Summary: The Azure Landing Zone Lead/Architect role involves hands-on deployment of Azure Landing Zones using the Azure Landing Zone Accelerator with Terraform. The position requires expertise in designing network topologies, implementing Microsoft's Cloud Adoption Framework, and managing Azure operations. The candidate will work closely with client architecture teams to create deployable Terraform-based solutions for regulated environments.
Key Responsibilities:
- Deploy Azure Landing Zones using the Azure Landing Zone Accelerator with Terraform.
- Design hub-and-spoke network topologies for centralized connectivity and workload isolation.
- Implement multi-tier management group structures based on Microsoft's Cloud Adoption Framework.
- Manage Azure subscriptions and resources, including RBAC and policy governance.
- Utilize Azure Entra ID for identity and access management.
- Integrate Terraform state management and CI/CD pipelines for deployments.
- Implement application-tier resilience patterns within landing zones.
- Collaborate with client architecture teams to translate governance decisions into deployable solutions.
Key Skills:
- Hands-on experience with Azure Landing Zone Accelerator and Terraform.
- Proven experience in designing hub-and-spoke network topologies.
- Deep knowledge of Microsoft's Cloud Adoption Framework.
- Strong Azure operational and administration skills.
- Experience with Azure Entra ID and IAM.
- Proficiency in Terraform state management and CI/CD integration.
- Experience with application-tier resilience patterns.
- Ability to work with client architecture teams.
Salary (Rate): undetermined
City: undetermined
Country: undetermined
Working Arrangements: remote
IR35 Status: undetermined
Seniority Level: undetermined
Industry: IT
Role: Azure Landing Zone Lead/Architect
Location: Columbus, Ohio/Remote
Duration: 6-12 Months
Description:
- Hands-on experience deploying Azure Landing Zones using the Azure Landing Zone Accelerator (ALZ) with Terraform - designing, provisioning, and iterating on custom management group hierarchies, subscription vending, and policy-as-code deployments (this is the core, non-negotiable skill).
- Proven experience designing hub-and-spoke network topologies - centralized connectivity subscription, hub-based egress (no direct internet from spokes), and spoke-to-hub peering for workload isolation.
- Deep working knowledge of Microsoft's Cloud Adoption Framework (CAF), with the ability to design multi-tier management group structures beyond the CAF default (e.g., segmenting workloads by environment, data sensitivity classification, vendor/SaaS ownership, and decommissioning lifecycle) and translate them into deployable Terraform modules.
- Strong Azure operational and administration experience - subscription/resource group management, RBAC, quota and policy governance, cost control, and day-2 operations across a multi-subscription environment.
- Hands-on experience with Azure Entra ID (Azure AD) and IAM - conditional access, role assignments, PIM, service principals/managed identities, and federated identity for workload access.
- Proficiency with Terraform state management, module design, and CI/CD pipeline integration (Azure DevOps or GitHub Actions) for repeatable, versioned landing zone deployments.
- Experience with application-tier resilience patterns within a landing zone - e.g., Blue/Green (LIVE/staging) subscription or resource group structures with load-balanced, zero-downtime traffic switching.
- Ability to work directly with client architecture teams to translate whiteboard-level segmentation and governance decisions into a deployable Terraform-based landing zone, supporting regulated/enterprise environments.