Logo for Conexess Group

Sr. Cloud Engineer - Azure

Role overview

Qualifications

  • 8+ years in enterprise infrastructure engineering, with 3+ years designing and running production workloads in Microsoft Azure.
  • Demonstrated production ownership of Azure Virtual Desktop or RemoteApp at scale.
  • Terraform in production, including module design, remote state, and code review discipline.
  • Deep Active Directory and Entra ID knowledge.

Responsibilities

  • Design and build Azure Virtual Desktop and RemoteApp environments.
  • Lead migration of remaining Citrix XenApp/XenDesktop workloads onto AVD.
  • Build and maintain Azure landing zones.
  • Write and maintain infrastructure as code in Terraform.

Key facts

Hard skills

Other skills

  • Problem Solving

About the company

Conexess Group logo

Conexess Group

Staffing & Recruiting

Conexess Group is a staffing and consulting solutions provider that combines the technology you need with relationships you can trust. We understand that one size never fits all, which is why we work with our clients to develop specialized solutions that fit their organizations, coupled with responsive service that ensures we get the job done right. By getting to know our clients on a deeply personal level, we unlock the potential of our elite technical knowledge and talent network, granting access to game-changing consultants and concierge-level service. And our 80 years of combined experience enables us to attract only the best specialized talent, whom we always treat with the utmost respect and professionalism. In fact, many of our consultants have come to view Conexess as a career counselor, providing constant updates on the latest opportunities. Our culture and values reflect our innovative approach toward attracting and retaining the most talented experts and producing consistent results for our Fortune 500 and mid-cap clients. Known for our technological leadership and entrepreneurial passion, our firm has been delivering value to our clients by providing solutions to their most complex challenges. Whether you’re in need of specialized talent or a boost to your career, we look forward to working with you. Specialties: IT Staff Augmentation | ERP Consulting Solutions | Accounting & Finance Recruitment

Company details

Company typeSME
IndustryStaffing & Recruiting
Company size51 - 200

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Our history:
From our start in 2009, Conexess has established itself in 3 markets, employing nearly 200+ individuals nationwide. Operating in over 15 states, our client base ranges from Fortune 500/1000 companies to mid-small range companies. For the majority of the mid-small range companies, we are exclusively used due to our outstanding staffing track record

Who We Are:
Conexess is a full-service staffing firm offering contract, contract-to-hire, and direct placements. We have a wide range of recruiting capabilities, from help desk technicians to CIOs. We are also capable of offering project-based work.

What you'll do

  • Design and build Azure Virtual Desktop and RemoteApp environments — host pools, workspaces, application groups, FSLogix profile management, image lifecycle, autoscale, and session host patching — supporting thousands of concurrent users across multiple regions.
  • Lead migration of remaining Citrix XenApp/XenDesktop workloads onto AVD, including application discovery, packaging, remediation, user acceptance testing, and cutover planning with application owners.
  • Build and maintain Azure landing zones: subscription and management group topology, hub-and-spoke networking, ExpressRoute and VPN connectivity, route tables, NSGs, Azure Firewall, and private endpoints for PaaS services with no public egress.
  • Write and maintain infrastructure as code in Terraform.
  • Implement identity and access design across Entra ID and on-premises Active Directory: hybrid join, Entra Domain Services or AD DS for AVD, conditional access, MFA, Privileged Identity Management, and role-based access aligned to segregation-of-duties requirements.
  • Implement platform guardrails with Azure Policy, RBAC, resource locks, tagging standards, and Defender for Cloud; remediate findings and keep the estate at or above the internal secure baseline.
  • Own encryption and key management: Key Vault, HSM-backed keys, customer-managed keys, certificate lifecycle, and secrets handling in pipelines.
  • Design and test disaster recovery for cloud and hybrid workloads — Azure Site Recovery, backup tiering, immutable/air-gapped copies, cross-region failover — and document RTO and RPO evidence for annual resilience testing.
  • Keep the VMware estate stable and supported while it winds down, then decommission it: migrate or rebuild the workloads still running on vSphere and vSAN, reclaim licensing, retire the clusters and the storage, backup, and load balancing tied to them, and confirm each decommission with asset and CMDB records updated.
  • Support the Windows Server estate through the transition, across Windows Server 2016–2025, including patching, hardening, and clustering.
  • Automate operational work in PowerShell and Azure CLI: provisioning, image builds, health checks, reporting, and remediation runbooks.
  • Produce and maintain architecture diagrams, runbooks, build documents, and control evidence; represent your changes in CAB and answer questions from internal audit, risk, and external examiners.
  • Provide escalation support for production incidents, participate in the on-call rotation, and complete root cause analysis on major incidents.
Required qualifications
  • 8+ years in enterprise infrastructure engineering, with 3+ years designing and running production workloads in Microsoft Azure.
  • Demonstrated production ownership of Azure Virtual Desktop or RemoteApp at scale — not a lab or pilot. Prior Citrix experience is a strong plus, because you will be migrating away from it.
  • Terraform in production, including module design, remote state, and code review discipline.
  • Azure DevOps (or GitHub Actions) pipeline authoring for infrastructure deployment, with approval gates and environment promotion.
  • Deep Active Directory and Entra ID: forests, domains, OUs, Group Policy, DNS, DHCP, LDAP, sites and replication, and hybrid identity synchronization.
  • Azure networking fundamentals: VNet design, peering, private endpoints and Private DNS zones, NSG and firewall rule design, and hybrid connectivity troubleshooting.
  • Windows Server engineering across current and legacy versions, including patching, hardening, and clustering.
  • PowerShell scripting for automation at scale.
  • Disaster recovery design and live failover testing, with the ability to state and defend RTO and RPO numbers.
  • Clear technical writing. If it isn't documented, in this environment it didn't happen.
Candidates without prior regulated-industry experience will be considered, but must demonstrate they can work within these constraints:
  • Experience operating under formal change management — CAB approval, change windows, freeze periods, back-out plans, and no undocumented production changes.
  • Understanding of segregation of duties in practice: engineers who build the pipeline do not unilaterally approve their own production deployments.
  • Familiarity with the control environment banks operate under — FFIEC guidance, GLBA safeguards, SOX IT general controls, and PCI-DSS where card data is in scope — and comfort producing evidence for internal audit, regulatory examinations, and third-party assessments.
  • Experience with privileged access management (CyberArk, BeyondTrust, or Entra PIM) and just-in-time elevation rather than standing administrative rights.
  • Data residency and data classification awareness: knowing which workloads can move to cloud, which cannot, and why the answer is sometimes "no. "
  • Logging and retention discipline — centralized diagnostic settings, Log Analytics, SIEM integration, and retention periods that satisfy record-keeping obligations.
  • Vendor and third-party risk awareness when introducing new tooling into the estate.
  • Ability to pass a financial-industry background check and, where applicable, fingerprinting.
Preferred
  • Azure certifications: AZ-104 (Administrator), AZ-140 (Azure Virtual Desktop Specialty), or AZ-305 (Solutions Architect Expert).
  • Experience consolidating multiple VDI platforms onto a single delivery platform.
  • Have a strong background in Fortinet networking products.
  • Enterprise backup and replication tooling: Commvault, Rubrik, Veeam, Zerto, or Azure Backup at scale.
  • Exposure to Azure Monitor, Log Analytics workspaces, and KQL for operational reporting.
  • Experience in a bank, credit union, insurer, or other examined financial institution.
  • Project leadership experience coordinating migrations with application owners and business stakeholders.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Cloud Engineer Related jobs

Other jobs at Conexess Group

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.