Job Description
Senior Terraform / IaC Engineer — Azure Landing Zone
Practice
Cloud & Infrastructure, Avanade India
Location
Bengaluru/NCR, India (Hybrid)
Experience
6–10 years overall in cloud infrastructure and platform engineering, with deep hands-on Terraform experience building Azure landing zones and provisioning Azure services as code
Role Summary
Avanade India’s Cloud & Infrastructure practice is looking for a Senior Terraform / Infrastructure as Code Engineer to build enterprise Azure platforms for our clients. This is a deeply hands-on subject-matter-expert role — the person in it writes the Terraform that provisions the landing zone, and is measured on the quality and reusability of the code they produce.
You will work within the platform team on the landing zone build and on the Azure services that sit inside it, taking the target-state design and turning it into tested, reusable, parameterised Terraform that runs through automated pipelines. The role suits an engineer who wants to stay hands-on, set the standard for how infrastructure code is written, and be the go-to person on Terraform for the engagement.
Key Responsibilities
- Build Azure landing zones using Terraform — management groups, subscriptions, policy assignments, networking, identity and the core platform services that sit within them.
- Write, structure and maintain reusable Terraform modules rather than one-off configurations — variables, locals, dynamic blocks, outputs and clean module interfaces.
- Provision and configure Azure services as code: networking, Key Vault, storage, Log Analytics, compute, backup, private endpoints and policy assignments.
- Parameterise a single codebase to deploy consistently across multiple environments and regions.
- Design and manage Terraform state at scale — remote backends, state segmentation, locking and provider configuration.
- Test and validate infrastructure code — terraform validate and plan, tflint, and a security scanner such as Checkov or tfsec, wired into the development workflow.
- Work to proper Git discipline — feature branches, pull requests and meaningful code review, both giving and receiving.
- Document modules properly — README, inputs and outputs, and worked examples so other engineers can consume them.
- Support the CI/CD pipelines that deliver the infrastructure — Terraform plan and apply stages, approval gates, secrets handling and drift detection.
- Write supporting automation in PowerShell, Bash or Python where Terraform alone is not the right tool.
- Troubleshoot deployment failures, state issues and drift, and remediate them cleanly.
- Act as the hands-on Terraform SME for the engagement — setting coding standards, reviewing others’ code and uplifting engineers around you.
- Contribute reusable modules and patterns back to the practice IP library.
Required Skills & Experience
- 6–10 years of overall experience in cloud infrastructure, platform engineering or infrastructure automation, with a substantial recent focus on Microsoft Azure.
- Strong hands-on Terraform (HCL) — modules, variables, locals, dynamic blocks, outputs, and dependency and provider management.
- Demonstrated experience building and testing reusable modules rather than writing one-off configurations.
- Experience building Azure landing zone components with Terraform, aligned to Cloud Adoption Framework patterns.
- Hands-on Azure resource experience: networking, Key Vault, storage, Log Analytics, policy assignments, compute and identity.
- Comfortable parameterising a single codebase across multiple environments and regions.
- Terraform state management at scale — remote backends, state design and access model.
- Familiarity with terraform validate and plan, tflint, and a security scanner (Checkov or tfsec).
- Git discipline: feature branches, pull requests and meaningful code review.
- Proper module documentation — README, inputs/outputs and examples.
- Clear communication with architects, engineers and client technical teams.
Preferred / Good to Have
- Scripting in PowerShell, Bash or Python for supporting automation.
- DevOps capability for infrastructure delivery: multi-stage YAML pipelines in Azure DevOps (or GitHub Actions), Terraform CI (format, validate, lint, security scan on pull requests) and CD (plan and apply stages, environments, approval gates).
- Service connections and workload identity federation in place of long-lived secrets; securing the Terraform state backend.
- Release management practice — branching and release strategy, artifact management and agent pools.
- Scheduled drift detection, pipeline health monitoring and platform monitoring with Azure Monitor and Log Analytics.
- Certifications: HashiCorp Terraform Associate, AZ-104, AZ-400 or AZ-305.
- Experience with Azure Landing Zone accelerators (Terraform ALZ modules / Enterprise-Scale).
- Exposure to Bicep or ARM, and to AWS or GCP providers.
- Experience in a global delivery / SI environment (Avanade, Accenture, or similar) working with distributed teams.
Qualification
.