Location: NZ / Remote
Engagement Type: Fixed-term contract, 2–3 months
Rate: Competitive day/hour rate, commensurate with experience
About the Project:
This is a hands-on delivery role for an experienced engineer to lead the migration and network separation of workloads from our existing infrastructure and Azure tenancy into a new environment. You will be responsible for carving out, rebuilding, and cutting over cloud and network services cleanly, securely, and with minimal disruption to the business.
This is not a learning role — we need someone who has done this work before and can hit the ground running from day one.
What You'll Deliver:
- Plan and execute the separation of network and cloud workloads from the current Azure tenancy into a new, independent tenancy.
- Design and build the target-state Azure environment — subscriptions, VNets, subnets, NSGs, route tables, peering, VPN/ExpressRoute, storage, and VM workloads.
- Migrate Virtual Machines, VNets, and associated services between tenancies with clear cutover plans and rollback options.
- Re-architect and deploy the Fortinet network stack (FortiGate firewalls, VPNs, policies, SD-WAN, segmentation) to support the separated environment.
- Migrate and re-establish Microsoft 365 workloads — Exchange Online, SharePoint, OneDrive, Teams, Intune, and Entra ID (Azure AD) — including identity, licensing, and conditional access.
- Produce migration runbooks, cutover schedules, risk assessments, and post-migration documentation.
- Work closely with internal IT, security, and business stakeholders to coordinate change windows and validate outcomes.
What You Must Bring (Non-Negotiable):
- Solid, hands-on experience leading Azure tenant-to-tenant migrations or network separation projects.
- Deep working knowledge of Azure — VMs, VNets, networking, storage, backup, and subscription/tenant architecture.
- Strong Fortinet experience — FortiGate configuration, firewall policy design, VPN, routing, and segmentation.
- Proven experience migrating and administering Microsoft 365 workloads at scale, including Entra ID / Azure AD.
- Confident scripting in PowerShell (Azure CLI, Bicep, or Terraform a plus).
- Strong networking fundamentals — TCP/IP, routing, DNS, VLANs, firewall design.
- Ability to work independently, own deliverables end-to-end, and communicate clearly with both technical and non-technical stakeholders.