Remote Principal Cloud Engineer (Microsoft Azure)
Medical Review Institute of America · Salt Lake City, UT · 1 wk ago
RemoteRemoteEngineeringFull-time
Position Overview
Our Principal Cloud Engineer serves as the organization's senior technical authority for cloud architecture and infrastructure, defining standards and governance practices. They also mentor and guide the Systems Administration and Information Security teams, ensuring knowledge is shared through documentation, standards, and coaching.
Roles
- Serve as the highest-level technical authority and subject matter expert for all Azure cloud infrastructure and architecture
- Define cloud engineering standards, architectural patterns, and governance practices that the organization adopts and follows
- Own and lead cloud infrastructure projects end-to-end — from design and planning through execution, delivery, and post-deployment operations
- Mentor and develop the Systems Administration and Information Security teams — building organizational cloud competency through hands-on guidance, deliberate coaching, and knowledge transfer
- Collaborate with Development teams to design and deliver application infrastructure on Azure
- Provide Tier 2/3 escalation support to the IT Help Desk for complex infrastructure and cloud issues
- Partner with the Information Security team to implement and evidence compliance controls for HITRUST 11.3r2 and SOC2
Major Responsibilities or Assigned Duties
- Architect, deploy, and manage a secure Azure cloud environment including hub-spoke network topology, Virtual Networks, Network Security Groups, Azure Firewall, Application Gateway, API Management, and Private Endpoints
- Define and enforce cloud governance standards including subscription management, Azure Policy, resource organization, tagging taxonomy, and cost management across all environments
- Build and own CI/CD pipelines for infrastructure deployments with automated security scanning, testing, and progressive delivery
- Establish change management and release governance processes ensuring all infrastructure changes are reviewable, approved, and auditable in a regulated healthcare environment — without becoming a bottleneck
- Lead cloud migration projects — assess workloads, develop migration strategies, execute cutovers, validate post-migration health, and decommission legacy infrastructure
- Design and deliver Azure infrastructure for new application onboarding; create reusable patterns and templates the team follows for future workloads
- Manage hybrid connectivity including ExpressRoute, VPN Gateway, and site-to-site connectivity between Azure and on-premises environments
- Design and maintain cloud observability covering metrics, logs, and alerting with SLOs that reflect real operational impact — ensuring the team catches issues before they affect the business
- Establish formal incident response processes including runbooks, escalation paths, and post-incident reviews; own disaster recovery and business continuity planning with defined and tested RPO/RTO targets
- Manage Azure identity and access architecture including Entra ID, Role-Based Access Control (RBAC), Privileged Identity Management (PIM), Key Vault, and Managed Identities
- Implement cloud security controls as defined by the Information Security team; build audit logging, evidence generation, and access-review processes that satisfy HITRUST 11.3r2, SOC2, and HIPAA requirements and hold up during audits
- Develop scripting and automation solutions (PowerShell, Python, or Bash) to reduce manual operational burden and improve team efficiency
- Create and maintain comprehensive technical documentation — architecture diagrams, runbooks, standard operating procedures, and how-to guides — that build team knowledge and reduce key-person dependency
- Support after-hours availability and on-call response for critical infrastructure events as requested
Requirements
- 7–10 years of experience in infrastructure, systems, or cloud engineering
- 5 years of senior or principal level experience in Microsoft Azure
- Demonstrated experience building or establishing a cloud engineering practice or function — not just operating an existing one; comfort setting standards others follow
- Expert-level knowledge of Azure networking including hub-spoke topology, Virtual Networks, NSGs, Azure Firewall, Application Gateway, ExpressRoute, Private Endpoints, and DNS
- Proven ability to independently architect Azure environments — designing governance, security, and operational frameworks from the ground up, not inheriting them
- Expert-level experience with Infrastructure as Code (Terraform or Azure Bicep) including module design, state management, CI/CD integration, and enforcement of no-manual-change disciplines
- Strong experience with CI/CD pipeline tooling (Azure DevOps, GitLab, or GitHub Actions) including automated security scanning and progressive delivery practices
- Demonstrated experience leading cloud migration projects including workload assessment, planning, execution, and legacy decommission
- Strong project leadership — able to own and drive multiple complex initiatives simultaneously with minimal oversight
- Proven ability to mentor and develop technical staff across multiple teams; experience building organizational capability through deliberate knowledge transfer and hands-on coaching
- Experience establishing incident response, disaster recovery, and business continuity practices with defined and tested RPO/RTO targets
- Expert-level knowledge of Azure identity and security services including Entra ID, RBAC, PIM, Key Vault, and Defender for Cloud
- Networking and security fundamentals: network segmentation, secrets management, least-privilege access, and certificate lifecycle management
- Proficiency in at least one scripting or automation language (PowerShell, Python, or Bash)
- Working knowledge of compliance frameworks (HITRUST, SOC2, HIPAA) with experience building audit evidence processes that hold up under scrutiny
- Clear written communication and sound judgment under production pressure — able to make decisions and convey technical context to non-technical stakeholders
- Experience with Zero Trust Network Access (ZTNA) solutions preferred
- Experience with Azure AI and platform services preferred
- Familiarity with healthcare data exchange standards (EDI, HL7, or SFTP-based interfaces) preferred