We are looking for a hands-on Senior Azure Infrastructure Automation Engineer to help us mature and extend how infrastructure is delivered across our organization. We already have a working Infrastructure-as-Code (IaC) framework and a meaningful library of Terraform modules in place—this role is about taking that foundation to the next level: expanding our module coverage, refining and hardening the existing environment, and building a new AI-enabled self-service layer on top.
The central mission is to make infrastructure self-service. You will grow our standardized, opinionated Terraform module library and expose it through an AI-enabled developer experience—so that engineers can describe what they need and have compliant, production-ready infrastructure generated for them automatically, with our standards and guardrails baked in. If you are excited about Terraform at scale, platform engineering, anding modern AI tooling to real infrastructure problems, this role is for you.
What You'll Work On:
Expanding the module library – building on our existing Terraform modules to broaden coverage across our Azure estate, standardizing patterns and ensuring security, naming, tagging, and policy guardrails are built in by default.
Refining the existing IaC framework – hardening and improving our current Terraform and Terragrunt environment for maintainability, consistency, and quality, with stronger linting, validation, testing, and CI/CD.
An AI-enabled self-service experience (the new build) – an IaC MCP (Model Context Protocol) server and configured agent skills so that developers using Claude Code or GitHub Copilot can interrogate our approved modules and standards, understand the “rules of the road,” and automatically build the infrastructure their projects need.
Automated governance – change-management automation integrated with ServiceNow, plus developer-facing workflows and golden paths delivered through Port.io.
Key Responsibilities:
Refine, harden, and extend our existing IaC framework using Terraform and Terragrunt, improving consistency, maintainability, and quality across environments.
Expand and standardize our existing Terraform module library, authoring additional modules to broaden Azure coverage, with secure defaults, consistent naming/tagging, and embedded policy guardrails.
Establish and enforce IaC quality standards using TFLint and policy-as-code, including linting, validation, automated testing, and pre-merge checks.
Build the AI-assisted self-service platform: stand up and maintain an IaC MCP server and author the agent skills/context that encode our standards, so developers can use Claude Code or GitHub Copilot to query approved modules and generate compliant infrastructure for their projects.
Automate change management by integrating IaC deployment pipelines with ServiceNow (change requests, approvals, CMDB updates) to keep delivery fast while staying audit-ready.
Design and implement self-service workflows, scaffolding, and golden paths through Port.io and other developer-portal/automation tooling.
Build and maintain CI/CD and GitOps pipelines for infrastructure delivery.
Write and maintain supporting automation in PowerShell, Python, and Bash.
Manage identity, access, and authentication patterns through Microsoft Entra ID (Azure AD), including RBAC and least-privilege design for the platform.
Partner with development teams to remove provisioning bottlenecks, gather feedback on the self-service experience, and continuously improve it.
Help grow and mentor the platform team as it scales, championing platform-engineering and self-service principles across the organization.
Ensure infrastructure and automation are secure, reliable, and compliant with organizational policies and best practices.
Required Skills & Experience:
Mastery-level Terraform and Terragrunt for Infrastructure-as-Code, including authoring reusable modules and managing infrastructure at scale.
Hands-on experience with TFLint and IaC quality tooling—linting, validation, automated testing, and enforcing standards across a codebase.
Deep Azure expertise across IaaS and PaaS services and the surrounding ecosystem.
Proven track record designing standardized, reusable module libraries and opinionated IaC patterns that other teams build on.
Strong scripting and automation skills in PowerShell, Python, and Bash.
Solid experience with CI/CD and GitOps workflows for infrastructure delivery.
Working knowledge of identity, access, and authentication using Microsoft Entra ID (Azure AD) and RBAC.
A genuine platform-engineering mindset—you care about developer experience and building safe, easy self-service for others.
Ability to design secure, scalable, and resilient automation solutions.
Preferred Qualifications:
Experience building or integrating MCP (Model Context Protocol) servers, or otherwise exposing tools and data to AI coding assistants.
Familiarity with Claude Code and/or GitHub Copilot and AI-assisted development workflows, including configuring agent skills, context, or guardrails.
Hands-on experience with Port.io or another Internal Developer Portal (e.g., Backstage).
Experience automating change management with ServiceNow or similar ITSM platforms.
Policy-as-code experience (e.g., OPA/Conftest, Sentinel, Azure Policy) and IaC security scanning (Checkov, tfsec/Trivy).
Infrastructure testing experience (e.g., Terratest, native Terraform tests).
Familiarity with Kubernetes / AKS and container orchestration.
Experience with configuration management and orchestration tooling (e.g., Ansible).
Familiarity with monitoring, observability, and incident-response practices.
Excellent communication skills and the ability to collaborate across multiple teams.
Certifications (Preferred):
HashiCorp Certified: Terraform Associate (or Terraform Authoring & Operations Professional)
Microsoft Certified: Azure Solutions Architect Expert
Microsoft Certified: DevOps Engineer Expert
Certified Kubernetes Administrator (CKA)
Other relevant cloud, automation, or security certifications are a plus.
The pay range that the employer in good faith reasonably expects to pay for this position is $36.98/hour - $57.79/hour. Our benefits include medical, dental, vision and retirement benefits. Applications will be accepted on an ongoing basis.
Tundra Technical Solutions is among North America’s leading providers of Staffing and Consulting Services. Our success and our clients’ success are built on a foundation of service excellence. We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic. Qualified applicants with arrest or conviction records will be considered for employment in accordance with applicable law, including the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. Unincorporated LA County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: client provided property, including hardware (both of which may include data) entrusted to you from theft, loss or damage; return all portable client computer hardware in your possession (including the data contained therein) upon completion of the assignment, and; maintain the confidentiality of client proprietary, confidential, or non-public information. In addition, job duties require access to secure and protected client information technology systems and related data security obligations.