Staff Azure Cloud Engineer, Automation

Posted Yesterday
Be an Early Applicant
Irvine, CA, USA
Hybrid
140K-185K Annually
Senior level
Financial Services
The Role
Lead design and build of an Azure landing zone using Terraform and Azure Verified Modules. Own Terraform Cloud setup, networking/firewall configuration, CI/CD pipelines, policy-as-code guardrails, security/observability baseline, and a self-service application delivery pattern. Collaborate with security, network, and IT teams to codify standards and mentor future hires while executing hands-on implementation.
Summary Generated by Built In
Come for the Challenge. Stay for the Experience.
At HCVT, we believe every challenge presents an opportunity to positively impact our clients and people. Talented and ambitious individuals who seek limitless professional opportunities thrive at HCVT. Our team is known for its technical skill and ability to help clients address complex business issues all while investing in and supporting our people to provide a rewarding employee experience.
 
What We Do and Who We Serve
We offer Tax, Audit, Advisory, and Business Management services to our clients, which include private and public companies, high-net-worth individuals, and family offices. We also specialize in serving clients across the following industries: Private Equity, Real Estate & Hospitality, Media & Entertainment, High-Net-Worth Individuals, Manufacturing & Distribution, Professional Services Firms, Technology, Healthcare, Nonprofit Organizations, and Affordable Housing.  
 
We Live Our Core Values
Our values guide us in our day-to-day interactions with our clients and each other—Integrity at our Core; Building Success Together; Passion for Excellence; and Diversity, Equity, & Inclusion. We are focused and committed to the needs of our clients and our team.
 
Discover How Far You Can Go.
Opportunities abound at HCVT. Our firm has experienced steady growth since its founding in 1991 and continues to expand its client service offerings, creating new opportunities for professionals to grow their careers. We make significant investments in training and provide interesting, diverse, and intellectually stimulating work for our teams—the kind of work that helps you develop and refine your skills to advance in the profession. 
 
Hybrid Work
HCVT currently offers a hybrid work model that allows eligible employees to work both remotely and in the office, based on business needs and team coordination. When working remotely, employees are expected to meet the same performance standards, adhere to the same policies, and maintain the same level of communication, collaboration, and responsiveness as working in the office. Please note that this arrangement is not guaranteed and subject to change at any time. We will strive to provide reasonable notice of any changes to your work location or schedule whenever possible.

About the Role

We are creating a new Azure cloud platform to serve as the foundation for a multi-year cloud modernization program. We need a Lead Azure Cloud Engineer who can walk in, take design ownership, and start building in week one. This is a hands-on, individual-contributor role: you will write the code yourself, stand up the pipelines yourself, and set the technical bar the rest of the teams build against.

You are the senior-most and dedicated cloud engineering voice on this program. You need to be well-rounded: as comfortable troubleshooting a firewall rule or a network route as you are writing a Terraform module or designing the pipeline that deploys it. You will need to work with the firm's existing IT, security, and network teams to land on shared standards, and then you're the one who codifies them into automation.

Tools and Stack You'll Work In

Azure (landing zone, networking, Entra ID) - Terraform + Terraform Cloud - Azure Verified Modules - GitHub Actions - Microsoft Defender for Cloud - Azure Policy - Azure Monitor / Log Analytics - GitHub Copilot / Anthropic Claude (AI-assisted delivery).  Our policy-as-code and shift-left scanning has not been finalized; helping evaluate and select this tooling is part of the role.

An internal developer platform pattern for self-service application delivery (e.g. HashiCorp HCP Waypoint, which integrates with HCP Terraform).

