What are the responsibilities and job description for the Cloud Infrastructure Engineer position at Digital Prospectors?
Position: Cloud Infrastructure Architect (Azure Focus)
Location: Boston, MA
Length: 9-12 Months
**note: w2 candidates only, not open for C2C partnership**
Overview:
Our client is seeking an experienced Cloud Infrastructure Architect with a strong focus on Microsoft Azure. This hands-on role is responsible for designing, implementing, and optimizing cloud infrastructure solutions that align with the university’s cloud strategy. The ideal candidate will have deep expertise in Azure architecture, governance, security, networking, and automation. You will work closely with cloud engineers, security teams, and application teams to drive cloud adoption, scalability, cost optimization, and security best practices.
Key Responsibilities:
Cloud Architecture & Design:
- Design and implement scalable, secure, and resilient Azure cloud architectures that align with cloud strategy.
- Develop reference architectures, best practices, and governance frameworks for cloud adoption.
- Define and implement hybrid cloud architectures, integrating on-premises data centers with Azure services.
Cloud Infrastructure & Networking:
- Architect and oversee Azure network components, including Virtual Networks (VNets), VPN Gateways, ExpressRoute, Load Balancers, Azure Firewall, and Network Security Groups (NSGs).
- Ensure high availability and performance across cloud workloads through proper network design and resource allocation.
- Drive modernization efforts by leveraging Azure Virtual WAN, Private Link, and hybrid connectivity solutions.
Security & Compliance:
- Lead cloud security hardening initiatives, implementing Azure Security Center, Defender for Cloud, Microsoft Sentinel, and Zero Trust security models.
- Establish governance and compliance frameworks to ensure adherence to NIST 800-171, GDPR, HIPAA, and other regulatory requirements.
- Design and implement Azure Identity and Access Management (IAM), including Azure Active Directory (AAD), Role-Based Access Control (RBAC), Privileged Identity Management (PIM), and Conditional Access Policies.
Cost Optimization & Governance:
- Develop and enforce cost governance strategies, leveraging Azure Cost Management Billing, Reserved Instances, Spot VMs, and Azure Hybrid Benefit.
- Implement tagging strategies, FinOps methodologies, and cloud cost optimization best practices.
- Work closely with finance teams to provide cost forecasts, budget controls, and resource efficiency recommendations.
Automation & Infrastructure as Code (IaC):
- Define Infrastructure as Code (IaC) best practices using Terraform, Bicep, and ARM templates to automate cloud deployments.
- Oversee CI/CD integration for infrastructure automation using Azure DevOps, GitHub Actions, or Terraform Cloud.
- Implement configuration management and policy enforcement using Azure Policy, Azure Blueprints, and Desired State Configuration (DSC).
Required Qualifications:
- Experience: Minimum 7 years of experience in cloud architecture with a strong focus on Azure infrastructure.
- Azure Expertise: Deep understanding of Azure networking, security, compute, storage, and hybrid connectivity.
- Infrastructure as Code (IaC): Proficiency in Terraform, Bicep, ARM templates, and PowerShell for infrastructure automation.
- Cloud Security & Compliance: Strong knowledge of Azure AD, RBAC, PIM, Conditional Access, Zero Trust Security, and regulatory compliance.
- Cloud Networking: Expert-level experience with VNets, VPNs, ExpressRoute, Azure Load Balancers, and Azure Firewall.
- Cost Optimization: Proven track record in Azure cost governance, Reserved Instances, FinOps, and budget forecasting.
- Monitoring & Incident Response: Experience implementing and managing Azure Monitor, Log Analytics, and Application Insights.
- Certifications:
- Microsoft Certified: Azure Solutions Architect Expert (AZ-305) – Required.
- Microsoft Certified: Azure Security Engineer Associate (AZ-500) – Preferred.
- Microsoft Certified: DevOps Engineer Expert (AZ-400) – Preferred.
Preferred Qualifications:
- Experience working in multi-cloud environments (Azure & AWS).
- Hands-on experience with Azure Kubernetes Service (AKS) and containerization technologies.
- Familiarity with Azure SQL, CosmosDB, Azure Data Lake, and Azure Synapse Analytics.
- Experience with Zero Trust security models and cloud governance frameworks.