OZ Digital LLCremote

Salary
Posted
Jul 21, 2026
Location
Last confirmed open
Jul 24, 2026

What this job asks for AI summary

A senior infrastructure engineering role centered on designing and maintaining hardened Azure environments for consulting clients. Day-to-day work involves managing Azure Landing Zones, leading Terraform code reviews, enforcing zero-trust network controls, and replacing static secrets with identity-based authentication. The role suits an experienced cloud engineer with deep Terraform and Azure networking expertise who is comfortable working alongside senior technical leadership on security-focused infrastructure.

Senior level

Must have (13)
TerraformAzureMicrosoft Entra IDAzure Key VaultOIDCAzure Private LinkPrivate EndpointsGitHub ActionsAzure DatabricksAzure Landing ZonesAzure RBACAZ-305 (Azure Solutions Architect Expert)HashiCorp Terraform Associate or Hashicorp Terraform Advanced
Nice to have (1)
AZ-500 (Azure Security Engineer Associate) or Sc 500

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

Why we read it this way (6)

No work location or metro area is specified in the posting; CBSA fields are left blank. The role may be remote or on-site at a client site — the JD does not clarify.

SOC classification is a genuine judgment call: the role writes and owns Terraform infrastructure-as-code (pointing to 15-1252 Software Developers), but its day-to-day work is heavily operational — managing Azure Landing Zones, network perimeter controls, and identity layers — which also fits 15-1244. The primary deliverable (authoring and reviewing IaC, designing secure infrastructure blueprints) tips the classification toward 15-1252.

Two certifications are explicitly marked 'Required' in the posting (AZ-305 and HashiCorp Terraform Associate or Advanced) and are treated as hard gates. The Terraform cert lists two tiers as acceptable alternatives.

AZ-500 and SC-500 are listed under 'Preferred' certifications and are captured as preferred accordingly.

Split-Horizon Private DNS Zone linking is a specific networking technique called out in the requirements section; it is captured under the broader 'Private Endpoints' / 'Azure Private Link' skills rather than as a separate entry, as it is a configuration pattern within those services rather than a distinct named product.

No compensation, employment type, or experience-year floor is stated in the posting.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