As the Staff Azure Cloud Engineer, you will be responsible for, but not limited to, the following:

  • Design and build the Azure landing zone, aligned to Microsoft's Cloud Adoption Framework design areas (identity, network topology, resource organization, governance, management, security) and reviewed against the Well-Architected Framework's five pillars at each milestone.
  • Build with Azure Verified Modules (AVM) as the base layer, composing right-sized custom Terraform modules on top rather than hand-rolling every resource or adopting the full CAF Enterprise-Scale module wholesale.
  • Own the Terraform Cloud (TFC) setup end to end: workspace structure (one state file per workload per environment), variable sets, run triggers, and remote state strategy.
  • Own hands-on networking and firewall configuration: hub-spoke topology, NSGs, Azure Firewall, WAF rules, private endpoints, and DNS. There is no separate network architect on this program; you need to be able to design, configure, and troubleshoot these yourself, informed by the firm's existing network/security teams.
  • Work with internal teams to define our to-be cloud native software engineering practice and process, then codify it. Coding standards, module and repo conventions, branching and review workflow, policy-as-code approach, and the shift-left tooling chain (scanning, testing, gating) are not yet decided. You  will work with the firm's existing security and engineering teams to land on a standard, and then turns that into working Terraform, pipelines, and documentation.
  • Establish policy-as-code guardrails (approach and tooling still to be decided, e.g. HashiCorp Sentinel, OPA, or another option you recommend and help evaluate) so that governance is enforced automatically on every plan
  • Build the CI/CD pipeline for infrastructure changes: automatic plan on every pull request, mandatory human review, manual apply gate
  • Help stand up our shift-left scanning practice: the goal is that IaC, code, and dependency issues are caught early in the engineering cycle.
  • Set up the security and observability baseline: Microsoft Defender for Cloud, centralized Log Analytics, Azure Policy at the management-group scope, hub-spoke network segmentation, and private endpoints.
  • Coordinate with the firm's identity/security and network teams on Entra ID architecture (app registrations, Conditional Access, PIM) and network/firewall standards.
  • Set the technical example for module structure, versioning, documentation, and code review standards that future hires on this program will follow as the team grows.
  • Extend the paved path from infrastructure to application delivery. Define a golden, self-service deployment pattern so Backend and Frontend engineers can ship application code onto the landing zone without hand-rolling their own pipelines.

We expect that our Staff Azure Cloud Engineer will have the following qualifications:

  • 6+ years in cloud infrastructure/platform engineering, with real production ownership, not just POCs.
  • A well-rounded Azure Cloud generalist, comfortable across Terraform/IaC, Azure networking, and firewalls/network security,
  • Deep, hands-on Terraform experience: module authorship, remote state, workspace/environment strategy, version pinning, and awareness of the tradeoffs in monorepo vs. per-module repo structures.
  • Strong, hands-on Azure networking and security: hub-spoke topology, NSGs, Azure Firewall, WAF rules, private endpoints, DNS, and hybrid/legacy connectivity patterns, plus identity (Entra ID, RBAC, managed identity) and governance (management groups, Azure Policy).
  • Working knowledge of SOC 2 control families (access control, change management, logging/monitoring, network security) well enough to design a landing zone that satisfies them by default, even without prior formal audit experience.
  • Able to work effectively with the firm's existing security, network, and IT teams
  • Direct experience building CI/CD pipelines for infrastructure changes (GitHub Actions, Azure DevOps, or equivalent), including plan/apply gating patterns.
  • Working knowledge of policy-as-code approaches (e.g. Sentinel, OPA) and IaC/security scanning practices.
  • Comfortable being the first cloud engineer on the program: able to make and defend decisions yourself.
  • Strong scripting ability (PowerShell, Bash, or Python) for tooling and automation glue.
  • Comfortable defining a self-service application deployment pattern (a “golden path”) that other engineers can use to ship application code without needing deep Terraform expertise themselves.
  • Preferred Qualifications
  • Direct experience with Terraform Cloud/Enterprise specifically (not just open-source Terraform CLI).
  • Prior experience building a landing zone from zero, versus inheriting and extending one.
  • Experience consuming (or ideally contributing to) Azure Verified Modules.
  • Direct experience operating in a compliance-driven environment (SOC 2, HIPAA, or similar) through an actual audit cycle, where controls needed to be demonstrable, not just implemented.
  • Experience mentoring other infrastructure/platform engineers.
  • Experience with HashiCorp HCP Waypoint, or a similar internal developer platform (IDP) approach, for standardizing self-service application deployment.
  • HashiCorp Terraform Associate or Professional certification.
  • Microsoft certifications: AZ-305 (Solutions Architect) and/or AZ-400 (DevOps Engineer); AZ-500 (Security) is a plus.

