About this role
Unlike generalist operations roles, the Specialist Engineer is the definitive technical authority within their domain. They design and architect platform solutions, lead complex implementations, serve as the L3 escalation point beyond L2, guide and upskill the operations team, and drive continuous platform improvement. The ideal candidate has hands-on mastery of multiple technology stacks and can move fluidly between deep technical problem-solving and stakeholder-facing architecture discussions.
Key Responsibilities
Technology
SME & L3 Escalation
· Serve as the definitive
technical escalation point (L3) for complex incidents that exceed L2 capability
— owning the problem through to permanent resolution.
· Provide expert-level analysis
and diagnosis across assigned technology domains: network security platforms,
Azure cloud services, observability stacks, and identity infrastructure.
· Lead post-incident technical
reviews for high-severity events, producing architecture-level RCA reports that
identify root cause, systemic risk, and strategic remediation steps.
· Act as the technical advisor to
the Cloud Strategy & Operations Head on platform decisions, technology
selection, and engineering trade-offs within your domain.
Platform
Architecture & Design
· Design and validate architecture
for network security, cloud networking, identity, storage, and observability
components across multi-region Azure and hybrid datacenter environments.
· Produce low-level design (LLD)
documents, architecture decision records (ADRs), and configuration standards
for all platforms within your SME domain.
· Evaluate new platform
capabilities, vendor features, and emerging technologies; produce formal
assessment and recommendation reports for adoption or rejection.
· Define and enforce configuration
baselines, hardening standards, and design patterns across your domain —
ensuring L1/L2 operations are built on a well-engineered foundation.
Network
Security Platform Engineering
· Architect and implement Palo
Alto NGFW deployments — zone design, security policy framework, NAT strategy,
Panorama policy hierarchy, and HA/clustering configuration.
· Design and manage Zscaler ZIA
and ZPA at an architectural level — tenant configuration, forwarding policy
design, PAC file management, SSL inspection architecture, and ZPA application
segment design.
· Configure and manage
Azure-native firewall solutions, Web Application Firewall (WAF) policies,
Application Gateway rules, and Azure Front Door routing profiles for
multi-region traffic management.
· Manage firewall deployments from
Azure Marketplace — lifecycle ownership including initial deployment, policy
governance, version management, and decommission planning.
· Define and govern firewall
change management processes; review all L2-submitted rule changes for security
posture impact before CAB submission.
Cloud
Traffic Management & Networking
· Design and implement
multi-region Azure network topologies — hub-and-spoke, Virtual WAN, and peering
architectures with ExpressRoute and Site-to-Site VPN for hybrid connectivity.
· Architect and manage Azure Load
Balancers, Application Gateways, Azure Front Door, and Traffic Manager for
high-availability and geo-redundant application delivery.
· Design and govern Azure API
Management (APIM) deployments — API gateway policies, product configurations,
rate limiting, authentication, and developer portal management.
· Implement and manage network
traffic management policies — BGP route manipulation, custom UDR
configurations, traffic steering, and failover path validation.
· Monitor and analyse sFlow and
NetFlow telemetry for network traffic baselining, anomaly detection, and
capacity planning across cloud and datacenter network segments.
Identity,
Access & Endpoint Security
· Architect and administer Azure
AD and ADFS at an enterprise level — hybrid identity design, federation trust
configuration, Conditional Access policy frameworks, and Privileged Identity
Management.
· Design and manage CyberArk PAM
at an architectural level — vault architecture, safe design, master policy
governance, CPM/PVWA/PSM component management, and privileged account
onboarding strategy.
· Manage Trend Micro EDR (Apex One
/ XDR) platform — policy framework design, agent deployment strategy, custom
detection rules, XDR correlation tuning, and integration with SIEM or
observability platforms.
· Define and maintain the
privileged access management strategy across cloud and on-premises
environments, ensuring all administrative access flows through governed,
auditable pathways.
Observability
Engineering
· Architect and own the end-to-end
observability platform — Prometheus federation design, Grafana enterprise
dashboard framework, alerting rule governance, and long-term metrics retention
strategy.
· Deploy, configure, and optimise
APM solutions (Dynatrace, AppDynamics, New Relic, Azure Application Insights,
or equivalent) — instrumentation strategy, agent rollout, baseline definition,
and SLA tracking integration.
· Design and implement sFlow and
NetFlow monitoring infrastructure — collector deployment, flow analysis, custom
visualizations, and integration with the unified observability platform.
· Build and maintain Azure Monitor
and Log Analytics at scale — diagnostic settings governance, KQL query library,
workbook templates, and cross-workspace query architecture for hybrid
environments.
· Define observability standards
for the managed environment — what must be monitored, how alerts are
structured, and how operational health is communicated to stakeholders.
