Principal Cloud Platform Engineer

Kubota Tractor Corporation — United States · Posted ~1 hour ago

Lead Full-time

Skills

Azure cloud architecture cloud infrastructure automation security frameworks Zero Trust Microsoft Azure Azure Landing Zone

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A principal-level cloud engineering position responsible for designing enterprise cloud platforms, implementing automation strategies, improving security posture, and guiding technical standards.

Highlights

Senior technical authority role with responsibility for enterprise cloud architecture, security, automation, and mentoring engineering teams.

Description

For Earth For Life The Principal Cloud Platform Engineer will serve as the technical authority for enterprise cloud platform architecture and implementation across the organization’s Azure environment. This role is responsible for establishing and maintaining the Azure Landing Zone architecture, driving infrastructure automation strategy, and ensuring alignment with security frameworks including CIS Azure Foundations Benchmark and Zero Trust principles. The Principal Engineer will lead cross-functional initiatives spanning network connectivity, identity management, data platforms, and application landing zones while mentoring engineering teams and establishing technical standards that scale with organizational growth. Key Responsibilities This position does the following in accordance with all applicable Federal, State and local laws / regulations and the Company’s policies, procedures and guidelines: Architect and maintain enterprise Azure Landing Zone implementations including management groups, policy governance, and subscription vending strategies Design hub-and-spoke network topologies with Azure Firewall Premium, VPN gateways, ExpressRoute, and Private Link integration for hybrid connectivityEstablish Infrastructure as Code standards using Terraform, including module development,state management strategies, and drift detection mechanismLead the design of multi-region disaster recovery architectures leveraging Azure Site Recovery, geo-redundant storage, and automated failover orchestrationDefine and implement Azure Policy and Governance frameworks ensuring compliance with CIS Microsoft Azure Foundations Benchmark and regulatory requirementsArchitect identity and access management solutions using Microsoft Entra ID, Privileged Identity Management (PIM), and RBAC strategies across platform and application landing zonesDesign and implement CI/CD pipeline architectures using Azure DevOps with security gates, automated testing, and approval workflowsLead platform observability strategy including Log Analytics Workspace design, diagnostic settings, Azure Monitor alerting, and centralized audit loggingCollaborate with data engineering teams on Data Platform Landing Zone architecture including Microsoft Fabric integration and analytics infrastructureFacilitate integration of modern identity providers (e.g. Auth0 Customer Identity Cloud, Entra ID) with application workloadsProvide technical leadership and mentorship to cloud engineering teams, establishing coding standards, review processes, and knowledge sharing practicesEvaluate emerging Azure services and capabilities, providing recommendations for platform modernization and optimizationCollaborate with security teams on vulnerability management, security posture assessment, and incident response planningPartner with business stakeholders to translate requirements into scalable, secure cloud architectures.Other duties as assigned. Qualifications Bachelor’s degree in Computer Science, Information Systems, Engineering, or related discipline and 8 years of cloud platform engineering experience required.In lieu of a degree, at least 10 years related experience required.Experience architecting and implementing Azure Landing Zones following Microsoft Cloud Adoption FrameworkExperience with Infrastructure as Code using Terraform at enterprise scale including module development and state managementDeep knowledge of Azure networking including Virtual Networks, Azure Firewall, VPN Gateway, ExpressRoute, Private Link, and DNS architectureExperience implementing Azure Policy and Governance at scale across management group hierarchiesExperience with Microsoft Entra ID, Privileged Identity Management, Conditional Access, and enterprise RBAC patternsExperience designing CI/CD pipelines in Azure DevOps with YAML templates and secure deployment patternsStrong understanding of security frameworks including CIS Benchmarks, Zero Trust architecture, and defense-in-depth strategiesExperience with Azure monitoring and observability including Log Analytics, Azure Monitor, and diagnostic configurationExperience with container technologies including Azure Container Apps, Azure Kubernetes Service, and container registry patternsTechnically proficient with Infrastructure as Code: Terraform (primary), ARM Templates, BicepTechnically proficient with CI/CD: Azure DevOps, GitHub ActionsTechnically proficient with Scripting: PowerShell, Bash, PythonTechnically proficient with Operating Systems: Linux (Ubuntu, RHEL), Windows ServerTechnically proficient with Monitoring: Azure Monitor, Log Analytics, Grafana, Application InsightsTechnically proficient with Version Control: Git, Azure ReposTechnically proficient with Collaboration: Confluence, Jira, ServiceNowTechnically proficient with Containers: Docker, Azure Container Apps, Kubernetes (preferred)Microsoft certifications such as Azure Solutions Architect Expert (AZ-305), Azure Administrator Associate (AZ-104), or Azure Security Engineer Associate (AZ-500) preferredExperience with Azure Data Platform services including Microsoft Fabric, Azure Data Factory, or Azure Synapse preferredExperience with customer identity platforms such as Auth0, Azure AD B2C, or similar CIAM solutions preferredExperience in financial services, agriculture, or manufacturing industries preferredTechnically proficient with Cloud Platforms: Azure (primary), familiarity with AWS or GCP preferredProficient in the use of MS Office suite. Physical Requirements Requires sufficient personal mobility and physical reflexes, to permit the employee to function in a general office environment and accomplish tasks and duties as outlined above. Kubota is an equal opportunity at will employer and does not discriminate against any employee or applicant for employment because of age, race, religion, color, disability, sex, sexual orientation or national origin. Kubota is an equal opportunity at will employer and does not discriminate against any employee or applicant for employment because of age, race, religion, color, disability, sex, sexual orientation or national origin.