The following skills are essential for this role. Candidates must demonstrate strong proficiency across these areas:
Infrastructure & Automation
- Infrastructure as Code (IaC) — Terraform (primary and non-negotiable) ★ Mandatory
- CI/CD pipeline automation: Bitbucket, Jenkins, XLR, AWS CodePipeline, GitHub Actions
Azure Architecture
- Strong Azure architecture experience: compute, storage, networking, and platform services
- Enterprise-scale Azure landing zones: management groups, subscriptions, and governance models
- Compute platforms: Azure VMs, App Services, Azure Functions, AKS (architecture-level understanding)
Identity & Security
- Identity & access management using Entra ID (Azure AD), RBAC, PIM, and managed identities
- Security architecture: Zero Trust principles, Azure Defender, and secure baseline controls
- Secrets & encryption: Azure Key Vault, certificate and key lifecycle management
- Policy & compliance: Azure Policy, initiatives, and governance enforcement at scale
Networking
- Azure networking (hands-on): hub-spoke VNETs, subnets, NSGs, UDRs, and routing
- Private connectivity: Private Endpoints, Azure DNS (public/private), name resolution patterns
Observability & Resilience
- Observability & operations: Azure Monitor, Log Analytics, alerting and diagnostics
- High availability & DR design: availability zones, regional failover, and backup strategies