Responsibilities
- Design and manage modular, parameter-driven Azure infrastructure using Bicep or Terraform, with support for multiple environments
- Operate and maintain AKS clusters including node pool configuration, version upgrades, role-based access controls, network policies, CNI setup (Azure CNI or Overlay), ingress routing via NGINX or Application Gateway, horizontal pod autoscaling, and pod security baselines
- Develop and sustain multi-phase CI/CD pipelines in Azure DevOps using YAML, incorporating reusable templates, variable sets, deployment environments, and manual approval checkpoints
- Create and maintain PowerShell scripts for automated provisioning, deployment orchestration, and environment lifecycle management — proficiency in PowerShell is required
- Investigate and resolve security vulnerabilities, including patching CVEs and addressing findings from VAPT assessments within defined timeframes
- Enforce Kubernetes security policies such as pod security standards, network segmentation rules, and minimal-privilege access controls across namespaces
- Develop and manage KQL-driven monitoring alerts, dashboards, and interactive workbooks within Microsoft Sentinel and Log Analytics
- Maintain and optimize Prometheus and Grafana deployments for real-time visibility into containerized applications
- Write efficient, layered Dockerfiles that minimize image size and comply with security benchmarks
- Oversee container image lifecycle in Azure Container Registry, including tagging conventions, retention rules, and cross-region replication
Work Arrangement
Remote (Worldwide)