About this role
Required qualifications:
- 8+ years of software/platform engineering, with demonstrated technical leadership of a team or major workstream
- Expert in HashiCorp Boundary: both deployment (controllers/workers, SSH/RDP/database brokering, session recording, Entra ID OIDC, on-prem AD over ExpressRoute) and the operational access model (scopes, roles, grants, principal mapping, user onboarding)
- Deep AWS networking experience and a working understanding of enterprise cross-cloud network engineering: AWS Cloud WAN, AWS Network Firewall, AWS Transit Gateway, IPAM; and the routing path from AWS to Azure
- Strong Azure networking: VNet routing, Private Endpoint/Private DNS, NSG and route-table design for Boundary worker-to-target paths
- Production Terraform/Terragrunt against an established enterprise IaC module pattern; familiarity with azurerm, azapi, and azuread providers
- Strong in Python for lifecycle automation and pipeline tooling
- Solid grounding in DevSecOps: SAST/SCA tooling (Veracode, SonarQube, or CodeQL), dependency and vulnerability remediation, secrets management
- Comfortable in Linux/shell, Docker, and operating production services (on-call, incident/change management)
- Excellent written communication: pattern documentation, runbooks, and onboarding guides that future organizations will use to adopt this platform
AI skills
- Daily, fluent use of Claude Code and/or GitHub Copilot for implementation, refactoring, test generation, and code review
- Ability to establish team standards for AI-assisted development: effective prompting, trust-vs-verify discipline on generated code, security/IP guardrails, and reviewing AI-authored changes
- Working understanding of LLM fundamentals: context windows, tokens, model selection, and prompt/context engineering
- Experience integrating AI into developer workflows and agentic/automation tooling (MCP servers, AI-driven CI steps, codegen and doc-generation pipelines)
- Able to evaluate AI tooling pragmatically: measuring real productivity and quality impact, not hype
Nice to have
- Experience with RDP session recording compensating controls or supplementary tooling
- Azure VM domain-join and on-prem DNS troubleshooting at depth
- GitHub Actions and CI/CD pipeline authoring
Must have skills: Azure VNet routing Private Endpoint Private DNS NSG ROUTETABLE DESIGN, Python (Strong), Terraform (Strong), aws cloud wan aws network firewall aws transit gateway IPAM, hashiCorp Boundary Expert
We are a Digital Product Engineering company that is scaling in a big way! We build products, services, and experiences that inspire, excite, and delight. We work at scale — across all devices and digital mediums, and our people exist everywhere in the world (15000+ experts across 26 countries, to be exact). Our work culture is dynamic and non-hierarchical. We are looking for great new colleagues. That is where you come in!
Tech stack
AWSAzureTerraformPythonDockerLLM
About the company
Nagarro
IT Services · Public · Munich, Germany
Stage & Valuation
Public · $510M
Open roles on NewJob
Most hiring in
Engineering (46) · Data & ML (5) · BizOps (1)
Nagarro delivers digital product engineering and breakthrough technology services for industry leaders and challengers. The company offers artificial intelligence, machine learning, cloud solutions, and IT services.
More at Nagarro
Associate Director - ServiceNow Architect
Engineering
$200K–$250K
Principal Engineer - Senior Project Manager
Engineering
$170K–$230K
.NET Developer
Engineering
See all 210+ roles at Nagarro →
Similar roles at other companies
A
Senior Site Reliability Engineer - Tactical Reconnaissance & Strike
Engineering
$166K–$220K
I
Cloud Engineer I - Softeon
Engineering
$75K–$95K
I
Cyber Cloud Security Engineer - Vice President
Engineering
$170K–$200K
R
Senior Cloud Security Engineer
Engineering
$123K–$181K
See all Engineering roles →