About LTi Technology SolutionsLTi Technology Solutions is a leading provider of asset finance and leasing software, purpose-built for the financial services industry. Our flagship platform, Aspire, powers the full asset finance lifecycle, from origination and credit decisioning through portfolio management, billing, accounting, and end-of-term; for banks, captives, independent finance companies, and specialty lenders across North America and internationally.Backed by private equity and in active growth mode, LTi is making the most significant platform investment in the company's history: a ground-up re-platform of Aspire onto a modern .NET and React architecture running on Microsoft Azure. Our customers manage billions of dollars in lease and loan portfolios on Aspire, and the next generation of the product will carry that mission-critical workload forward on a foundation built for scale, extensibility, and speed of delivery.This is a rare opportunity to join a profitable, established software company at an inflection point, where foundational engineering investment will directly shape product strategy, customer outcomes, and competitive differentiation.Position SummaryLTi is hiring a Senior Platform Engineer to build and own the cloud platform beneath the next-generation Aspire product. This is a greenfield Azure build: subscription and landing zone design, infrastructure as code, CI/CD, identity and secrets, observability, and the security controls a mission-critical financial services platform requires.Reporting to the VP of Engineering, the Senior Platform Engineer works as part of a small senior team. Platform decisions and architecture decisions get made together rather than handed across a wall. This is an individual contributor role without direct reports.You will write the Bicep or Terraform, build the pipelines, wire the telemetry, and set the security posture. The operating principle is that the platform is a product and its customers are the engineers who ship on it, so automation, self-service, and documentation matter more than gatekeeping. The ideal candidate has built this foundation before and knows which controls pay for themselves and which only add friction.Essential Functions & DutiesCloud Foundation & Infrastructure as CodeDesign and build the Azure foundation, including subscription and resource group topology, networking and private connectivity, environment tiers, and the isolation boundaries that support secure multi-tenancyExpress all infrastructure as versioned, reviewable code in Bicep or Terraform, with reusable modules, environment parameterization, drift detection, and no click-ops path to productionStand up the managed Azure services the product depends on (App Service, Container Apps or AKS, Azure SQL, Service Bus, Key Vault, App Configuration, Storage, Redis, Front Door), making explicit managed-versus-self-run tradeoffs with the teamEstablish backup, restore, and disaster recovery for data and infrastructure, and prove the recovery path through scheduled exercises rather than documentationCI/CD & Developer ExperienceBuild CI/CD pipelines in Azure DevOps or GitHub Actions covering build, test, scanning, artifact management, environment promotion, progressive deployment, and automated rollbackHelp define PR quality gates, branching and release strategy, and database migration practice that let the team ship continuously without ceremonyPartner on the local developer inner loop, including containerized dependencies, seed data, one-command environment setup, and fast test execution, so a new engineer can ship a meaningful change within their first weekProvide ephemeral, on-demand environments so feature work, migration dry runs, and customer-facing demos do not queue behind a shared environmentExtend LTi's AI-assisted development practices into platform work, including agentic workflows for pipeline, infrastructure, and operational tooling, leveraging LTi's existing Claude Code environmentSecurity & ComplianceOwn the security posture of the platform, including identity and access through Microsoft Entra ID, workload identity, least-privilege RBAC, secrets management in Key Vault, and certificate lifecycleBuild security into the pipeline rather than after it, with SAST, dependency and container scanning, IaC scanning, secret detection, SBOM generation, and a defined triage and remediation pathImplement software supply chain controls including artifact signing, provenance, base image management, and patch cadenceProduce the evidence trail that customers, auditors, and SOC 2 style examinations require, including access reviews, change history, and log retention, and treat audit readiness as a continuous state rather than an annual scrambleReliability & ObservabilityEstablish observability from day one, including structured logging, distributed tracing, metrics, and dashboards in Application Insights and Azure Monitor, with tenant-aware correlation across HTTP, messaging, and background jobsDefine SLOs, alerting, and on-call practice for a platform carrying mission-critical lease and loan portfolios, tuning for signal rather than volumeLead incident response practice, including runbooks, escalation paths, and blameless postmortems that produce durable fixesOwn performance and capacity work, including load and soak testing, scaling policy, noisy-neighbor mitigation, and cloud cost visibility and accountability by environment and tenantPartnership & PracticeServe as the platform counterpart to the Staff Software Engineer, participating in architecture and design review so that deployability, security, and operability are settled early rather than discovered lateAuthor and maintain runbooks, ADRs for platform decisions, and the standards by which infrastructure changes are reviewedSupport the re-platform migration effort with the environments, pipelines, and operational tooling that repeatable customer cutovers and rollbacks requireRaise the operational bar across the team through code review, pairing, and enablement, with the explicit goal of making the team independent of any single personKnowledge, Skills & AbilitiesAzure & InfrastructureDeep hands-on experience deploying and operating production workloads on Microsoft Azure, including compute, Azure SQL, Service Bus, Key Vault, App Configuration, Storage, and networkingExpert proficiency with infrastructure as code, including module design, state management, and environment parameterizationStrong containerization skills with Docker, and Kubernetes fundamentals where AKS is the right answerWorking knowledge of multi-tenant SaaS isolation models and the infrastructure decisions that enforce themCI/CD & AutomationProven experience building CI/CD systems, including automated testing, security scanning, artifact management, and progressive deliveryStrong scripting and automation skills in PowerShell, Bash, Python, or C#Familiarity with .NET build, packaging, and deployment, and with database migration strategy under continuous deliverySecurity & CompliancePractical command of cloud security, including identity, OAuth 2.0 and OpenID Connect, workload identity, network segmentation, key and secret management, and encryption in transit and at restExperience embedding security tooling into pipelines and driving remediation without stalling deliveryExposure to compliance frameworks relevant to financial services software such as SOC 2 or ISO 27001, and comfort producing audit evidenceReliability & Ways of WorkingExperience defining SLOs, alerting, and on-call rotation for a production SaaS platform, and fluency with observability tooling, ideally Application Insights and Azure MonitorBias toward automation, self-service, and documentation over manual gatekeeping, and toward boring, well-supported technology unless there is a defensible reason to do otherwiseAbility to partner closely with application engineers and to translate platform tradeoffs into business terms for product and executive audiencesWorking knowledge of cloud cost drivers and the architectural decisions that shape spend at scaleEducation & ExperienceEducationBachelor's degree in Computer Science, Software Engineering, or a related technical discipline; equivalent professional experience will be consideredRelevant certifications (Microsoft Certified: DevOps Engineer Expert, Azure Administrator Associate, Azure Solutions Architect Expert) are valued but not requiredExperienceMinimum 6 years of professional experience in platform, DevOps, SRE, or infrastructure engineering, with at least 3 years on Microsoft AzureDemonstrated experience standing up cloud infrastructure and CI/CD for a greenfield platform, not only maintaining an inherited oneProven track record supporting multi-tenant SaaS in a commercial software environment where uptime, data accuracy, and auditability are mission-criticalExperience implementing DevSecOps controls in a regulated or security-sensitive environment, ideally financial servicesExperience working as an embedded partner to application engineers rather than as a downstream operations functionExperience in high-growth software environments where velocity and pragmatism are valued alongside engineering rigorLTi Technology Solutions is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.