Storage
& Infrastructure Specialisation
· Architect and manage NetApp
ONTAP storage environments — volume layout, aggregate design, QoS policy
configuration, SnapMirror replication topology, and storage efficiency
settings.
· Manage Azure-native storage
services — storage account configuration, lifecycle policies, Azure NetApp
Files, and blob/file/queue/table service governance.
· Lead storage performance
investigations — capacity forecasting, throughput bottleneck analysis, and
remediation planning for both cloud and on-premises storage tiers.
Automation,
IaC & Knowledge Transfer
· Lead infrastructure-as-code
adoption within your domain — author Terraform modules, Ansible playbooks, or
ARM/Bicep templates for all managed platform components.
· Build automation scripts
(PowerShell, Python, Bash) for complex operational tasks that cannot be
simplified for L1/L2 — packaging them as governed, documented runbooks.
· Conduct structured knowledge
transfer sessions for L2 engineers; develop training materials, lab exercises,
and troubleshooting guides to elevate team capability.
· Maintain a domain-specific
knowledge base — detailed configuration guides, architecture diagrams, design
decisions, and lessons learned from complex incidents and implementations.
Requirements
Cloud &
Hybrid Infrastructure
· 8 – 12 years of overall
IT/infrastructure experience; minimum 5 years in cloud infrastructure, network
security, or platform specialisation roles.
· Expert-level knowledge of
Microsoft Azure — multi-region networking, advanced security services,
identity, and platform architecture across hybrid environments.
· Strong hybrid infrastructure
background — Azure and on-premises datacenter integration via ExpressRoute,
Site-to-Site VPN, and Azure Arc with consistent management planes.
· Advanced Windows Server and
Linux administration — applied in the context of hosting platform services
(DNS, DHCP, NTP, ADFS, RADIUS) rather than generic server support.
Network
Security Platforms
· Expert-level Palo Alto NGFW —
Panorama management, zone-based policy design, application-layer security, HA
failover, and large-scale rule base governance.
· Deep Zscaler expertise — ZIA and
ZPA architectural design, SSL inspection, PAC file deployment, GRE/IPSec tunnel
configuration, and multi-tenant management.
· Azure WAF, Application Gateway,
Azure Front Door, and Traffic Manager — policy design, routing rules, health
probe configuration, and TLS termination management.
· Azure API Management — policy
expressions, product configuration, OAuth/subscription-based access, and API
lifecycle governance.
· Azure Marketplace firewall
deployment — vendor-specific deployment patterns, HA design, and integration
with Azure networking.
Identity
& Privileged Access
· Azure AD and ADFS —
enterprise-scale hybrid identity, federation design, Conditional Access policy
frameworks, and PIM role assignment governance.
· CyberArk PAM — vault
architecture, CPM/PVWA/PSM/AAM component design, master policy governance, and
privileged account discovery and onboarding.
· Trend Micro Apex One / XDR —
policy framework design, custom detection rule authoring, XDR integration, and
performance tuning in large-scale environments.
Observability
& APM
· Prometheus and Grafana at scale
— federation architecture, remote write configuration, alerting rule design,
and enterprise dashboard governance.
· APM platform expertise
(Dynatrace, AppDynamics, New Relic, or Azure Application Insights) —
instrumentation design, agent management, SLA dashboard creation, and anomaly
detection tuning.
· sFlow and NetFlow — collector
design, traffic analysis, custom reporting, and integration with observability
platforms.
· Azure Monitor and Log Analytics
— KQL query authoring, diagnostic settings governance, and cross-workspace
architecture for hybrid environments.
Storage
· NetApp ONTAP — advanced volume
management, aggregate design, QoS policies, SnapMirror replication, and ONTAP
performance analysis tools.
· Azure storage services — account
configuration, lifecycle management, Azure NetApp Files, and storage
performance optimisation.
Automation
& IaC
· Terraform and/or Ansible —
authoring reusable modules and playbooks for network security, cloud platform,
and identity infrastructure components.
· Scripting proficiency:
PowerShell, Python, Bash — building complex automation tools and operational
utilities beyond simple task scripts.
· CI/CD awareness — understanding
of how infrastructure changes flow through pipelines and how to integrate IaC
with deployment workflows.
Certification (Preferred)
Domain | Certification |
Microsoft
Azure | AZ-305 (Solution
Architect) | AZ-500 (Security) | AZ-104 (Administrator) |
Network
Security | Palo Alto PCNSE | Zscaler ZCCP (Professional) |
Identity
& PAM | CyberArk Sentry or
Guardian | SC-300 (Microsoft Identity) |
Endpoint
Security | Trend Micro Certified
Professional |
Observability | Grafana Certified
Associate | Dynatrace or AppDynamics certification |
Automation | HashiCorp Terraform
Associate | Red Hat Ansible Automation |
Service
Management | ITIL v4 Foundation or above |
Tired of cold applications?
Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.
Know someone who'd be great for this?