Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузи резюме
О рекламодателе
ОБЩЕСТВО С ОГРАНИЧЕННОЙ ОТВЕТСТВЕННОСТЬЮ "ЦЕНТР НАЦИОНАЛЬНЫХ ИНТЕЛЛЕКТУАЛЬНЫХ СИСТЕМ" ИНН: 9704271170
описание
The team is delivering a Unified Automation Platform, an Internal Developer Platform (IDP) that standardizes new-project delivery, centralizes access to development resources, and enables software creation through templates and golden paths. It provides self-service capabilities across hybrid environments spanning Azure and on-premises VMware.
задачи
Architect Infrastructure as Code modules for Azure services, databases, and Azure VMware Solution, including managed-identity wiring, private endpoints, and diagnostic settings
Define Azure identity architecture in partnership with the security team, covering Entra ID, Active Directory, Group Policy Objects, M365 groups, SPN/app registrations, managed identities, and secrets storage in OpenBao/Key Vault
Design the Azure Kubernetes Service platform, including clusters, node pools, baseline add-ons, namespace and tenant onboarding, and an operations dashboard
Collaborate with the Network Architect on core connectivity, Azure Firewall, NSGs, DNS, NetBox IPAM, and ExpressRoute, ensuring Azure modules integrate with the network foundation
Define the Image Factory architecture for VM and container golden images, including Linux and Windows/cloudbase-init baselines, CIS hardening, agent injection, image scanning, and Shared Image Gallery publishing and versioning
Establish Infrastructure as Code Engine standards, including remote state/backend, locking, RBAC, module registry, testing framework, drift detection, policy hooks, and secrets injection
Partner with the Backstage Architect to expose Azure provisioning capabilities as Backstage golden-path templates
Partner with Integration Architects on observability, ITSM/CMDB, and security integrations involving Azure resources
Provide architectural governance during implementation, validate production deployments, and support module lifecycle ownership during adoption
требования
10+ Years of Azure solution or enterprise architecture experience
Deep expertise in Terraform/OpenTofu for Azure infrastructure automation, including module design, state management, and CI/CD-driven deployment pipelines using Azure DevOps
Working knowledge of Azure networking constructs, including VNets, private endpoints, and NSGs, to integrate compute and data modules with the network foundation
Hands-on experience architecting Azure Kubernetes Service at production scale, including networking, policy, and multi-tenant namespace design
Background in Azure identity and access architecture, including Entra ID, Active Directory, managed identities, and RBAC, as well as secrets integration
Proficiency in Ansible for VM post-provisioning and golden-image pipelines
Excellent written and spoken English (B2+), with strong technical communication skills
Будет плюсом: Microsoft Azure partner-level engagements or equivalent certifications, Azure VMware Solution private cloud provisioning, certificate lifecycle management platforms such as Venafi and their integration with Azure Key Vault, integrating Azure infrastructure automation with a Backstage-based or comparable developer portal, policy-as-code engines such as OPA/Conftest and Azure Policy, prior experience in large-scale multi-region Azure landing-zone or platform engineering