
Senior Azure Cloud/Platform Engineer - MF
- Hybrid
- Midrand, Gauteng, South Africa
- Johannesburg, Gauteng, South Africa
- Pretoria, Gauteng, South Africa
+2 more- Cloud
Join as a Senior DevOps Engineer (Azure) to build scalable cloud solutions, automate CI/CD, and work on impactful projects while mentoring teams and driving innovation.
Job description
DVT is one of the top software development companies on the continent. Our software engineers are consulting on cutting edge applications at top companies in South Africa, as well as consulting globally. You will have the opportunity to work alongside some of the most established developers in the country and globally with the latest technologies.
DVT is seeking a Senior Azure Cloud/Platform Engineer to design and build a fully private Azure environment. This is a greenfield platform buildout, not application deployment into an existing environment. The engineer will establish the Azure networking foundation, configure all PaaS and managed services behind Private Endpoints, deploy private AKS clusters, and ensure end-to-end hybrid DNS resolution across an existing site-to-site VPN. All infrastructure must be codified for repeatable deployment across Production and Test environments.
Job requirements
DUTIES AND RESPONSIBILITIES
Azure Private Networking
Design and implement the VNet topology with appropriately segmented subnets for AKS, Private Endpoints, Application Gateway, and management
Deploy and configure Private Endpoints for Azure Container Registry, Azure SQL, Azure Storage (Blob and Table), Azure Key Vault, Azure Service Bus, and Azure App Configuration
Configure Private DNS Zones for all services
Configure Network Security Groups (NSGs) and User-Defined Routes (UDRs) to enforce least-privilege network access
Disable public access on all PaaS services once private connectivity is confirmed
Hybrid Connectivity and DNS
Work with infrastructure team to validate and optimise the existing site-to-site VPN
Deploy Azure DNS Private Resolver or DNS forwarder infrastructure to enable on-premises resolution of Azure Private DNS Zones
Conditional DNS forwarding on on-premises DNS servers
Ensure end-to-end name resolution works for all services across the VPN boundary — including validating that the VPN does not block cloud endpoints when both environments are active
AKS Private Cluster Deployment
Deploy AKS with a private API server endpoint (no public Kubernetes API exposure)
Configure Azure CNI networking with IP address planning to avoid conflicts with on-premises ranges
Set up node pool autoscaling for Production and scale-to-minimum/zero for the Test environment
Integrate AKS with Azure Container Registry via Private Endpoint and managed identity
Configure workload identity for secure access to Azure PaaS services from pods
Enable the Dapr extension for AKS as an Azure-managed cluster extension
Azure Application Gateway and Ingress
Deploy Azure Application Gateway with WAF v2 as the ingress point into the AKS cluster
Configure backend pools, health probes, and routing rules for the application workloads
Configure ingress routing to support traffic switching between on-premises and cloud based on availability and response time
Integrate TLS termination with certificates managed in Azure Key Vault
Security and Identity
Configure Azure Key Vault with private access for secrets, certificates, and encryption keys
Set up managed identities across all services to eliminate credential-based authentication
Implement RBAC across all deployed resources
Integrate with Entra ID (Azure AD) configure the foundational app registrations, tenant configuration, and identity infrastructure
Observability Infrastructure
Configure Azure Monitor, Container Insights, and Log Analytics workspace for the AKS cluster
Set up Application Insights resources for the .NET workloads
Configure Dapr's telemetry pipeline to flow into the same Application Insights and Log Analytics infrastructure
Establish alert rules and Azure Monitor workbooks for cluster health, node scaling, and Private Endpoint connectivity
Infrastructure as Code
Codify all infrastructure in Terraform or Bicep using a modular structure that supports environment-level parameterisation
Ensure the same codebase can deploy both Production (zone-redundant) and Test (cost-optimised, scale-to-zero) environments
Implement CI/CD pipelines for infrastructure deployment via Azure DevOps
Establish drift detection and automated compliance checks
Required Experience and Skills
Must-have
5+ years in Cloud Engineering, Platform Engineering, or Infrastructure Engineering roles, with at least 3 years focused on Azure
Proven hands-on experience designing and deploying Azure Virtual Networks, subnets, NSGs, UDRs, and network peering
Deep experience with Azure Private Endpoints and Private DNS Zones across multiple PaaS services (SQL, Storage, Key Vault, ACR, Service Bus)
Experience deploying and operating AKS private clusters, including Azure CNI networking, node pool management, and workload identity
Strong experience with Azure Application Gateway (WAF v2) configuration and backend integration
Experience with hybrid connectivity: site-to-site VPN, DNS resolution across cloud/on-premises boundaries, Azure DNS Private Resolver or forwarder VM
On-premises infrastructure experience; understanding of how cloud and on-prem coexist in hybrid architectures, including firewalls, VPN gateways, and on-prem networking
Proficiency in Terraform or Bicep for infrastructure as code, with experience building multi-environment deployable modules
Experience with Azure Key Vault, managed identities, and Entra ID integration
Strong understanding of Kubernetes internals: networking (CNI), RBAC, Helm, ingress controllers, pod identity
Experience building CI/CD pipelines for infrastructure deployment (Azure DevOps preferred)
Experience configuring Azure Monitor, Container Insights, and Log Analytics for AKS clusters
Excellent documentation skills and experience with technical handover
Advantageous
Microsoft Azure certifications: AZ-305 (Solutions Architect), AZ-104 (Administrator), or AZ-400 (DevOps Engineer)
Certified Kubernetes Administrator (CKA)
Experience with Dapr on AKS cluster extension deployment, component configuration, and integration with Azure-backed state stores and pub/sub
Experience with Azure Service Bus (Private Endpoint configuration, topic/subscription topology)
Experience with Azure App Configuration for multi-environment feature and configuration management
Experience with Azure Database Migration Service and Data Migration Assistant
Experience with Azure landing zone frameworks (Cloud Adoption Framework, Enterprise-Scale)
Experience with Application Insights and OpenTelemetry instrumentation pipelines
Experience with cost optimisation patterns: AKS scale-to-zero, Azure SQL auto-pause, reserved instances
Familiarity with MassTransit over Azure Service Bus
Experience in telecommunications or ISP environments
Knowledge of GitOps tools such as ArgoCD or Flux
Who we are:
or
All done!
Your application has been successfully submitted!
You've already applied for this job
Thank you for your interest - we've already received your application, so this new submission can't be accepted. Your previous application is on file.
