We are Lenovo. We do what we say. We own what we do. We WOW our customers.
Lenovo is a US$69 billion revenue global technology powerhouse, ranked #196 in the Fortune Global 500, and serving millions of customers every day in 180 markets. Focused on a bold vision to deliver Smarter Technology for All, Lenovo has built on its success as the world's largest PC company with a full-stack portfolio of AI-enabled, AI-ready, and AI-optimized devices (PCs, workstations, smartphones, tablets), infrastructure (server, storage, edge, high performance computing and software defined infrastructure), software, solutions, and services. Lenovo's continued investment in world-changing innovation is building a more equitable, trustworthy, and smarter future for everyone, everywhere. Lenovo is listed on the Hong Kong stock exchange under Lenovo Group Limited (HKSE: 992) (ADR: LNVGY).
This transformation together with Lenovo's world-changing innovation is building a more inclusive, trustworthy, and smarter future for everyone, everywhere. To find out more visit www.lenovo.com, and read about the latest news via our StoryHub.
Key Responsibilities
Platform Operations Advanced Support
- Lead daytoday L2 operations across Azure services (VMs, VNets, LB, App Services, AKS, Storage, Key Vault, SQL/MI, Backup/ASR).
- Own incident triage and L2/L3 troubleshooting using Azure Monitor, Log Analytics, Application Insights, and Sentinel.
- Perform rootcause analysis (RCA), implement corrective/preventive actions, and update runbooks/SOPs.
- Serve as the technical escalation point for junior engineers and operations teams.
Provisioning, Automation Infrastructure Engineering
- Develop and maintain IaC deployments (ARM/Bicep/Terraform), including reusable modules, standards, and CI/CD integrations.
- Enhance Azure DevOps/GitHub Actions pipelines for automated builds, tests, deployments, and governance enforcement.
- Manage hardened image baselines, VM extensions, diagnostics configurations, and OS lifecycle updates.
- Contribute to engineering backlogs and drive improvements that reduce operational toil.
Governance, Compliance Security Engineering
- Implement and maintain enterprise policies using RBAC, PIM, Azure Policy, management groups, subscription standards, and identity controls via Entra ID.
- Enforce tagging, naming, backup, and DR requirements across environments.
- Support security operations (Defender for Cloud, vulnerability remediation, endpoint protection) and participate in audits and compliance reporting.
- Maintain evidence for regulatory/governance requirements (baselines, patching, access reviews, cost attribution reports).
Networking Connectivity Engineering
- Support and troubleshoot advanced networking elements: VNets, subnets, NSGs, Azure Firewall, Private Endpoints, Application Gateway/WAF, and network diagnostics.
- Assist in designing and maintaining hybrid connectivity (ExpressRoute, VPN, Private Link, and service endpoint architectures).
- Validate configurations against landing zone and Cloud Adoption Framework (CAF) standards.
Cost, Performance Optimization
- Analyze resource utilization and recommend rightsizing, reserved instances, savings plans, and architecture efficiency improvements.
- Perform performance deepdives (compute, storage, network) and contribute to capacity planning.
- Provide optimization insights to product/application teams and drive continuous improvement cycles.
Collaboration Continuous Improvement
- Work closely with application, DevOps, security, and operations teams to meet SLAs and reduce repeat incidents.
- Mentor junior engineers and help mature operational processes.
- Produce highquality documentation, KB articles, automation scripts, and engineering standards.
- Support cloud service onboarding and platform enablement for new workloads.
Required Qualifications Skills
- 46 years of cloud/infrastructure/operations experience with strong handson Azure expertise.
- Deep understanding of Azure core services: VNets, NSGs, LB, VMs, Storage, Key Vault, IAM, monitoring, backup/DR.
- Strong proficiency in PowerShell and/or Python for automation.
- Practical experience with IaC (ARM/Bicep/Terraform) and Gitbased CI/CD workflows.
- Solid understanding of Entra ID identity concepts, PIM, least privilege, and security baselines.
- Handson experience with log analytics (KQL), Sentinel, Defender for Cloud, and vulnerability remediation.
- Proven troubleshooting skills across compute/storage/network/platform layers.
- Familiarity with Azure landing zones/CAF, policydriven governance, subscription architecture.
- Experience with containers/AKS, App Gateway/WAF, Private Link, ASR, and Azure Backup.
- Understanding of cost management frameworks (tagging, budgeting, showback/chargeback).
- Strong communication skills and ability to lead small technical initiatives.
Preferred Certifications
- Microsoft Certified: Azure Administrator (AZ104)
- Azure Security Engineer (AZ500) or Identity Engineer (SC300)
- Terraform Associate (HashiCorp)
- Azure Solutions Architect (AZ305) preferred but not mandatory
We are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, color, sex, age, religion, sexual orientation, gender identity, national origin, status as a veteran, and basis of disability or any federal, state, or local protected class.