID, RBAC, and private key management, and lead CI/CD

Qualifications

  • 5+ years in Cloud/Platform/Infrastructure roles with Azure focus.

Responsibilities

  • Design and implement private Azure networking (VNets, subnets, NSGs, UDRs) and private endpoints for PaaS services.

Skills

Azure networking
AKS private clusters
Terraform
Bicep
Azure Private Endpoints
Private DNS Zones
Azure DevOps
Dapr integration
RBAC
Entra ID
Kubernetes internals
CI/CD pipelines
Azure Monitor
OpenTelemetry

Tools

Terraform
Bicep
Azure DevOps
OpenTelemetry
Dapr

Job description

DVT is one of the top software development companies on the continent. Our software engineers are consulting on cutting edge applications at top companies in South Africa, as well as consulting globally. You will have the opportunity to work alongside some of the most established developers in the country and globally with the latest technologies.

DVT is seeking a Senior Azure Cloud/Platform Engineer to design and build a fully private Azure environment. This is a greenfield platform buildout, not application deployment into an existing environment. The engineer will establish the Azure networking foundation, configure all PaaS and managed services behind Private Endpoints, deploy private AKS clusters, and ensure end-to-end hybrid DNS resolution across an existing site-to-site VPN. All infrastructure must be codified for repeatable deployment across Production and Test environments.

Duties And Responsibilities
Azure Private Networking
  • Design and implement the VNet topology with appropriately segmented subnets for AKS, Private Endpoints, Application Gateway, and management
  • Deploy and configure Private Endpoints for Azure Container Registry, Azure SQL, Azure Storage (Blob and Table), Azure Key Vault, Azure Service Bus, and Azure App Configuration
  • Configure Private DNS Zones for all services
  • Configure Network Security Groups (NSGs) and User-Defined Routes (UDRs) to enforce least-privilege network access
  • Disable public access on all PaaS services once private connectivity is confirmed
Hybrid Connectivity and DNS
  • Work with infrastructure team to validate and optimise the existing site-to-site VPN
  • Deploy Azure DNS Private Resolver or DNS forwarder infrastructure to enable on-premises resolution of Azure Private DNS Zones
  • Conditional DNS forwarding on on-premises DNS servers
  • Ensure end-to-end name resolution works for all services across the VPN boundary — including validating that the VPN does not block cloud endpoints when both environments are active
AKS Private Cluster Deployment
  • Deploy AKS with a private API server endpoint (no public Kubernetes API exposure)
  • Configure Azure CNI networking with IP address planning to avoid conflicts with on-premises ranges
  • Set up node pool autoscaling for Production and scale-to-minimum/zero for the Test environment
  • Integrate AKS with Azure Container Registry via Private Endpoint and managed identity
  • Configure workload identity for secure access to Azure PaaS services from pods
  • Enable the Dapr extension for AKS as an Azure-managed cluster extension
Azure Application Gateway and Ingress
  • Deploy Azure Application Gateway with WAF v2 as the ingress point into the AKS cluster
  • Configure backend pools, health probes, and routing rules for the application workloads
  • Configure ingress routing to support traffic switching between on-premises and cloud based on availability and response time
  • Integrate TLS termination with certificates managed in Azure Key Vault
Security and Identity
  • Configure Azure Key Vault with private access for secrets, certificates, and encryption keys
  • Set up managed identities across all services to eliminate credential-based authentication
  • Implement RBAC across all deployed resources
  • Integrate with Entra ID (Azure AD) configure the foundational app registrations, tenant configuration, and identity infrastructure
Observability Infrastructure
  • Configure Azure Monitor, Container Insights, and Log Analytics workspace for the AKS cluster
  • Set up Application Insights resources for the .NET workloads
  • Configure Dapr's telemetry pipeline to flow into the same Application Insights and Log Analytics infrastructure
  • Establish alert rules and Azure Monitor workbooks for cluster health, node scaling, and Private Endpoint connectivity
Infrastructure as Code
  • Codify all infrastructure in Terraform or Bicep using a modular structure that supports environment-level parameterisation
  • Ensure the same codebase can deploy both Production (zone-redundant) and Test (cost-optimised, scale-to-zero) environments
  • Implement CI/CD pipelines for infrastructure deployment via Azure DevOps
  • Establish drift detection and automated compliance checks
Required Experience And Skills
Must-have
  • 5+ years in Cloud Engineering, Platform Engineering, or Infrastructure Engineering roles, with at least 3 years focused on Azure
  • Proven hands-on experience designing and deploying Azure Virtual Networks, subnets, NSGs, UDRs, and network peering
  • Deep experience with Azure Private Endpoints and Private DNS Zones across multiple PaaS services (SQL, Storage, Key Vault, ACR, Service Bus)
  • Experience deploying and operating AKS private clusters, including Azure CNI networking, node pool management, and workload identity
  • Strong experience with Azure Application Gateway (WAF v2) configuration and backend integration
  • Experience with hybrid connectivity: site-to-site VPN, DNS resolution across cloud/on-premises boundaries, Azure DNS Private Resolver or forwarder VM
  • On-premises infrastructure experience; understanding of how cloud and on-prem coexist in hybrid architectures, including firewalls, VPN gateways, and on-prem networking
  • Proficiency in Terraform or Bicep for infrastructure as code, with experience building multi-environment deployable modules
  • Experience with Azure Key Vault, managed identities, and Entra ID integration
  • Strong understanding of Kubernetes internals: networking (CNI), RBAC, Helm, ingress controllers, pod identity
  • Experience building CI/CD pipelines for infrastructure deployment (Azure DevOps preferred)
  • Experience configuring Azure Monitor, Container Insights, and Log Analytics for AKS clusters
  • Excellent documentation skills and experience with technical handover
Advantageous
  • Microsoft Azure certifications: AZ-305 (Solutions Architect), AZ-104 (Administrator), or AZ-400 (DevOps Engineer)
  • Certified Kubernetes Administrator (CKA)
  • Experience with Dapr on AKS cluster extension deployment, component configuration, and integration with Azure-backed state stores and pub/sub
  • Experience with Azure Service Bus (Private Endpoint configuration, topic/subscription topology)
  • Experience with Azure App Configuration for multi-environment feature and configuration management
  • Experience with Azure Database Migration Service and Data Migration Assistant
  • Experience with Azure landing zone frameworks (Cloud Adoption Framework, Enterprise-Scale)
  • Experience with Application Insights and OpenTelemetry instrumentation pipelines
  • Experience with cost optimisation patterns: AKS scale-to-zero, Azure SQL auto-pause, reserved instances
  • Familiarity with MassTransit over Azure Service Bus
  • Experience in telecommunications or ISP environments
  • Knowledge of GitOps tools such as ArgoCD or Flux
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Azure Cloud/Platform Engineer - MF
Senior Azure Cloud/Platform Engineer - MF

