Given that mix, I’d title this Cloud Engineer or Senior Cloud Engineer and make it explicitly multi-cloud, with cloud platform engineering, governance, security, identity, connectivity, data platforms, and cost optimization all in scope.
Cloud Engineer – Azure, AWS & Cloud Platform EngineeringPosition SummaryThe Cloud Engineer is responsible for designing, implementing, securing, automating, and operating enterprise cloud infrastructure across Microsoft Azure and Amazon Web Services (AWS).
This position supports the organization's cloud strategy by building standardized cloud landing zones, establishing secure connectivity between cloud and on-premises environments, implementing identity and access controls, supporting cloud-native data platforms such as Snowflake and Databricks, and maintaining appropriate cloud security and financial governance.
The Cloud Engineer works closely with Infrastructure, Information Security, Network Engineering, Application Development, Data Engineering, Architecture, and Finance teams to provide secure, reliable, scalable, and cost-effective cloud services.
The successful candidate will combine hands-on cloud engineering expertise with a strong understanding of automation, security, identity, networking, governance, and FinOps principles.
Key ResponsibilitiesAzure & AWS Cloud EngineeringDesign, deploy, administer, and support enterprise infrastructure across Microsoft Azure and AWS.
Provision and maintain cloud compute, storage, networking, identity, security, and platform services.
Establish repeatable standards for cloud infrastructure deployment and configuration.
Support production and non-production cloud environments throughout their lifecycle.
Implement high-availability, resiliency, backup, and disaster-recovery capabilities.
Troubleshoot complex cloud infrastructure, application connectivity, identity, performance, and security issues.
Evaluate cloud-native services and recommend appropriate solutions based on business, technical, security, and financial requirements.
Maintain cloud architecture diagrams, standards, runbooks, and operational documentation.
Design, implement, and maintain enterprise landing zones in Azure and AWS.
Establish standardized account, subscription, management group, organizational unit, network, identity, logging, security, and tagging structures.
Implement cloud governance through Azure Policy, AWS Organizations, Service Control Policies, and related controls.
Establish guardrails that enable development teams to use cloud services while maintaining security and compliance requirements.
Maintain naming, tagging, resource organization, and lifecycle standards.
Support account and subscription provisioning through standardized and automated processes.
Develop reusable infrastructure patterns for application and development teams.
Implement controls to identify and prevent cloud configuration drift.
Participate in cloud architecture and design reviews.
Design and support connectivity between cloud environments, data centers, offices, and external services.
Configure and maintain Azure Virtual Networks and AWS VPCs.
Support Azure ExpressRoute and AWS Direct Connect connectivity.
Configure and troubleshoot routing, peering, private endpoints, network security groups, DNS, NAT, VPN, and firewall connectivity.
Implement secure private connectivity to cloud services wherever appropriate.
Work with Network and Security teams to maintain appropriate segmentation between cloud environments and application tiers.
Troubleshoot complex hybrid-cloud connectivity issues.
Understand cloud traffic flows sufficiently to identify routing, DNS, firewall, identity, application, and service-endpoint problems.
Integrate cloud platforms and applications with Microsoft Entra ID.
Implement and support identity federation and Single Sign-On (SSO).
Manage Azure RBAC, AWS IAM roles and policies, service identities, managed identities, and application identities.
Implement least-privilege access models.
Support privileged-access management and administrative access controls.
Implement Conditional Access and multi-factor authentication requirements in coordination with Information Security.
Support automated identity provisioning and deprovisioning where appropriate.
Review and remediate excessive, stale, or inappropriate cloud permissions.
Assist with cloud identity governance and periodic access reviews.
Administer and support Upwind as part of the organization's cloud security program.
Use Upwind to identify cloud vulnerabilities, configuration risks, runtime threats, attack paths, and workload exposure.
Investigate cloud security findings and coordinate remediation with Infrastructure, Security, DevOps, and Application teams.
Assist with prioritizing vulnerabilities based on actual workload exposure and runtime risk.
Support cloud workload protection across virtual machines, containers, Kubernetes, and cloud-native services.
Implement secure cloud configuration standards and guardrails.
Review cloud security posture and identify opportunities to reduce attack surface.
Integrate cloud security findings into vulnerability-management and security-operations processes.
