Principal Technical Consultant - AI/Cloud Platform Engineering

Ahead GmbHUnited States, Chicago, Illinois, New York, New Yorkleverpaskelbta 2026-08-25
Privaloma:PythonGitAzureCloudDevOpsCI/CDAIHealthTechSecuritySeniorLeadJuniorHybrid

What you will do Consulting and delivery leadership

Work directly with client stakeholders to interpret business and operational challenges and translate them into the right technical solution, whether that is an Azure landing zone, a migration wave, or an agentic platform: which platform fits, what data and governance boundaries apply, and what the first production candidate should be.

Lead junior and mid-level consultants on your engagements: set technical direction, review their work, unblock them daily, and develop them into independent delivery owners.

Shape engagements alongside AHEAD account teams: scope workstreams, define deliverables, estimate effort, and keep delivery on plan as client priorities shift.

Build and maintain strong client relationships beyond the current statement of work, and identify opportunities to expand AHEAD's footprint through upsell and cross-sell.

Serve as the senior technical voice in client steering and working sessions, presenting options with tradeoffs and a clear recommendation rather than a menu.

Azure platform engineering

Lead Azure discovery and assessment engagements: current-state architecture reviews, workload and application inventories, dependency mapping, and cloud readiness assessments that inform landing zone and migration roadmaps.

Design and deploy enterprise-scale Azure landing zones aligned to the Cloud Adoption Framework: management group and subscription hierarchies, hub-spoke or Virtual WAN networking, policy-as-code guardrails, and identity and RBAC foundations.

Plan and execute migrations to Azure: workload assessment and right-sizing with Azure Migrate, migration wave sequencing, cutover runbooks, and post-migration validation across compute, storage, databases, and containers.

Establish hybrid and cross-premises connectivity: ExpressRoute, VPN gateways, and DNS strategies that connect client on-premises environments to Azure.

Own cost governance and FinOps practices: budgets and alerts, tagging standards, reserved instance and savings plan strategy, and showback or chargeback reporting.

AI agent platform engineering and delivery

Design and deploy Microsoft Foundry environments for enterprise clients, including network-isolated configurations behind client firewalls: private endpoints, private DNS, subnet delegation, managed identity and RBAC design, and customer-managed keys.

Stand up Copilot Studio governance for client tenants: environment strategy and environment groups, DLP baselines and connector governance, generative AI settings, channel approval flows, and licensing and capacity guidance.

Build promotion pipelines in GitHub Actions that move agents from sandbox to production through automated tests, evaluation thresholds, and human approval gates implemented as environment protection rules.

Implement evaluation and safety frameworks: golden datasets, quality, retrieval, and safety evaluators run in CI, and compensating controls for model paths where platform content filtering does not apply.

Develop agents in code with the Foundry SDK (Python) and in Copilot Studio, and establish ALM so agents move between environments by pipeline rather than by hand.

Advise clients on model selection and placement across the Foundry catalog, including OpenAI and Anthropic models, with data residency, in-region inference, and cost as first-class constraints.

Documentation and enablement

Author the design documents, as-builts, build guides, technical roadmaps, and runbooks the client operates from after the engagement ends.

Run workshops, enablement sessions, and office hours for client makers, developers, and administrators.

Prepare review packages and evidence for client AI governance boards, and keep decision registers current during delivery.

What you bring 8+ years in engineering or technical consulting, including 5+ years delivering Azure infrastructure, landing zones, or migrations, and at least 18 months delivering GenAI or agent systems to production.

Delivery leadership. You have led small consulting or engineering teams on client work: assigning and reviewing work, mentoring junior consultants, and staying accountable for the engagement outcome, not just your own tasks.

Solution framing. You can take an ambiguous client problem and land it as a concrete architecture, whether that is an Azure landing zone, a migration plan, or an agentic system: pattern, platform choice, data boundaries, and the governance path to production. You know when the right answer is not an agent, and when it is not a rebuild.

Azure landing zone and migration depth. Hands-on delivery of Cloud Adoption Framework landing zones, Azure Migrate-based discovery and migration, hub-spoke or Virtual WAN network design, and workload right-sizing at enterprise scale.

Azure platform core services. Hands-on design and implementation across compute, storage, networking, databases, containers, identity, and security: VNets, private endpoints, private DNS, managed identities, Entra ID, and RBAC. You can explain what must exist before a network-injected Azure service can be created and what cannot be changed afterward.

Microsoft Foundry, hands-on. The account and project model, agent development with the current azure-ai-projects Python SDK, versioned agent deployments, model catalog management, and Azure AI Search for retrieval in isolated environments.

Copilot Studio, hands-on. Building agents with generative orchestration, environment administration, DLP and connector governance, agent identity, and solution-based ALM with the pac CLI.

IaC and CI/CD ownership. Infrastructure as code with Terraform, Bicep, or ARM, and GitHub Actions workflows with environments, protection rules, and OIDC federation to Azure. Pipelines and landing zones you built, not ones you used.

Evaluation-driven delivery. You promote agents on evaluation results against a baseline, not on demos, and you can design the dataset and thresholds that make that possible.

Consulting-grade communication. Design documents and technical roadmaps other people can execute, and the ability to explain and defend technical decisions with client executives, security teams, and governance boards.

Nice to have Microsoft credentials: Azure Solutions Architect Expert (AZ-305), Azure Administrator Associate (AZ-104), Azure DevOps Engineer Expert (AZ-400), Azure AI Apps and Agents Developer Associate (AI-103), Agentic AI Business Solutions Architect (AB-100), Copilot Studio Applied Skills, or AZ-500.

HashiCorp Terraform Associate certification, and GitHub Actions certification (GH-200).

Delivery experience in regulated or confidentiality-driven industries such as legal, financial services, or healthcare.

Microsoft Purview, Application Insights tracing for agent workloads, and the Copilot Agent Kit.

Power Platform administration background.

Experience working alongside client AI governance or review boards.