Our client, a global financial Powerhouse is looking for a highly skilled Azure Automation & Governance Engineer to play a critical role in strengthening their Azure tenant governance, automation capability and identity architecture.
This is a hands-on technical position focused on automation, compliance, RBAC governance, PAM/PIM optimisation and Entra ID design across enterprise-scale Azure environments. You'll be responsible for building robust automation frameworks, improving subscription governance and ensuring tenant standards are consistently enforced.
If you enjoy building structured, compliant, automated cloud environments, this role is for you.
Key Responsibilities
Develop automation scripts to:
- Validate tenant standards
- Generate compliance reports
- Produce detailed success/failure/error logs
- Deploy and manage Azure resources using Terraform (Infrastructure as Code)
- Use Azure Automation to execute scripts for automated monitoring and alerting
- Govern Azure subscriptions:
- Identify and remove invalid/non-compliant subscriptions
- Improve and optimise Azure RBAC configurations
- Assess, maintain, and enhance PAM/PIM configurations
- Document role assignments
- Improve activation processes and request quality
- Produce and publish tenant creation standards
- Enforce governance and compliance controls across Azure environments
- Design and document Entra ID Low-Level Designs (LLDs) for Core LMP tenants
- Maintain high-quality technical documentation across all governance and identity initiatives
Required Skills & Experience
- Strong Scripting and automation capability (PowerShell, Python, or similar)
- Solid experience with Terraform (IaC) in Azure environments
- Hands-on experience with Azure Automation
- Deep understanding of:
- Azure subscription governance
- RBAC best practices
- Privileged Access Management (PAM)
- Privileged Identity Management (PIM)
- Experience designing and documenting Entra ID architectures
- Ability to produce structured technical documentation (LLDs, standards, governance controls)
- Strong understanding of cloud compliance and governance frameworks
Desirable
- Experience in multi-tenant or enterprise-scale Azure environments
- Familiarity with Microsoft Cloud Adoption Framework or Well-Architected Framework
- Security-focused mindset with experience improving identity posture
This role will pay approx. £350-£400 p/day Inside IR35