job summary:
We're seeking an Azure Engineer with ITOps expertise to work on a team focused on keeping the systems secure, stable, and available. The ideal candidate will bring deep expertise in production support, strong analytical and troubleshooting skills, and a genuine passion for ensuring critical systems operate smoothly and efficiently. You'll collaborate closely with product, security, and operations teams to automate everything-provisioning, deployments, observability, incident response, and compliance-while supporting a rotational shift model to ensure 24x7 coverage.
location: Telecommute
job type: Contract
salary: $70 - 80 per hour
work hours: 9am to 5pm
education: Bachelors
responsibilities:
- Design, build, and maintain Azure landing zones and platform services (e.g., VNet, Private Endpoints, Key Vault, Azure Firewall/NSGs, Application Gateway/WAF)
- Implement Infrastructure as Code (IaC) with Terraform and/or Bicep; enforce GitOps workflows (branching, PRs, policy checks)
- Create reusable modules, pipelines, and golden patterns for app teams; champion automation-first approaches
- Define and measure SLIs/SLOs, error budgets, and reliability roadmaps for critical services
- Implement and tune observability (logs, metrics, traces) using Azure Monitor, Log Analytics, Application Insights, and PrometheGrafana where applicable
- Conduct capacity planning, resiliency testing (chaos, failover, DR), and performance tuning across services
- Build secure, robust CI/CD pipelines (GitHub Actions / Azure DevOps Pipelines) with automated testing, scans, and approvals
- Standardize deployment strategies (blue/green, canary, rolling) for containerized and PaaS workloads
- Implement guardrails using Azure Policy, RBAC, PIM, and Blueprints (or equivalent) to enforce least privilege and compliance (e.g., SOC 2, ISO 27001, HIPAA as relevant)
- Manage secrets and certificates (Key Vault) and integrate security testing (SAST/DAST/Container scanning) into pipelines
- Support vulnerability remediation and patching SLAs
- Own incident response, including rotational shifts and on-call; lead triage, root cause analysis (RCA), and post-incident reviews
- Optimize cost (FinOps), tagging standards, budgets, and proactive spending alerts
- Maintain runbooks, knowledge base articles, and automation for routine operations
- Act as a technical mentor; review designs/PRs; contribute to architecture decisions
- Partner with app teams to onboard workloads, define nonfunctional requirements, and drive platform adoption
qualifications:
5 to 7 years of hands-on experience supporting Azure-based infrastructure and services in production
Expertise in several of: AKS, App Services, Functions, APIM, Azure SQL/MI, Cosmos DB, Storage, Event Hub/Service Bus, Redis, VNet/Peering, Private Link, Application Gateway/WAF, Front Door
Strong IaC with Terraform (preferred) and/or Bicep; Git-based workflows; GitHub or Azure DevOps
Proven SRE background: SLI/SLO design, error budgets, incident management, RCA, capacity and performance engineering
CI/CD design and operations (GitHub Actions / Azure DevOps Pipelines); artifact/versioning strategies; release governance
Observability with Azure: Monitor, Log Analytics, Application Insights, and alerting/automations (Action Groups, Logic Apps, Functions)
Solid networking fundamentals (DNS, TLS, routing, firewalls, load balancing), identity (AAD/Entra ID), and secrets management (Key Vault)
Scripting proficiency in PowerShell and/or Python; Linux fundamentals
Strong understanding of Azure security best practices, including Role-Based Access Control (RBAC), Privileged Identity Management (PIM), Azure Policy, and Managed Identities for secure access management and governance
skills:
APIM,Application Insights,automated testing,AAD,Azure DevOps Pipelines,Bicep,Azure Monitor,CI/CD,Cosmos DB,robust CI/CD pipelines,deployment strategies,DNS,DAST,Firewall,firewalls,Git-based workflows,GitHub Actions,GitHub,Grafana,Identity Management,ITOps,Infrastructure as Code (IaC),secrets management,Key Vault,Linux,load balancing,Log Analytics,versioning,Azure,Azure DevOps,Logic Apps,networking fundamentals,Peering,performance tuning,PaaS,Prometheus,Python,Redis,RBAC,Role-Based Access Control,routing,Azure SQL,Scripting proficiency,vulnerability remediation,SAST,Terraform,TLS,PowerShell,analytical,passion,troubleshooting skills,reliability,proactive,secure access,architecture,automate,automation,automations,Blueprints,budgets,capacity planning,FinOps,governance,HIPAA,ISO 27001,incident reviews,incident management,incident response,infrastructure,knowledge base,tagging,technical mentor,metrics,performance engineering,production support,root cause analysis,RCA,security,security best practices,security testing,Standardize,triage,workflows
Equal Opportunity Employer: Race, Color, Religion, Sex, Sexual Orientation, Gender Identity, National Origin, Age, Genetic Information, Disability, Protected Veteran Status, or any other legally protected group status.
At Randstad Digital, we welcome people of all abilities and want to ensure that our hiring and interview process meets the needs of all applicants. If you require a reasonable accommodation to make your application or interview experience a great one, please contact
Pay offered to a successful candidate will be based on several factors including the candidate's education, work experience, work location, specific job duties, certifications, etc. In addition, Randstad Digital offers a comprehensive benefits package, including: medical, prescription, dental, vision, AD&D, and life insurance offerings, short-term disability, and a 401K plan (all benefits are based on eligibility).
This posting is open for thirty (30) days.
It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
![]()