Atlas Search is looking for Infrastructure Engineer in Mundelein, IL.
This local job opportunity with ID 3875693858 is live since 2026-10-08 02:36:41.
We’re looking for a Senior Cloud Infrastructure Engineer to help build and operate the core Azure platform that supports applications, data, and AI across the firm.
This is a hands-on platform engineering role focused on Azure landing zones, identity, networking, Infrastructure-as-Code, governance, automation, and self-service infrastructure. You’ll own the shared cloud foundation and help create a secure, scalable “paved road” for engineering teams through reusable Terraform modules, policy-driven guardrails, and automated provisioning.
This is not a help desk, support, or traditional cloud operations role. You’ll join a lean, high-trust engineering team and work closely with senior technical leadership, taking ownership of projects from architecture and design through implementation, documentation, and handoff.
What You’ll Do
Azure Platform Engineering
- Design, build, and operate Azure landing zones across compute, networking, storage, and identity.
- Build and maintain a reusable Terraform Infrastructure-as-Code platform, including shared modules, state management, and pipeline-driven deployments.
- Develop and maintain golden Terraform modules that enable engineering teams to provision infrastructure through standardized, governed patterns.
- Build and manage Azure networking including VNets, hub-and-spoke architecture, NSGs, private endpoints, DNS, and hybrid connectivity.
- Implement Azure governance through Management Groups, Azure Policy, RBAC, and cost-management controls.
- Build self-service capabilities such as subscription provisioning and environment scaffolding while maintaining appropriate security and governance guardrails.
- Own the platform-engineering layer supporting Azure Update Manager, partnering with operations teams on execution.
Identity & Access
- Build and enhance hybrid identity infrastructure spanning Active Directory, AD Connect, and Microsoft Entra ID.
- Engineer Entra ID capabilities including Conditional Access, Privileged Identity Management (PIM), Identity Governance, access reviews, entitlement management, and RBAC.
- Own cloud and hybrid access-control architecture and make RBAC design decisions across workloads.
- Act as an engineering escalation point for SSO, SAML, and OIDC integration issues.
Automation & Engineering Efficiency
- Identify repetitive infrastructure and operational tasks and build automation to eliminate manual effort and reduce engineering toil.
- Develop automation using PowerShell, Python, Terraform, and CI/CD pipelines.
- Build self-service tooling and automated workflows that improve the developer and infrastructure experience.
- Leverage modern AI engineering tools such as Claude and Microsoft Copilot to accelerate scripting, documentation, and solution design.
- Continuously evaluate opportunities to improve the Azure platform through automation and engineering best practices.
Security & Compliance
- Build security controls and baselines directly into Azure infrastructure through policy-as-code and secure-by-default landing zones.
- Support a zero-trust architecture integrating technologies such as Zscaler, Microsoft Defender for Endpoint, and Entra Conditional Access.
- Design cloud infrastructure with security, compliance, and access segregation in mind.
- Support change management and audit requirements within a regulated environment, including SEC, FINRA, and SOX IT controls.
- Partner with GRC and security teams to provide technical documentation and evidence for audits.
- Implement appropriate access segregation and network controls for sensitive data and workloads.
Project Ownership & Documentation
- Take full ownership of infrastructure projects from architecture and scoping through implementation, documentation, and handoff.
- Create architecture documentation, runbooks, change records, and post-implementation reviews.
- Maintain clear documentation around the platform and its capabilities for internal engineering teams.
- Track project work and dependencies through Jira and Confluence.
- Provide proactive status updates to leadership and surface risks, blockers, and dependencies early.
- Clearly communicate technical concepts and project status to both technical and non-technical stakeholders.
What We’re Looking For
- 4+ years of hands-on Azure infrastructure engineering experience in a production enterprise environment.
- Experience owning or building shared Azure platforms, landing zones, or cloud infrastructure foundations.
- Strong hands-on experience with Terraform, including module development, state management, and pipeline-driven deployments.
- Strong understanding of Azure networking, including:
- VNets
- Hub-and-spoke architecture
- NSGs
- Private endpoints
- DNS
- ExpressRoute and/or VPN connectivity
- Experience with Microsoft Entra ID and hybrid identity, including Active Directory, AD Connect, Conditional Access, PIM, and RBAC.
- Experience with Azure governance, including Management Groups, Azure Policy, RBAC, and cost management.
- Strong experience with Azure DevOps, including YAML pipelines, service connections, self-hosted agents, and artifact management.
- Experience with PowerShell and/or Python for infrastructure automation.
- Strong documentation and project-management habits, including experience managing Jira tickets and tracking infrastructure projects through completion.
- Excellent written and verbal communication skills.
- Ability to independently take ownership of technical projects with minimal supervision.
Nice to Have
- Microsoft certifications such as AZ-104, AZ-305, or SC-300.
- Experience with Zscaler ZIA/ZPA or similar cloud security platforms.
- Knowledge of SAML/OIDC and enterprise SSO integrations.
- Automation engineering experience focused on self-service tooling, workflow automation, or eliminating repetitive infrastructure tasks.
- Experience using Claude, Microsoft Copilot, or other AI engineering tools in day-to-day development and infrastructure work.
- Experience with Rubrik, BeyondTrust PRA, or similar enterprise backup and privileged-access technologies.
- Familiarity with Docker or AKS.
- Experience working in financial services or another highly regulated industry.
What Makes This Role Different
This is an opportunity to work on the core Azure platform rather than simply operating it. You’ll have meaningful ownership over the architecture, Infrastructure-as-Code, identity, networking, governance, automation, and developer experience that underpin the firm's cloud environment.
You’ll work alongside senior technical leadership on a lean team where engineers are expected to design, build, automate, and own — not simply execute tickets or follow runbooks.
Work Environment
- Senior-level, hands-on engineering position.
- Collaborative, high-trust team environment.
- Significant ownership and autonomy across Azure platform initiatives.
- Role is focused on platform engineering rather than day-to-day IT operations or end-user support.