Skip to content

Senior Azure Cloud/Platform Engineer - MF

  • Hybrid
    • Midrand, Gauteng, South Africa
    • Johannesburg, Gauteng, South Africa
    • Pretoria, Gauteng, South Africa
    +2 more
  • Cloud

Join as a Senior DevOps Engineer (Azure) to build scalable cloud solutions, automate CI/CD, and work on impactful projects while mentoring teams and driving innovation.

Job description

DVT is one of the top software development companies on the continent. Our software engineers are consulting on cutting edge applications at top companies in South Africa, as well as consulting globally. You will have the opportunity to work alongside some of the most established developers in the country and globally with the latest technologies.

DVT is seeking a Senior Azure Cloud/Platform Engineer to design and build a fully private Azure environment. This is a greenfield platform buildout, not application deployment into an existing environment. The engineer will establish the Azure networking foundation, configure all PaaS and managed services behind Private Endpoints, deploy private AKS clusters, and ensure end-to-end hybrid DNS resolution across an existing site-to-site VPN. All infrastructure must be codified for repeatable deployment across Production and Test environments.

Job requirements

DUTIES AND RESPONSIBILITIES

Azure Private Networking

  • Design and implement the VNet topology with appropriately segmented subnets for AKS, Private Endpoints, Application Gateway, and management

  • Deploy and configure Private Endpoints for Azure Container Registry, Azure SQL, Azure Storage (Blob and Table), Azure Key Vault, Azure Service Bus, and Azure App Configuration

  • Configure Private DNS Zones for all services

  • Configure Network Security Groups (NSGs) and User-Defined Routes (UDRs) to enforce least-privilege network access

  • Disable public access on all PaaS services once private connectivity is confirmed

Hybrid Connectivity and DNS

  • Work with infrastructure team to validate and optimise the existing site-to-site VPN

  • Deploy Azure DNS Private Resolver or DNS forwarder infrastructure to enable on-premises resolution of Azure Private DNS Zones

  • Conditional DNS forwarding on on-premises DNS servers

  • Ensure end-to-end name resolution works for all services across the VPN boundary — including validating that the VPN does not block cloud endpoints when both environments are active

AKS Private Cluster Deployment

  • Deploy AKS with a private API server endpoint (no public Kubernetes API exposure)

  • Configure Azure CNI networking with IP address planning to avoid conflicts with on-premises ranges

  • Set up node pool autoscaling for Production and scale-to-minimum/zero for the Test environment

  • Integrate AKS with Azure Container Registry via Private Endpoint and managed identity

  • Configure workload identity for secure access to Azure PaaS services from pods

  • Enable the Dapr extension for AKS as an Azure-managed cluster extension

Azure Application Gateway and Ingress

  • Deploy Azure Application Gateway with WAF v2 as the ingress point into the AKS cluster

  • Configure backend pools, health probes, and routing rules for the application workloads

  • Configure ingress routing to support traffic switching between on-premises and cloud based on availability and response time

  • Integrate TLS termination with certificates managed in Azure Key Vault

Security and Identity

  • Configure Azure Key Vault with private access for secrets, certificates, and encryption keys

  • Set up managed identities across all services to eliminate credential-based authentication

  • Implement RBAC across all deployed resources

  • Integrate with Entra ID (Azure AD) configure the foundational app registrations, tenant configuration, and identity infrastructure

Observability Infrastructure

  • Configure Azure Monitor, Container Insights, and Log Analytics workspace for the AKS cluster

  • Set up Application Insights resources for the .NET workloads

  • Configure Dapr's telemetry pipeline to flow into the same Application Insights and Log Analytics infrastructure

  • Establish alert rules and Azure Monitor workbooks for cluster health, node scaling, and Private Endpoint connectivity

Infrastructure as Code

  • Codify all infrastructure in Terraform or Bicep using a modular structure that supports environment-level parameterisation

  • Ensure the same codebase can deploy both Production (zone-redundant) and Test (cost-optimised, scale-to-zero) environments

  • Implement CI/CD pipelines for infrastructure deployment via Azure DevOps

  • Establish drift detection and automated compliance checks

Required Experience and Skills

Must-have

  • 5+ years in Cloud Engineering, Platform Engineering, or Infrastructure Engineering roles, with at least 3 years focused on Azure

  • Proven hands-on experience designing and deploying Azure Virtual Networks, subnets, NSGs, UDRs, and network peering

  • Deep experience with Azure Private Endpoints and Private DNS Zones across multiple PaaS services (SQL, Storage, Key Vault, ACR, Service Bus)

  • Experience deploying and operating AKS private clusters, including Azure CNI networking, node pool management, and workload identity

  • Strong experience with Azure Application Gateway (WAF v2) configuration and backend integration

  • Experience with hybrid connectivity: site-to-site VPN, DNS resolution across cloud/on-premises boundaries, Azure DNS Private Resolver or forwarder VM

  • On-premises infrastructure experience; understanding of how cloud and on-prem coexist in hybrid architectures, including firewalls, VPN gateways, and on-prem networking

  • Proficiency in Terraform or Bicep for infrastructure as code, with experience building multi-environment deployable modules

  • Experience with Azure Key Vault, managed identities, and Entra ID integration

  • Strong understanding of Kubernetes internals: networking (CNI), RBAC, Helm, ingress controllers, pod identity

  • Experience building CI/CD pipelines for infrastructure deployment (Azure DevOps preferred)

  • Experience configuring Azure Monitor, Container Insights, and Log Analytics for AKS clusters

  • Excellent documentation skills and experience with technical handover

Advantageous

  • Microsoft Azure certifications: AZ-305 (Solutions Architect), AZ-104 (Administrator), or AZ-400 (DevOps Engineer)

  • Certified Kubernetes Administrator (CKA)

  • Experience with Dapr on AKS cluster extension deployment, component configuration, and integration with Azure-backed state stores and pub/sub

  • Experience with Azure Service Bus (Private Endpoint configuration, topic/subscription topology)

  • Experience with Azure App Configuration for multi-environment feature and configuration management

  • Experience with Azure Database Migration Service and Data Migration Assistant

  • Experience with Azure landing zone frameworks (Cloud Adoption Framework, Enterprise-Scale)

  • Experience with Application Insights and OpenTelemetry instrumentation pipelines

  • Experience with cost optimisation patterns: AKS scale-to-zero, Azure SQL auto-pause, reserved instances

  • Familiarity with MassTransit over Azure Service Bus

  • Experience in telecommunications or ISP environments

  • Knowledge of GitOps tools such as ArgoCD or Flux

Who we are:

or