You Matter - HCVT provides a variety of benefits and perks that help sustain a healthy and thriving work environment.

  • Visit the Benefits section to learn more.

This salary range is specific to the state(s) listed and takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill set and education; experience and training; licensure and certifications; and other business and organizational needs. A reasonable estimate of the range for this position is $140,000 to $185,000.
 
Connect with us: 
LinkedInInstagramFacebookHCVT Website
 
#LI-GC1
#LI-Hybrid

The ordinance requires employers to state, in all job solicitations, postings and advertisements, that the employer will consider applicants in a manner consistent with the requirements of the Fair Chance Initiative.  
 

Skills Required

  • 6+ years in cloud infrastructure/platform engineering with production ownership
  • Well-rounded Azure Cloud generalist across Terraform/IaC, Azure networking, and firewall/network security
  • Deep, hands-on Terraform experience including module authorship, remote state, workspace strategy, and versioning
  • Strong hands-on Azure networking and security: hub-spoke topology, NSGs, Azure Firewall, WAF, private endpoints, DNS, hybrid connectivity
  • Identity and governance experience: Entra ID, RBAC, managed identity, management groups, Azure Policy
  • Working knowledge of SOC 2 control families (access control, change management, logging/monitoring, network security)
  • Ability to work effectively with internal security, network, and IT teams
  • Direct experience building CI/CD pipelines for infrastructure changes (GitHub Actions, Azure DevOps, or equivalent) including plan/apply gating
  • Working knowledge of policy-as-code approaches (e.g., Sentinel, OPA) and IaC/security scanning practices
  • Comfortable being the first cloud engineer on a program and making/defending architectural decisions
  • Strong scripting ability (PowerShell, Bash, or Python) for tooling and automation
  • Ability to define a self-service application deployment pattern (golden path) for other engineers
  • Direct experience with Terraform Cloud/Enterprise
  • Prior experience building a landing zone from zero
  • Experience consuming or contributing to Azure Verified Modules
  • Direct experience operating in a compliance-driven environment (SOC 2, HIPAA, etc.) through an audit cycle
  • Experience mentoring other infrastructure/platform engineers
  • Experience with HashiCorp HCP Waypoint or similar internal developer platform
  • HashiCorp Terraform Associate or Professional certification
  • Microsoft certifications AZ-305 and/or AZ-400 (AZ-500 a plus)
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: West Los Angeles, CA
683 Employees
Year Founded: 1991

What We Do

We are a Top 30 CPA firm headquartered in Los Angeles, providing tax, audit and assurance, business management, mergers & acquisition, and valuation advisory services to clients across a wide variety of industries. Our engagement teams are business-focused, and our business model is built on partner access and advice. We have been recognized by Inside Public Accounting as one of the “Best of the Best” firms for a record 17 consecutive years, validating we do the right things for our people, our clients, and our communities. With a team of over 700 members operating from nine offices throughout California, and offices in Arizona, Texas, and Utah, we have the scale and bench strength to meet your needs—whether a business, nonprofit organization or a high net worth individual. We are known in the marketplace as a firm with deep technical skills addressing the most complex tax issues associated with partnerships and pass-through entities. Clarifying and resolving complex issues is what we do. How we do it is what sets us apart from other CPA firms. To learn more about HCVT, visit us at www.hcvt.com. If you’d like to be a part of our team, connect with us at [email protected] or visit https://jobs.lever.co/hcvt.

Similar Jobs

HCVT Logo HCVT

Cloud Engineer

Financial Services
Hybrid
Westlake Village, CA, USA
683 Employees
140K-185K Annually

Taboola Logo Taboola

Senior Data Scientist

AdTech • Big Data • Digital Media • Marketing Tech
Hybrid
Los Angeles, CA, USA
1900 Employees
139K-185K Annually

CDW Logo CDW

Consultant

Information Technology
Remote or Hybrid
US
15100 Employees
156K-241K Annually

Golden Hippo Logo Golden Hippo

Total Rewards Specialist

Digital Media • eCommerce • Information Technology • Marketing Tech • Retail • Social Media • Analytics
Hybrid
Woodland Hills, CA, USA
500 Employees
56K-75K Annually

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account