Back to jobs
New

Contract - Staff Cloud Platform Engineer

Mountain View, CA

We are CARIAD, an automotive software development team with the Volkswagen Group. Our mission is to make the automotive experience safer, more sustainable, more comfortable, more digital, and more fun. To achieve that we are building the leading tech stack for the automotive industry and creating a unified software platform for over 10 million new vehicles per year. We’re looking for talented, digital minds like you to help us create code that moves the world. Together with you, we’ll build outstanding digital experiences and products for all Volkswagen Group brands that will transform mobility. Join us as we shape the future of the car and everyone around it.

Role Summary:

​The Cloud Platform Engineering role is responsible for designing, securing, automating, and operating a scalable, multi-tenant hybrid Azure and on-premises infrastructure environment. The position functions at a high level of technical ownership, leading major components of the Azure landing zone architecture and reusable platform patterns, Infrastructure as Code implementation, Zero Trust security controls, governance standards, and platform reliability strategies. The role partners cross-functionally with Engineering, Security, and Operations teams, serves as an escalation point for complex issues, and drives automation, compliance, resiliency, and continuous improvement across the organization’s cloud and core infrastructure platforms. Finally, the role acts as a technical lead within the Cloud Platform Engineering function; mentors other engineers and guides design reviews.

Role Responsibilities:

Cloud platform engineering and deployment (40%)

  • Design, implement, and evolve secure, scalable, multi-tenant Azure platform solutions.
  • Build and maintain landing zone building blocks (identity baseline, networking baseline, logging baseline) and reusable platform patterns to accelerate tenant onboarding.
  • Implement Azure Lighthouse capabilities to support scalable multi-tenant operations and delegated administration.
  • Integrate IAM solutions (e.g., SailPoint IdentityNow or equivalent) for identity provisioning and lifecycle governance.
  • Engineer secure hybrid cloud integrations between on-premises and Azure environments.
  • Evaluate and implement Azure platform innovations and security best practices.
  • Collaborate with engineering, InfoSec, and operations stakeholders to ensure technical alignment.

Infrastructure as Code (IaC) and automation (15%)

  • Develop and maintain shared Terraform modules and ARM/Bicep templates that standardize approved platform patterns.
  • Integrate IaC into CI/CD pipelines to enable automated, compliant infrastructure deployments.
  • Define and implement tagging, naming, and configuration management standards.
  • Automate shared services, networking configurations, RBAC policies, and platform governance controls.
  • Maintain module versioning/release notes and migration guidance to drive adoption with minimal friction.
  • Implement security validation tools within deployment pipelines.
  • Apply version control and DevOps best practices to infrastructure delivery.

Security and compliance engineering (15%)

  • Implement and maintain Azure RBAC, PIM, and Zero Trust controls across environments.
  • Configure secure access models including JIT, NSGs, Key Vault, and conditional access.
  • Automate security baselines using Defender for Cloud, Sentinel, and governance frameworks.
  • Support audit and compliance activities in collaboration with InfoSec teams.
  • Ensure platform security across hybrid cloud and virtualization environments.

Platform operations and reliability (15%)

  • Engineer tenant provisioning workflows and onboarding automation.
  • Build and maintain enterprise monitoring strategies for logs, metrics, and alerts across hybrid and multi-tenant environments.
  • Design, implement, and maintain backup and disaster recovery (DR) strategies across cloud and on-premises infrastructure.
  • Ensure regular backup validation, restore testing, and compliance with retention policies and business continuity requirements.
  • Support distributed monitoring infrastructure across hybrid environments.
  • Serve as escalation point for complex cloud and infrastructure troubleshooting.
  • Maintain documentation, playbooks, and operational standards.
  • Drive high availability, resiliency, and performance optimization.

Core infrastructure expertise (10%)

  • Strong understanding of virtualization technologies (vSphere, vCenter, ESXi, Azure VDI).
  • Administration of Windows, macOS, and Linux operating systems.
  • Microsoft 365 (O365) administration experience.
  • Active Directory (AD) and Azure AD (Entra ID) administration.
  • Networking fundamentals including DNS, VLANs, routing, firewalls, and hybrid connectivity.
  • Experience in hybrid on-prem/cloud environments applying security and availability best practices.
  • Proficiency in Python, PowerShell, and SQL scripting.

Change and incident management (5%)

  • Participate in enterprise ITSM-aligned change management processes.
  • Lead technical Root Cause Analysis (RCA) for critical platform incidents; coordinate fixes across partnering teams and drive follow-through to prevention.
  • Contribute to CAB discussions and cross-team escalation processes.
  • Drive continuous improvement through lessons learned and automation.

