Cloud Infrastructure / DevOps Engineer / Platform
About the Role
Design and implement the complete Terraform OSS infrastructure as code (IaC) architecture for the Data Analytics Platform (DAP), including:
- Module structure (networking, compute, storage, security, governance, Fabric)
- Environment-specific variable files
- Remote state backend configuration (Azure ADLS Gen2 with state locking)
- Branching strategy in Azure DevOps
Design the Azure Management Group hierarchy and subscription architecture aligned with Microsoft's Azure Landing Zone (Enterprise Scale) principles, adapted for NCDHHS DHB governance requirements.
Design a Hub-Spoke network topology including:
- Azure Firewall with deny-by-default rules
- Private endpoints for all Azure and Fabric services
- Azure Private DNS zones
- Azure Bastion for administrative access
- VPN/ExpressRoute configuration
Design Azure DevOps CI/CD pipeline architecture for all version-controllable DAP assets:
- Terraform IaC
- Azure Data Factory pipeline definitions
- Fabric Notebook code
- Power BI deployments
- SQL scripts
Design a GitFlow branching strategy with the following workflow: feature branches → develop → release → main/production. Implement pull request policies enforcing minimum reviewer requirements, automated test passes, and security scan passes before merge.
Design a drift detection approach using scheduled Azure DevOps pipelines to alert on configuration drift from declared Terraform state.
Responsibilities
Development and Build Phase
- Provision all four DAP environments (Development, Test, UAT, Production) using Terraform IaC, ensuring 100% infrastructure as code coverage with no manually provisioned resources in any environment
- Implement Azure DevOps CI/CD pipelines for all infrastructure and application assets with mandatory Checkov and tfsec security scanning gates that block deployment on HIGH or CRITICAL findings
- Configure Azure Management Group hierarchy, Azure Policy assignments (including tag enforcement, allowed resource types, and security baseline policies), and subscription-level governance controls
- Build and maintain Hub-Spoke network topology with private endpoints, NSGs, and Azure Firewall across all environments
- Implement daily drift detection pipeline with Azure Monitor and Teams alerting for any infrastructure state divergence
- Manage Terraform state in Azure ADLS Gen2 with state locking, versioning, and minimum-privilege managed identity access control
- Configure Azure Monitor Log Analytics workspace, diagnostic settings for all platform services, and ServiceNow integration via Azure Monitor Action Groups for automated incident creation
- Provision and manage Microsoft Fabric capacities (F-SKU) across all environments, including auto-scaling configuration and capacity pause scheduling for non-production overnight windows to reduce cost by 60–70%
- Configure Azure Cost Management budgets, alerts, and tagging enforcement policies to support FinOps reporting requirements
Testing and Parallel Run Phase
- Ensure all test environments (Test, UAT) mirror production in security configuration, data protection measures, and reporting, maintained through the same Terraform IaC as production
- Execute Disaster Recovery test by failing over production workloads to the secondary Azure Government region, validating RTO/RPO targets, and producing DR test results documentation
- Support security penetration testing by providing infrastructure access and configuration documentation to the security assessment team
- Execute production readiness validation checklist, confirming all infrastructure components are fully operational and monitored before go-live
Go-Live and O&M Responsibilities
- Execute infrastructure components of the go-live cutover runbook: production environment activation, final smoke testing, monitoring validation, and rollback capability maintenance
- Administer the full Azure and Fabric platform infrastructure throughout O&M: subscription management, Terraform IaC updates for all infrastructure changes, Fabric capacity management and scaling
- Manage security patching and vulnerability remediation within required SLA timeframes, coordinating with the Security Architect for all HIGH and CRITICAL findings
- Conduct quarterly FinOps reviews, analyzing Azure Cost Management data, identifying right-sizing opportunities, and presenting optimization recommendations to NCDHHS
- Maintain all CI/CD pipelines, update Terraform provider versions, and manage infrastructure changes through a formal change control process with State approval
Requirements
Minimum Qualifications
- Bachelor's degree in Computer Science, Information Technology, Systems Engineering, or a related field
- Minimum 5 years of experience in cloud infrastructure engineering, DevOps, or platform administration, with at least 3 years on Microsoft Azure or Azure Government
- Demonstrated proficiency with Terraform OSS for infrastructure as code, including module design, remote state management, and CI/CD integration
- Experience with Azure DevOps: repositories, pipelines (YAML), pull request policies, environments, and deployment gates
- Experience deploying and managing Microsoft Azure networking components: Virtual Networks, Hub-Spoke topology, NSGs, private endpoints, Azure Firewall, and Azure Private DNS
- Experience with Azure services relevant to the DAP: Azure Monitor, Log Analytics, Cost Management, Azure Policy, and Azure Key Vault
- Experience with GitFlow branching strategy and Git-based version control
- Experience with CI/CD security scanning tools (Checkov, tfsec, or equivalent)
Preferred Qualifications
- Microsoft Certified: Azure Administrator Associate (AZ-104) or Azure DevOps Engineer Expert (AZ-400)
- Experience with Microsoft Fabric capacity administration and workspace governance
- Experience with FinOps practices and Azure Cost Management for cost optimization in government cloud environments
- Experience with ServiceNow ITSM integration for automated incident management
- Experience in state or federal government cloud environments with FedRAMP authorization requirements
- Terraform Associate certification or equivalent