Overview
Skills
Job Details
Job Description: Cloud Architect - Azure Golden Image and Auto-Patching
Position Title: Cloud Architect - Azure Golden Image and Auto-PatchingDepartment: Cloud Center of Excellence (CCOE)Location: Remote (US-based, supporting US West 3 and US East 2 regions) imeReports To:
Job Summary:The Cloud Architect - Azure Golden Image and Auto-Patching will lead the design and governance of the CCOE s Azure golden image rollout and auto-patching solution in Phase 1 of the Azure Foundation Services Plan. This role will architect a standardized, secure, and automated VM management framework across US West 3 (primary) and US East 2 (secondary) regions, using Terraform exclusively for provisioning. The architect will ensure alignment with the Security Adoption Framework (SAF), Palo Alto Networks Panorama, multi-region DR requirements, and Jira for task management, while driving stakeholder enablement through training and governance.
Key Responsibilities:
* Solution Architecture and Design (40%):
* Design Terraform-based architecture for Azure Shared Image Gallery and Azure Update Management, ensuring multi-region replication (US West 3 and US East 2) for DR.
* Define golden image specifications, including SAF-compliant security baselines, Azure Monitor/Log Analytics agents, managed firewall rules, and workload-specific software (e.g., PowerShell, .NET, Node.js).
* Architect Terraform modules for image creation pipelines, Shared Image Gallery setup, RBAC policies, and Azure Policy to enforce golden image usage.
* Design auto-patching schedules (e.g., monthly for Prod, weekly for Non-Prod) and compliance reporting via Azure Monitor and Azure Automation, provisioned via Terraform.
* Ensure Panorama HA synchronizes VM firewall policies across regions, integrated via Terraform.
* Governance and Policy (20%):
* Develop Azure Policies via Terraform to enforce golden image and auto-patching compliance, aligned with SAF.
* Define RBAC policies for team access to golden images, provisioned via Terraform.
* Establish governance frameworks for patch approval workflows, tracked in Jira.
* Update SAF documentation with VM image and patching compliance requirements, tracked in Jira.
* Integration and Dependencies (20%):
* Oversee integration of golden image deployment into Azure DevOps pipelines using Terraform, tracked in Jira.
* Ensure logging and monitoring of VMs via Azure Monitor, provisioned via Terraform, with compliance dashboards in Jira.
* Coordinate with networking teams to apply Panorama firewall policies to VMs, provisioned via Terraform, tracked in Jira.
* Align golden image and auto-patching dependencies with Phase 1 services (e.g., Governance, Networking, CI/CD).
* Stakeholder Enablement and Leadership (20%):
* Lead the creation of the CCOE-VMImages Jira project, defining epics, stories, and tasks for image creation, patching, and team adoption.
* Develop training materials and onboarding guides for golden image access and auto-patching, tracked in Jira.
* Collaborate with the CCOE training team to deliver workshops for all teams, ensuring adoption by Month 6, tracked in Jira.
* Provide technical leadership to engineers, reviewing Terraform code and resolving complex issues, tracked in Jira.
Qualifications:
* Bachelor s degree in Computer Science, Information Technology, or related field (or equivalent experience).
* 7+ years of experience designing cloud infrastructure solutions, with 5+ years focused on Azure.
* 4+ years of experience with Terraform for IaC, including advanced module design and multi-region deployments.
* Expertise in Azure Shared Image Gallery, Azure Image Builder, Azure Update Management, Azure Monitor, and Azure Automation.
* Strong knowledge of SAF, Palo Alto Networks Panorama, and multi-region DR architectures.
* Experience with Azure Policy, RBAC, and governance frameworks.
* Proficiency with Jira for project management and Azure DevOps for CI/CD pipelines.
* Excellent leadership, communication, and stakeholder management skills.
Preferred Skills:
* Azure certifications (e.g., AZ-305, AZ-400).
* Experience architecting secure VM management solutions at enterprise scale.
* Knowledge of network security integration with Panorama.
Tools and Technologies:
* Terraform, Azure Shared Image Gallery, Azure Image Builder, Azure Update Management, Azure Monitor, Azure Automation, Azure DevOps, Jira, Azure DevOps Wiki, Palo Alto Networks Panorama.
Success Metrics:
* 100% of teams using golden images by Month 6, tracked in Jira.
* 95% patching compliance for critical/security updates, monitored via Azure Monitor and Jira.
* 100% of golden images replicated to US East 2 for DR, verified via Terraform.
* 90% stakeholder satisfaction with training and onboarding, measured via Jira feedback.
Why Join Us?Lead a transformative cloud initiative within the CCOE, architecting secure and scalable VM management solutions for a global enterprise. Drive innovation using Terraform, Azure, and advanced security tools, shaping the future of cloud operations.