Lead Cloud Engineer
Hybrid in Republic of Lithuania
Microsoft Azure& 2 others
Looking for something else?
Find a vacancy that works for you. Send us your CV to receive a personalized offer.
Find me a jobWe are seeking a Lead Cloud Engineer to join our innovative team.
Our mission is to deliver a Unified Automation Platform (Internal Developer Platform) that standardizes secure, repeatable infrastructure delivery across Azure and on-premises VMware through templates and golden paths. You will drive Azure automation and AKS operations while advancing IaC/CaC engineering practices. Apply to empower teams to ship faster with consistent, compliant deployments.
Responsibilities
- Develop and maintain Terraform/OpenTofu modules for Azure App Services, Container Apps, Function Apps, Azure SQL, Cosmos DB, and Postgres, aligned with designs defined by the Azure Architect
- Operate and evolve the Azure Kubernetes Service (AKS) platform daily: cluster/node-pool provisioning, add-on configuration (ingress, cert-manager, external-dns, monitoring, policy), and namespace/tenant onboarding
- Configure identity wiring (managed identities, SPN/app registrations) and secrets integration (Azure Key Vault, OpenBao) for Azure workloads
- Create and maintain Image Factory pipelines for VM and container golden images (Linux and Windows/cloudbase-init baselines, CIS hardening, image scanning)
- Run Configuration as Code (Ansible) playbooks for VM post-provisioning and golden-image handoff
- Enable Backstage golden-path template integration for Azure provisioning, validating generated infrastructure end-to-end
- Diagnose and resolve production issues across Azure automation modules during Implementation and Adoption
- Contribute to module testing, drift detection, and documentation aligned with the platform's Infrastructure as Code Engine standards
Requirements
- 5+ years of hands-on experience building and operating Azure infrastructure via Terraform/OpenTofu, including CI/CD-driven deployment (Azure DevOps)
- Minimum 1 year of relevant leadership experience
- Expertise in operating Azure Kubernetes Service (AKS) clusters in production, covering networking, policy, and namespace management
- Proficiency in Azure identity constructs (managed identities, SPN/app registrations) and secrets integration (Key Vault, dynamic secrets)
- Skills in Configuration as Code (Ansible) for VM post-provisioning and golden-image pipelines
- Working knowledge of Azure networking constructs (VNets, private endpoints, NSGs) sufficient for integrating with the network foundation owned by the Network Architect
- Combined competency in Terraform (IaC) and Ansible (CaC) development, working AI-assisted with GitHub Copilot (provided project-wide) as standard practice
- Strong command of written and spoken English (B2+ level)
Nice to have
- Experience with Azure VMware Solution (AVS) private cloud provisioning
- Familiarity with image hardening/scanning tooling and Shared Image Gallery publishing
