Azure Infra Engineer
NexGen Tech Solutions
- Location
- Bengaluru, Karnataka, India
- Job type
- Full-time
Required skills
- Python
- PCI-DSS
- AWS
- Azure
- caching
- CDN
- CI
- DevOps
- DNS
- firewall
- GCP
- state management
- Terraform
- Vault
- PowerShell
About the role
NexGen Tech Solutions
Website:
nexgentechsolutions.com
Job details:
Position: Azure Infra Engineer
Location – Bangalore
What you'll do
- Design and maintain Azure infrastructure as code (Terraform and/or Bicep) across multiple environments, including module structure, state management, and CI/CD pipelines for infrastructure changes.
- Design and operate Azure networking: hub-spoke topologies, VNet peering, NSGs/ASGs, route tables, Private Link/Private Endpoints, DNS, and hybrid connectivity (ExpressRoute/VPN Gateway).
- Own the edge and WAF layer for public-facing services using Azure Front Door — routing, origin health, caching, and WAF policy tuning (detection vs. prevention rollout, custom and managed rule sets).
- Build security into the infrastructure itself: least-privilege RBAC, Managed Identity over static credentials, Azure Policy guardrails, and network-level isolation for anything holding sensitive data.
- Troubleshoot production networking and connectivity issues — from a Front Door 502 to a broken Private Endpoint DNS resolution — methodically and under time pressure.
- Partner with application and security teams on design reviews, translating requirements into concrete, reviewable infrastructure changes.
- Improve how the team works: catching configuration drift, reducing copy-pasted infrastructure in favor of shared modules, and raising the bar on what gets automated versus done by hand in the portal.
What you'll need
- 5–6+ years in an infrastructure/platform/DevOps engineering role, with much of that time on Microsoft Azure specifically.
- Production experience with Terraform, Bicep, or ARM — including state management, module design, and running infrastructure changes through CI/CD (not just applying from a laptop).
- Solid, hands-on Azure networking experience: VNets and subnetting, NSGs, route tables/UDRs, VNet peering and hub-spoke design, Private Link/Private Endpoints, and Azure DNS — able to explain why a topology is shaped the way it is, not just draw it.
- Direct experience configuring and operating Azure Front Door (or comparable global edge/CDN + WAF platform) for a production, public-facing service — routing rules, origin health, and WAF policy tuning.
- Strong security fundamentals in an Azure context: RBAC vs. Azure Policy, Managed Identity, Key Vault, and designing network isolation for sensitive workloads.
- A track record of owning production incidents involving networking or security misconfiguration — comfortable being the person diagnosing the issue, not just the one who gets paged.
- Clear written and verbal communication — you'll be documenting designs and explaining trade-offs to both engineers and non-infrastructure stakeholders.
Nice to have
- Azure certifications such as AZ-700 (Networking), AZ-500 (Security), or AZ-104/AZ-305.
- Experience with Azure Virtual WAN, Azure Firewall, or DDoS Protection at scale (multiple regions or a large hub-spoke estate).
- Exposure to compliance-driven environments (SOC 2, PCI-DSS, HIPAA, or similar) and translating those requirements into concrete network/security controls.
- Scripting ability (PowerShell, Python, or Go) for tooling, drift-detection automation, or custom Terraform providers/modules.
- Experience with a second major cloud (AWS/GCP) — not required, but useful shorthand for how well networking/security concepts transfer across providers.
- Prior experience mentoring or reviewing IaC changes from less experienced engineers.
Click on Apply to know more.
This page is fully interactive when JavaScript is enabled. Please enable JavaScript to apply or browse related roles.