Job Description
Azure Landing Zone Lead / ArchitectLocation: Remote
Duration: Contract
Rate: DOE
Key Responsibilities- Lead the design, implementation, and evolution of Azure Landing Zones using Azure Landing Zone Accelerator (ALZ) and Terraform.
- Design and deploy enterprise-scale management group hierarchies, subscription vending, and policy-as-code implementations.
- Develop scalable Terraform modules for reusable infrastructure deployments.
- Architect and implement hub-and-spoke Azure network topologies with centralized connectivity and secure workload isolation.
- Design management group structures aligned with Microsoft's Cloud Adoption Framework (CAF), customized for enterprise governance requirements.
- Establish Azure governance including:
- Azure Policies
- RBAC
- Resource organization
- Cost management
- Subscription governance
- Quota management
- Implement Azure Entra ID security and identity solutions including:
- Conditional Access
- Privileged Identity Management (PIM)
- Service Principals
- Managed Identities
- Federated Identity
- Build CI/CD pipelines for infrastructure deployments using Azure DevOps or GitHub Actions.
- Manage Terraform state and infrastructure versioning following Infrastructure-as-Code best practices.
- Design resilient deployment strategies including Blue/Green deployment models and zero-downtime workload transitions.
- Partner with enterprise architects and infrastructure teams to convert architectural designs into production-ready Azure Landing Zone deployments.
- Support onboarding of multiple application teams while continuously improving and hardening the landing zone.
Required Qualifications- Extensive experience designing and deploying Azure Landing Zones using Azure Landing Zone Accelerator (ALZ).
- Strong hands-on expertise with Terraform, including:
- Module development
- State management
- Infrastructure-as-Code best practices
- Experience designing enterprise Azure governance frameworks.
- Deep knowledge of Microsoft Cloud Adoption Framework (CAF).
- Expertise building customized management group hierarchies beyond CAF defaults.
- Strong Azure networking experience including:
- Hub-and-spoke architecture
- Centralized connectivity
- Private networking
- VNet peering
- Secure egress architecture
- Experience with Azure subscription lifecycle management and enterprise governance.
- Strong knowledge of Azure Entra ID including:
- RBAC
- Conditional Access
- PIM
- Managed Identities
- Service Principals
- Federated Identity
- Experience integrating Terraform deployments into Azure DevOps or GitHub Actions CI/CD pipelines.
- Strong understanding of enterprise security, governance, compliance, and operational best practices.
- Excellent communication skills with the ability to work directly with enterprise architecture and infrastructure teams.
Skills
Architectural Designunmatched
Best Practicesunmatched
Business Operationsunmatched
Cloud Computingunmatched
Communication Skillsunmatched
Continuous Deployment/Deliveryunmatched
Continuous Improvementunmatched
Continuous Integrationunmatched
Cost Controlunmatched
DevOpsunmatched
Enterprise Architectureunmatched
Enterprise Protectionunmatched
GitHubunmatched
Identity Data Managementunmatched
Identity Federationunmatched
Microsoft Product Familyunmatched
Microsoft Windows Azureunmatched
Network Topologyunmatched
Onboardingunmatched
Protocol Independent Multicast (PIM)unmatched
Scalable System Developmentunmatched
Software Administrationunmatched
United States Department of Energy (DOE)unmatched
Level up your application
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.
Free resume templatesImprove your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.
Free resume builder