DVT • Pretoria

On-site
ZAR 900,000 - 1,300,000
Microsoft Azure (Platform Engineer) - MF
Microsoft Azure (Platform Engineer) - MF

DVT • Midrand

On-site
ZAR 900,000 - 1,300,000
Senior Azure Cloud Engineer: Private Networking & AKS
Senior Azure Cloud Engineer: Private Networking & AKS

DVT • Pretoria

On-site
ZAR 900,000 - 1,300,000
Azure Engineer
Azure Engineer

Network Contracting • Gauteng

On-site
ZAR 480,000 - 720,000
Enterprise-scale Azure exposure
Automation technologies
Cloud transformation leadership
+3
Senior DevOps and Cloud Engineer
Senior DevOps and Cloud Engineer

Amarico • Cape Town

On-site
ZAR 900,000 - 1,300,000
Senior DevOps / SRE Cloud Engineer
Senior DevOps / SRE Cloud Engineer

Hire Resolve • Cape Town

On-site
ZAR 900,000 - 1,500,000
Competitive salary
Azure Devops Engineer
Azure Devops Engineer

Skywaves Rise • Gauteng

On-site
ZAR 700,000 - 1,000,000
Azure Infrastructure Engineer
Azure Infrastructure Engineer

Impronics Technologies • Johannesburg

On-site
ZAR 800,000 - 1,200,000
Azure Cloud Operations Lead
Azure Cloud Operations Lead

iDbase Software • Cape Town

On-site
ZAR 1,000,000 - 1,500,000
Biz Dev Ops Engineer (Contract)
Biz Dev Ops Engineer (Contract)

The Focus Group • Sandton

On-site
ZAR 1,000,000 - 1,800,000