We are seeking an Azure Cloud Engineer in Singapore. You will remediate security and configuration gaps across our Azure estate and build network landing zone components for workloads migrating from on-premises. This is a hands-on delivery role: build, test, migrate and document to the agreed architecture with disciplined change control, rollback planning and clear knowledge transfer.
Responsibilities
- Remediate cloud security, vulnerability and audit findings, tracking closure with evidence
- Harden Azure compute, storage, networking, key management and logging to agreed baselines
- Implement Azure Policy, tagging, governance guardrails, role-based access control (RBAC) and privileged access controls
- Build landing zone components including subscription and resource group structure, spoke virtual networks, subnets, route tables, network security groups, private endpoints and private Domain Name System (DNS)
- Configure hybrid connectivity including Azure VPN Gateway, Azure ExpressRoute, peering and firewall rules aligned to documented requirements
- Deliver repeatable builds using infrastructure as code and automation where practical
- Execute migration waves including assessment, data transfer, testing, cutover, rollback and cross-team coordination
- Produce as-built documentation, runbooks and structured knowledge transfer while following change management and Monetary Authority of Singapore (MAS) Technology Risk Management requirements
Requirements
- Azure engineering delivery experience across remediation and migration in production environments
- Delivery to defined architecture including raising conflicts early and working within formal change control
- Azure platform skills across compute, storage, governance and resource management
- Azure networking skills including virtual networks, subnets, network security groups, route tables, private endpoints, private DNS, VPN Gateway and ExpressRoute
- Identity and secrets management using Microsoft Entra ID, RBAC, Privileged Identity Management (PIM), Azure Key Vault and managed identities
- Infrastructure as code and automation using Terraform or Bicep plus Azure Command-Line Interface (CLI) and PowerShell
- Migration tooling experience such as Azure Migrate, Azure Site Recovery and dependency mapping
- On-site availability in Singapore with ability to support planned out-of-hours cutovers plus background screening and third-party access requirements
Nice to have
- Microsoft Defender for Cloud or broader cloud security tooling experience
- Azure Monitor and Azure Log Analytics experience, including alerting and cost visibility
- Azure certifications such as AZ-104, AZ-500, or AZ-700