Assist Information Security with cloud incident investigation and response.
Support the cloud infrastructure and platform components required for Snowflake and Databricks environments.
Assist with provisioning, connectivity, identity, security, and governance of enterprise data platforms.
Configure private connectivity and secure network access to cloud data services.
Integrate Snowflake and Databricks authentication with enterprise identity platforms.
Support storage, compute, networking, and security configurations associated with data workloads.
Work with Data Engineering and Analytics teams to establish scalable and secure platform architectures.
Assist with capacity, performance, and cost optimization of cloud data platforms.
Maintain appropriate separation between development, testing, and production data environments.
Support security and compliance requirements for sensitive and regulated data.
Develop and maintain Infrastructure as Code (IaC) for cloud infrastructure.
Automate deployment of cloud accounts, subscriptions, networks, security controls, and common infrastructure components.
Develop reusable cloud modules and deployment patterns.
Use technologies such as Terraform, Bicep, ARM, CloudFormation, PowerShell, Python, or equivalent automation platforms.
Integrate infrastructure deployment with CI/CD pipelines.
Implement appropriate source control, peer review, testing, and change-management practices.
Reduce manual cloud configuration wherever practical.
Identify repetitive operational processes that can be automated.
Participate in the organization's FinOps program and promote financial accountability for cloud consumption.
Monitor Azure, AWS, Snowflake, and Databricks consumption and spending.
Establish tagging and ownership standards that provide visibility into cloud costs.
Develop cost allocation and chargeback/showback capabilities.
Identify unused, underutilized, oversized, or orphaned cloud resources.
Recommend rightsizing, reservations, savings plans, storage-tiering, scheduling, and other optimization opportunities.
Analyze cloud cost trends and investigate unexpected spending increases.
Work with Finance, Procurement, Infrastructure, Application, and business teams to develop cloud budgets and forecasts.
Assist with evaluating the financial impact of architecture decisions.
Establish cost alerts, budgets, thresholds, and reporting.
Track realized savings from cloud optimization initiatives.
The Cloud Engineer is expected to consider cost as an architectural attribute alongside security, performance, availability, and scalability.
Monitoring, Reliability & OperationsImplement monitoring, logging, alerting, and observability across cloud environments.
Monitor cloud platform health, availability, capacity, performance, security, and cost.
Respond to cloud infrastructure incidents and participate in root-cause analysis.
Support application teams during production incidents involving cloud infrastructure.
Participate in an on-call rotation as required.
Maintain operational dashboards and alerting standards.
Develop and maintain cloud recovery procedures.
Participate in disaster-recovery and business-continuity testing.
Work with vendors and cloud providers to resolve complex technical issues.
Implement cloud infrastructure according to organizational security standards.
Support compliance requirements applicable to cloud environments.
Participate in vulnerability remediation and cloud security reviews.
Ensure encryption is appropriately implemented for data at rest and in transit.
Maintain secure management interfaces and privileged-access paths.
Support centralized cloud logging and security monitoring.
Participate in security incident investigation involving cloud resources.
Assist with evidence collection for audits and security assessments.
Support environments subject to HIPAA, HITRUST, SOC 2, ISO 27001, or similar security and regulatory requirements.
3–5+ years of infrastructure, cloud engineering, DevOps, or related technical experience.
Hands-on experience with Microsoft Azure and/or AWS, with working knowledge of both platforms strongly preferred.
Experience designing or operating enterprise cloud landing zones.
Strong understanding of cloud networking, routing, DNS, private connectivity, and hybrid-cloud architecture.
Experience with Azure ExpressRoute and/or AWS Direct Connect.
Experience with Microsoft Entra ID and cloud identity/access management.
Understanding of Azure RBAC and AWS IAM.
Experience with Infrastructure as Code and automation.
Understanding of cloud security principles and cloud workload protection.
Experience supporting enterprise production environments.
Strong troubleshooting and analytical skills.
Strong written and verbal communication skills.
Hands-on experience with Upwind or another CNAPP/cloud security platform.
Experience with Snowflake.
Experience with Azure Databricks and/or AWS-hosted Databricks.
Terraform experience.
Experience with Azure Policy and AWS Organizations/SCPs.
Experience with Kubernetes and containerized workloads.
