Logo
Astreya

Azure Infrastructure & Network Specialist

Astreya, Redmond, Washington, United States, 98052

Save Job

Role Summary Serve as a technical advisor and subject matter expert for global smart building portfolio, with a focus on secure IoT/OT networking, Azure integration, identity/SSO, and operational resilience. You will not implement changes directly; instead, you will triage issues, guide architecture and security decisions, lead risk mitigation strategies, and equip internal teams and partners through documentation, training, and governance.

Key Responsibilities IoT/OT Network & Security Advisory

Technical triage: Rapidly assess questions or incidents to distinguish network vs. device vs. cloud causes; recommend next steps and owners.

Advise on segmentation, encryption, and firewall policies for IoT/OT environments; define guardrails that balance safety, availability, and security.

Design secure dataflow patterns (edge → gateways → cloud) and certificate/credential handling approaches appropriate for constrained OT devices.

Produce risk assessments and mitigation plans for new integrations, vendor connections, and intersite traffic; track risks to closure.

Guide solution patterns across Azure IoT Hub, Device Provisioning Service (DPS), IoT Edge, Azure Digital Twins, and related telemetry/analytics services.

Advise on identity and SSO using Microsoft Entra ID (Azure AD) and modern auth flows; define least privilege controls and conditional access guardrails.

Define secure onboarding and offboarding patterns for devices and applications; recommend resilience/failover and rollback strategies.

Smart Building Systems Oversight

Provide technical insight into BAS/BMS, Environmental, People Density, occupancy, parking, digital signage and other Commercial & Industrial IoT systems and their integration with Azure IoT platforms.

Validate data integrity and performance through telemetry reviews, dashboards, and controlled tests; recommend tuning, buffering, and retry patterns.

Deliver stakeholder presentations that explain how building systems map to network and cloud architectures, highlighting operational and security implications.

Act as a Tier3 escalation point for complex IoT/OT connectivity and platform issues; perform deep diagnostics (logs, packet captures, edge/cloud traces).

Lead root cause analysis (RCA) and write clear post‑incident reports with preventive actions, ownership, and timelines.

Run knowledge‑transfer sessions and post‑incident reviews to build field/vendor capabilities and reduce repeat occurrences.

Lifecycle & Preventative Maintenance

Support lifecycle planning for firmware, certificates/keys, controller upgrades, and network segmentation milestones.

Partner with field teams and vendors to align preventative maintenance with uptime/SLA and security objectives; recommend proactive risk‑reduction actions.

Standards, Training & Documentation

Define onboarding requirements for IoT/OT solutions (compliance checks, service mapping, ops readiness).

Own and maintain KBAs, runbooks, RACIs, workflows, and architecture patterns; ensure global applicability and version control.

Create and deliver training modules and technical presentations for networking, operations, and app teams, measure adoption.

Global Project Support & Governance

Contribute to project scope, risk identification, acceptance criteria, and Key Performance Indicator (KPI) Objective and Key Results (OKR) definitions for global rollouts.

Facilitate risk workshops and status readouts; provide executive‑level presentations on readiness, risk posture, and remediation progress.

Coordinate across security, networking, facilities, and vendor teams to maintain alignment and accountability.

Attend onsite tests, commissioning events, device reviews, and vendor alignment meetings; provide realtime triage and decision support.

Capture onsite findings and convert them into updated standards, patterns, and training content.

Qualifications

IoT/OT networking, firewalls, and encryption: Strong grasp of routing, segmentation, VPNs/proxies, TLS/PKI, and secure edge‑to‑cloud patterns.

Azure IoT expertise: Practical advisory experience across IoT Hub, DPS, IoT Edge, Azure Digital Twins, and telemetry/analytics pipelines.

Identity & SSO: Hands‑on advisory experience with Microsoft Entra ID (Azure AD), modern auth (OIDC/SAML/OAuth2), and least privilege access patterns.

Troubleshooting & RCA: Demonstrated ability to lead deep diagnostics and produce clear, actionable RCAs with preventive controls.

Smart building Information Gathering systems: Working knowledge of Environmental, People Density, Parking and other various experiences.

Risk mitigation & governance: Ability to produce risk registers, mitigation plans, acceptance criteria, and track to closure.

Enablement skills: Excellent documentation, training, and presentation skills; ability to influence global stakeholders in a hybrid environment.

Seniority level Associate

Employment type Full-time

Job function Information Technology

Industries IT System Data Services and IT System Testing and Evaluation

#J-18808-Ljbffr