Responsibilities
- Prepare for the transition from a CSP to an MCA E-grade subscription
- Implement least privilege principles for all administrative accounts
- Create an automated process for creating, managing, and removing service principals
- Optimize incoming and outgoing internet access and access to various applications
- Optimize the organizational structure of resources and the application of policies at the appropriate level
- Ensure the Azure environment complies with the Microsoft Cloud Security Benchmark
- Define and implement baselines for all resource types in use
- Complete and harmonize the logging, monitoring, and alerting approach
- Guarantee the availability and performance of various Azure services according to agreed SLAs
- Establish automated deployments as the standard
- Provide self-service capabilities for development teams wherever possible
- Develop and implement the first iteration of cost management
- Optimize the approach for evaluating and selecting standard Azure building blocks
- Implement lifecycle management through automated and manual reviews
Required Knowledge & Experience
- Extensive knowledge of Azure and experience in setting up and managing cloud environments
- Experience with Infrastructure as Code (IaC) within Azure, preferably using Bicep, or Terraform with the willingness to transition
- Strong understanding of CI/CD principles and hands-on experience with tools such as Azure DevOps, GitHub Actions, or Jenkins
- Experience with automation and configuration management (e.g., Ansible, PowerShell, or Python)
- Knowledge of Azure security and governance, such as IAM, network security, and policy management
- Familiarity with monitoring and logging within Azure (e.g., Azure Monitor, Log Analytics, and Application Insights)
- Experience with containerization and container orchestration, such as Docker
- Practical experience with Git and version control
- Experience with other technologies is a plus (Zabbix, Linux, etc.), as well as Microsoft Dynamics (FO or Power Platform)