Azure Cloud Engineer (DevOps/Terraform)(Fixed-Term Contract)
Job Description: Azure Cloud Engineer (DevOps/Terraform)
Location: Singapore
Employment Type: Fixed-Term Contract (1 Year)
About Us
Dymon Asia Capital (“Dymon Asia”), founded in 2008, is a leading alternative investment firm with assets across public and private markets. The firm’s flagship hedge fund product is the Multi-Strategy Investment Fund (MSIF), an Asia-focused multi-manager multi-strategy fund that seeks to generate absolute consistent uncorrelated returns from emerging and developed markets.
Headquartered in Singapore, Dymon Asia operates from nine offices across the Middle East and Asia, including Hong Kong, Tokyo, Dubai, Shanghai, Mumbai, and Kuala Lumpur. Our platform is built on our people. We bring together diverse perspectives, expertise, and experience across our multi-strategy and private markets businesses. Maintaining a collaborative culture where our people are set up to do their best work is central to how we operate.
Core Engineering is looking for an Azure Cloud Engineer to join the Azure Cloud Team, responsible for designing, building, and operating the CI/CD and Infrastructure-as-Code (IaC) layer that underpins our Azure cloud platform. This role is suited to an engineer who wants meaningful ownership of the Terraform and GitLab toolchain for management groups, subscriptions, networks, shared services, and application landing zones, and who will help embed DevSecOps practices into every pipeline. This is a 1-year fixed-term contract position.
Key Responsibilities
- Design and implement Terraform modules for Azure, covering management groups, subscriptions, RBAC, hub-and-spoke VNets, firewalls, private endpoints, and shared services such as Key Vault, Log Analytics/Grafana, storage, container apps, and data platform components.
- Manage remote state, workspaces, and module versioning, and promote changes safely across dev, QA, and production environments.
- Build and maintain GitLab CI pipelines for infrastructure, with fmt, validate, plan, and apply stages (non-prod and gated prod) and MR-driven workflows featuring terraform plan comments, approvals, and controlled apply.
- Create reusable CI templates so application and data teams can easily consume standard jobs for infrastructure, deployment, and smoke tests.
- Work with application and data teams to integrate their repositories with GitLab CI templates (build, test, deploy) and wire deployments into Azure landing zones (App Service, Container Apps, Functions, Databricks, etc.), using Dev/QA/UAT/Prod environment patterns aligned to the new subscription and VNet structure.
- Integrate security scanning tools into CI pipelines (e.g. JFrog Advanced Security, SAST/SCA/IaC scanners) and help define policies and thresholds for blocking promotions based on vulnerability severity.
- Collaborate with Security and Infrastructure teams to ensure pipelines enforce guardrails by default, such as policy checks and image/IaC scans.
- Integrate pipelines with monitoring and alerting (Azure Monitor, Log Analytics, Grafana) for infrastructure and applications, and contribute to cost optimisation through auto-shutdown patterns for non-prod and standardized scaling and sizing parameters in Terraform modules.
- Participate in incident response and post-mortems, improving pipeline resilience and roll-back strategies.
- Document CI/CD patterns, Terraform module usage, and how-to guides, coach engineers on using GitLab pipelines, writing safe Terraform changes, and reading plan outputs, and promote an infra-as-code only mindset with no manual portal changes for platform resources.
Job Requirements
- Degree in Computer Science, Engineering, Information Technology, or a related discipline preferred.
- 5 to 8 years of experience in DevOps or Platform Engineering, with significant time on Azure.
- Strong hands-on experience with Terraform on Azure, including modules, multi-environment setups, and state backends.
- Proven track record building CI/CD pipelines in GitLab (or similar) for both infrastructure and applications.
- Solid understanding of Azure networking, including VNets, NSGs, private endpoints, and VPN/ExpressRoute.
- Working knowledge of Azure identity and platform services, including RBAC, managed identities, Key Vault, and Log Analytics.
- Competent in at least one scripting language (e.g. Python, PowerShell, Bash) for automation and glue code.
- Familiarity with DevSecOps practices, including integrating SAST, SCA/OSS, secret scanning, and container/IaC scanning into pipelines.
- Comfortable reviewing and improving others' Terraform and CI configurations via merge requests, with strong debugging and troubleshooting skills across infrastructure, pipelines, and cloud services.
- Clear written and verbal communication, with the ability to work effectively with infrastructure, security, and application teams.
Apply for this job
*
indicates a required field

