Citrin Cooperman offers a dynamic work environment, fostering professional growth and collaboration. They are seeking a Staff Cloud Engineer to join their Development team within the Information Technology department, focusing on securing, managing, and automating the cloud infrastructure that powers their data ecosystem.
Responsibilities:
- Deploy and manage cloud resources (primarily Azure and Microsoft Fabric infrastructure) using Infrastructure-as-Code (IaC) tools such as Terraform, Bicep, or ARM templates
- Build, maintain, and troubleshoot automated CI/CD pipelines (e.g., Azure DevOps, GitHub Actions) to streamline the deployment of data models, database changes, and infrastructure updates
- Implement and govern strict role-based access control (RBAC) and Entra ID (Azure AD) policies, ensuring users and applications have the principle of least privilege access to Fabric workspaces, data lakes, and SQL endpoints
- Manage virtual networks (VNETs), private endpoints, firewalls, and secure gateways to ensure all data ingress and egress is tightly controlled and isolated from public internet exposure
- Configure operational dashboards, logging, and alerting systems (e.g., Azure Monitor, Log Analytics) to proactively detect infrastructure anomalies, performance bottlenecks, or security events
- Monitor cloud consumption and resource utilization. Implement tagging strategies, set budget alerts, and identify opportunities to right-size compute and storage to optimize operational costs
Requirements:
- Have a bachelor's degree in computer science, information technology, engineering, or equivalent practical experience
- Be Microsoft Certified: Azure Administrator Associate (AZ-104)
- Be Microsoft Certified: Fabric Analytics Engineer Associate (DP-600)
- Be Microsoft Certified: Azure Network Engineer Associate (AZ-700)
- Be Microsoft Certified: Azure Security Engineer Associate (AZ-500)
- Have 2–4+ years of professional experience in Cloud Engineering, DevOps, or Cloud Administration within an enterprise environment
- Have strong hands-on experience with Microsoft Azure services, particularly those related to data, networking, and security
- Be proficient in scripting languages (PowerShell, Bash, or Python) for task automation
- Have practical experience writing and deploying Infrastructure-as-Code (Terraform, Bicep)
- Possess a solid understanding of CI/CD concepts and version control (Git)
- Be knowledgeable of core cloud networking principles (DNS, routing, subnets) and enterprise identity management (Active Directory / Entra ID)
- Have a automation-first mindset: Hates doing the same manual task twice. Instinctively looks for ways to script, template, and automate routine operational work
- Be security conscious: Understands that a data platform is a high-value target and consistently builds with defense-in-depth principles in mind
- Be reliable and methodical: Thrives in an operational capacity where predictability, documentation, and careful change management are celebrated