Responsibilities
- Provision and support production infrastructure on Azure and AWS using Terraform and Terraform Cloud workspaces
- Operate Azure Kubernetes Service (AKS) clusters hosting the IAM system across development, staging, and production environments
- Enforce Infrastructure as Code standards to ensure reproducibility, versioning, and recovery readiness
- Coordinate multi-workspace Terraform setups with intricate interdependencies
- Design and execute disaster recovery plans spanning Azure and AWS regions
- Administer and protect Azure platform components including networking, identity, compute, and security policies
- Deploy and maintain containerized .NET 8 applications on Kubernetes using Helm
- Configure event-driven autoscaling via KEDA for Redis Streams and message processing workloads
- Manage Kubernetes resources such as StatefulSets, Deployments, Services, ConfigMaps, and Secrets
- Improve container efficiency and security using multi-stage Docker builds
- Enforce pod security, network policies, and role-based access controls in Kubernetes
- Deploy and maintain self-hosted identity recovery systems in both cloud environments
- Integrate identity federation, single sign-on, and OAuth/OIDC protocols with the IAM platform
- Utilize HashiCorp Vault for managing secrets, dynamic credentials, and PKI services
- Set up Vault PKI for certificate issuance, mTLS, and secure service-to-service communication
- Handle Redis TLS/SSL configuration and certificate renewal processes
- Integrate with Azure Key Vault where required
- Implement security scanning, vulnerability detection, and compliance enforcement
- Develop and maintain Azure DevOps pipelines for CI/CD workflows
- Apply GitOps principles to automate deployment processes
- Create and update Makefiles and shell scripts for build, deployment, testing, and cleanup tasks
- Establish automated testing including Helm chart validation and integration testing
- Maintain consistent security and compliance standards across cloud providers
- Monitor and optimize cloud spending and resource utilization