Senior Cloud PlatformEngineer
We arelooking for a hands-on Platform Engineer with practical AI literacy to helpbuild and scale Platform on Microsoft Azure. The platform isdesigned as a self-service, governed and automation-led foundation that enablesproduct teams to move AI experiments and digital products from sandbox toproduction faster, safer and with clearer accountability.
This role'sits within the Platform & Software Engineering Division and will supportthe development of reusable platform capabilities across infrastructureprovisioning, CI/CD delivery, AI-assisted development, AI applicationhardening, identity and access, observability, FinOps, compliance automationand developer self-service. The successful candidate will help turn cloudcomplexity into secure, repeatable golden paths that product teams can consumewith minimal friction.
Key Responsibilities
- 1.Design,build and operate Azure-based platform capabilities that support the DigitalFactory across sandbox, QA, UAT and production environments.
- 2.Developand maintain infrastructure-as-code templates using tools such as Azure Bicep,Terraform or equivalent, enabling consistent and repeatable environmentprovisioning.
- 3.Buildself-service golden paths for product teams, including environmentprovisioning, application templates, deployment patterns, access requests andapproved tooling.
- 4.ImplementCI/CD pipelines using Azure DevOps, GitHub, ShipHATS or equivalent platforms toautomate build, test, release, promotion and rollback processes.
- 5.Embedsecurity, reliability and compliance controls into platform workflows throughpolicy-as-code, automated checks and guardrails.
- 6.Supportthe hardening of AI-generated or experimental applications into evaluable MVPsby applying secure-by-default architecture, containerization, API management,monitoring and deployment baselines.
- 7.Implementidentity and access controls using Microsoft Entra ID, role-based accesscontrol, Privileged Identity Management, Conditional Access and least-privilegepractices.
- 8.Developobservability capabilities using Azure Monitor, Log Analytics, dashboards andbusiness-relevant platform metrics covering cost, health, delivery, incidentsand compliance.
- 9.SupportFinOps and TCO transparency through resource tagging, budget alerts, costallocation, token-cost tracking and show back reporting to product owners.
- 10.Collaboratewith product owners, developers, security, audit, finance and leadershipstakeholders to ensure platform capabilities are practical, governed andaligned to business outcomes.
- 11.Documentreusable patterns, operating procedures and platform decisions to improveadoption, maintainability and knowledge retention.
Required Skills and Experience
- 1.10+years of hands-on engineering experience, including significant experiencedesigning, building, managing and operating cloud infrastructure on MicrosoftAzure in enterprise or regulated environments.
- 2.Deephands-on experience with Azure platform services such as Azure Landing Zones,Azure Policy, Azure Container Apps, Azure App Service, API Management, AzureMonitor, Log Analytics, Defender for Cloud and Azure Cost Management.
- 3.Hands-onexperience operating in Government Commercial Cloud (GCC) environments,including working within government cloud governance, security, compliance,identity, network and operational controls.
- 4.Extensivehands-on experience with infrastructure-as-code, automated provisioning andconfiguration management using Azure Bicep, Terraform or equivalent tools.
- 5.Extensiveexperience designing and operating CI/CD and GitOps pipelines using AzureDevOps, GitHub, ShipHATS or similar platforms, including automated build, test,security scanning, deployment promotion, rollback and release quality gates.
- 6.Stronghands-on experience applying DevSecOps practices and implementing platformguardrails, including secure software delivery, automated quality checks,secrets management, vulnerability scanning, policy-as-code and compliancecontrols.
- 7.Stronghands-on experience in identity and access engineering using Microsoft EntraID, RBAC, Conditional Access, PIM, access reviews and least-privilege accessgovernance.
- 8.PracticalAI literacy and experience using AI-assisted development tools such as Claude,GitHub Copilot, Microsoft Copilot or equivalent tools to improve softwaredelivery, code quality, documentation, testing or developer productivity.
- 9.Experienceintegrating, securing and operating AI/ML platform services on Azure, includingaccess controls, network security, service configuration, monitoring andproduction-readiness controls for AI-enabled applications.
- 10.Workingknowledge of Active Directory and enterprise identity integration concepts,including directory services, group-based access, authentication flows andhybrid identity considerations.
- 11.Workingknowledge of modern authentication and authorization standards, including SAML,OpenID Connect, OAuth 2.0, JWT and related enterprise application integrationpatterns.
- 12.Workingknowledge of containerization, APIs, cloud-native application patterns andproduction-readiness practices.
- 13.Experiencesupporting at least one production cloud-native application or shared platformcapability, with responsibility for reliability, monitoring, deployment oroperational support.
- 14.Abilityto translate platform architecture into reusable engineering patterns,templates, developer self-service capabilities and platform services thatproduct teams can consume with minimal friction.
- 15.Strongdocumentation and communication skills, with the ability to explain technicalconcepts to both engineering and non-technical stakeholders.
- 16.Comfortableworking in an agile, product-oriented environment where platform capabilitiesare built incrementally and improved through adoption feedback.
Preferred Skills
- 1.Experiencewith AI application platforms, Azure OpenAI, Microsoft Fabric, Synapse, dataproducts or AI governance patterns.
- 2.Experiencebuilding developer portals, internal platforms, platform APIs, self-serviceworkflows or golden-path engineering templates.
- 3.Familiaritywith public sector cloud environments, government security requirements orregulated enterprise environments.
- 4.Experiencewith observability, SRE practices, incident response automation, MicrosoftSentinel, alert routing and service health dashboards.
- 5.Understandingof FinOps practices, cloud cost optimization, TCO modelling and costaccountability mechanisms.
- 6.Exposureto tools such as Jira, Confluence, GitHub, Azure DevOps, ShipHATS, Copilot orother modern engineering productivity tools.