About the role
Key Responsibilities
• Address and close findings identified through cloud security assessments, vulnerability scans, and audits, while tracking remediation progress and maintaining clear evidence of resolution.
• Strengthen and secure Azure configurations in line with established standards across compute, storage, networking, key management, and logging.
• Implement Azure Policy, tagging, and governance controls across subscriptions and management groups. Review RBAC and privileged access assignments and remove outdated or unused resources.
• Build Azure landing zone components based on the approved architecture, including subscription and resource group structures, spoke VNets, subnets, route tables, security groups, private endpoints, and private DNS zones.
• Set up hybrid connectivity using VPN Gateway, ExpressRoute, and network peering, while implementing firewall rules aligned with the agreed network segmentation and business requirements.
• Use Infrastructure as Code where appropriate to deploy landing zone components in a consistent, scalable, and repeatable manner.
• Evaluate applications planned for cloud migration, identifying key dependencies, connectivity needs, data flows, and potential technical constraints.
• Deliver migration activities to Azure infrastructure and platform services, covering environment build, data migration, testing, cutover, and rollback, while coordinating with application, Windows, and Linux teams.
• Ensure migrated workloads meet required standards for performance, resilience, backup, and monitoring. Configure logging and alerting for appropriate security visibility and support the decommissioning of legacy infrastructure following approval.
• Maintain comprehensive as-built documentation and operational runbooks, follow established change management and security standards, ensure rollback procedures are tested, and conduct structured knowledge transfer with the permanent team.
Requirements
• 5+ years of hands-on experience in Azure engineering, with proven involvement in cloud migration, remediation, or infrastructure transformation projects.
• Demonstrated ability to implement solutions based on an established architecture while adhering to technical standards and formal change management processes.
• Strong working knowledge of core Azure services, including compute, storage, networking, Azure Policy, RBAC, and resource governance.
• Solid Azure networking experience across virtual networks, subnets, security groups, route tables, private endpoints, private DNS, VPN Gateway, and ExpressRoute.
• Experience with identity and secrets management, including Entra ID, RBAC, Privileged Identity Management, Key Vault, and managed identities.
• Hands-on experience with Infrastructure as Code and automation tools such as Terraform or Bicep, as well as PowerShell, Azure CLI, and CI/CD pipelines.
• Familiarity with Azure migration technologies, including Azure Migrate, Site Recovery, backup and replication solutions, and application dependency mapping.
• Experience with operational and monitoring tools such as Azure Monitor, Log Analytics, alerting, and cloud cost management.
• Experience working in regulated or security-sensitive environments, with an understanding of least-privilege access, controlled privileged access, and strict data-handling requirements. Financial services experience is a plus.
• Willingness to work on-site in Singapore and support planned out-of-hours migration or cutover activities. Strong documentation discipline and the ability to complete required background screening and third-party access checks are also expected.
Application
Dear Applicant,
If you or someone you know is interested, please send the CV directly to Ryan.Nguyen@evolutionjobs.sg (most preferred, as I may overlook some CVs due to the high volume).
Please note that visa sponsorship is not available at this time.