​General Skills:

  • Strategic systems thinking: Ability to design and manage complex, multi-tenant, hybrid environments while understanding how identity, networking, security, and operations interconnect.
  • Advanced problem-solving and root cause analysis: Strong troubleshooting skills with the ability to lead deep technical investigations and resolve complex infrastructure issues.
  • Security-first mindset: Consistently thinking about risk, access control, governance, and compliance when designing or modifying systems.
  • Automation and standardization: Drive to eliminate manual processes, create repeatable patterns, and enforce consistency across environments.
  • Operational discipline: Commitment to structured change management, documentation, backup validation, monitoring, and reliability standards.
  • Cross-functional collaboration: Ability to align with engineering, InfoSec, and operations teams to ensure governance, security, and technical requirements are met.
  • Ownership and accountability: Taking responsibility for platform stability, tenant onboarding, reliability, and long-term maintainability.
  • Risk-based decision making: Balancing innovation, speed, and scalability with governance and compliance requirements.
  • Clear technical communication: Explaining complex cloud, security, and infrastructure concepts clearly to stakeholders at different levels.
  • Continuous improvement and learning agility: Staying current with cloud innovations and proactively improving platform security, automation, and reliability.

​Required Specialized Skills:

  • Strong experience designing and operating secure, scalable Azure cloud platforms in hybrid (cloud and on-premises) environments
  • Deep expertise in Azure architecture, landing zones, governance, and multi-tenant management
  • Proficiency in Infrastructure as Code (Terraform, ARM/Bicep) with CI/CD pipeline integration and automated security validation
  • Advanced knowledge of identity and access management, including Azure AD (Entra ID), RBAC, PIM, Conditional Access, and Zero Trust principles
  • Hands-on experience with enterprise security tools such as Defender for Cloud, Sentinel, and Key Vault
  • Experience implementing monitoring, logging, and alerting strategies across hybrid environments
  • Strong understanding of backup, disaster recovery (DR), and high-availability design principles
  • Solid foundation in virtualization (VMware), Active Directory, and Microsoft 365 administration
  • Strong networking fundamentals including DNS, routing, firewalls, VLANs, and hybrid connectivity
  • Proficiency in automation and scripting using Python and PowerShell

​Desired Skills:

  • Azure certifications (e.g., AZ-104, AZ-305, AZ-500)
  • Experience implementing enterprise-scale landing zones using Microsoft Cloud Adoption Framework (CAF)
  • Strong knowledge of Azure Policy and policy-as-code governance frameworks
  • Experience with Microsoft Sentinel and advanced cloud security automation
  • Experience leading technical initiatives or mentoring engineers
  • Familiarity with identity governance platforms (e.g., SailPoint, Okta, or similar)

​Workplace Flexibility:

  • A flexible work schedule is required, including the ability to address issues outside of standard business hours.
  • May require occasional travel - up to 20%.

​Years of Relevant Experience:

  • 8+ years of infrastructure engineering experience
  • 5+ years designing and operating Azure cloud platforms with experience in multi-tenant or enterprise-scale deployments 

​Required Education:

  • Bachelor’s degree in Information Technology, Computer Science, or a related field, or equivalent practical experience

​Desired Education: 

  • Master’s degree in computer science, IT, or equivalent hands-on experience
  • ITIL Foundation Certification

Compensation

Salary range is dependent on factors such as geographical differentials, credentials or certifications, industry-based experience, qualification and training. In the city of Mountain View, CA, the salary range for this position is $78.00 - $90.00.

CARIAD, Inc. provides performance based merits and annual bonus along with a competitive benefits package. Benefits include medical, dental, vision, 401k with employer match and defined contribution plan, short and long term disability, basic life and AD&D insurance, employee assistance program, tuition reimbursement and student loan repayment plans, maternity and non-primary caregiver leave, adoption assistance, employee referral program and vacation and paid holidays. We also offer a unique vehicle lease program that covers registration and insurance fees. 

CARIAD is an Equal Opportunity Employer.  We welcome and encourage applicants from all backgrounds, and do not discriminate based on race, sex, age, disability, sexual orientation, national origin, religion, color, gender identity/expression, marital status, veteran status, or any other characteristics protected by applicable laws. 

Employment with Cariad Inc. is contingent upon the successful completion of this screening process. We emphasize the importance of compliance with export control and sanctions laws as a fundamental aspect of our operations. Our company is dedicated to adhering to these regulations to ensure the lawful and ethical conduct of our business activities. Employment with our company is contingent on either verifying U.S. citizenship or U.S. lawful permanent resident status or obtaining any necessary license or confirming the availability of an applicable exemption or license exception. You, the applicant, will be required to answer certain questions for export control purposes, and that information will be reviewed by compliance personnel to ensure compliance with federal law. Cariad Inc. may choose not to apply for a license or use an applicable license exception (if available) for such individuals whose access to export-controlled technology or software source code may require authorization and may decline to proceed with an applicant on that basis alone.

By submitting your application, you acknowledge and agree to participate in the export control and sanctions compliance screening process. Your cooperation in this matter is essential to our shared success and the integrity of our operations. Thank you for your understanding and commitment to upholding these important standards.

 

Create a Job Alert

Interested in building your career at Cariad, Inc.? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Education

Select...
Select...
Select...
Select...
Select...

Select...
Select...
Select...

U.S. Standard Demographic Questions

We invite applicants to share their demographic background. If you choose to complete this survey, your responses may be used to identify areas of improvement in our hiring process.
Select...
Select...
Select...
Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Cariad, Inc.’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.