Experience implementing Azure and AWS landing-zone architectures.
Experience with Azure ExpressRoute and AWS Direct Connect.
Experience with Microsoft Entra Conditional Access, managed identities, and enterprise application integration.
Experience with cloud-native monitoring and logging platforms.
Experience implementing FinOps practices in a multi-cloud environment.
Familiarity with the FinOps Framework.
Azure, AWS, Terraform, Kubernetes, FinOps, or security-related certifications are desirable.
Cloud Architecture: Understands how networking, identity, compute, storage, security, data platforms, and governance combine to form an enterprise cloud platform.
Automation: Approaches cloud infrastructure as software and favors repeatable, version-controlled deployments over manual configuration.
Security: Incorporates security into architecture and operations rather than treating security as a final approval step.
Financial Awareness: Understands that cloud engineering decisions directly affect operating expense and actively considers cost when designing solutions.
Troubleshooting: Can systematically isolate problems involving cloud networking, identity, security, infrastructure, and application dependencies.
Governance: Balances developer agility with enterprise requirements for security, standardization, compliance, reliability, and financial control.
Ownership: Takes responsibility for cloud services through design, deployment, operations, troubleshooting, optimization, and eventual retirement.
Collaboration: Works effectively across Infrastructure, Security, Networking, Application Development, Data Engineering, Architecture, Finance, and business teams.
Performance ExpectationsSuccess in this role will be evaluated based on:
Reliability and availability of cloud infrastructure.
Adoption and consistency of standardized landing zones.
Successful automation of cloud provisioning and configuration.
Reduction in manual cloud administration.
Cloud security posture and remediation of identified risks.
Appropriate identity and access controls.
Reliability of hybrid-cloud connectivity.
Cloud cost visibility and optimization.
Reduction of unused and underutilized cloud resources.
Successful delivery of cloud projects.
Quality of documentation and operational procedures.
Successful disaster-recovery testing.
Effectiveness in supporting Snowflake, Databricks, and other cloud platforms.
Collaboration with Infrastructure, Security, Data, Development, Finance, and Architecture teams.
One thing I deliberately did here is make FinOps a real engineering responsibility rather than a reporting exercise. For the environment you're building, the engineer should understand that choosing an oversized Azure VM, leaving Databricks compute running, poorly managing Snowflake consumption, or failing to use reservations/savings plans is an architectural issue—not just something Finance discovers later. I also made landing zones and guardrails central so this person is building the cloud platform rather than becoming a ticket-driven Azure/AWS administrator.
Skills Required
- 3-5+ years of infrastructure, cloud engineering, DevOps, or related technical experience
- Hands-on experience with Microsoft Azure and/or AWS; working knowledge of both platforms preferred
- Experience designing or operating enterprise cloud landing zones
- Strong understanding of cloud networking, routing, DNS, private connectivity, and hybrid-cloud architecture
- Experience with Azure ExpressRoute and/or AWS Direct Connect
- Experience with Microsoft Entra ID and cloud identity and access management
- Understanding of Azure RBAC and AWS IAM
- Experience with Infrastructure as Code and automation
- Understanding of cloud security principles and cloud workload protection
- Experience supporting enterprise production environments
- Strong troubleshooting and analytical skills
- Strong written and verbal communication skills
- Hands-on experience with Upwind or another CNAPP/cloud security platform
- Experience with Snowflake
- Experience with Azure Databricks and/or AWS-hosted Databricks
- Terraform experience
- Experience with Azure Policy and AWS Organizations or Service Control Policies
- Experience with Kubernetes and containerized workloads
- Experience implementing Azure and AWS landing-zone architectures
- Experience with Microsoft Entra Conditional Access, managed identities, and enterprise application integration
- Experience with cloud-native monitoring and logging platforms
- Experience implementing FinOps practices in a multi-cloud environment
- Familiarity with the FinOps Framework
- Azure, AWS, Terraform, Kubernetes, FinOps, or security-related certifications
What We Do
Founded in 1994 and headquartered in Conshohocken, Pennsylvania, MedRisk was established with a mission to revolutionize physical rehabilitation for workers' compensation patients. Over the last 30 years, the company has evolved into a leading managed care organization dedicated to physical rehabilitation and medical bill review for the casualty claims industry.







