Cloud Platform Engineer
Summary
Build and scale a secure, self-service Azure platform that lets product teams move AI experiments and digital products from sandbox to production faster with automated CI/CD, identity, observability and FinOps controls.
Senior Cloud PlatformEngineer
We arelooking for a hands-on Platform Engineer with practical AI literacy to helpbuild and scale Platform on Microsoft Azure. The platform isdesigned as a self-service, governed and automation-led foundation that enablesproduct teams to move AI experiments and digital products from sandbox toproduction faster, safer and with clearer accountability.
This rolesits within the Platform & Software Engineering Division and will supportthe development of reusable platform capabilities across infrastructureprovisioning, CI/CD delivery, AI-assisted development, AI applicationhardening, identity and access, observability, FinOps, compliance automationand developer self-service. The successful candidate will help turn cloudcomplexity into secure, repeatable golden paths that product teams can consumewith minimal friction.
Key Responsibilities
1. Design,build and operate Azure-based platform capabilities that support the DigitalFactory across sandbox, QA, UAT and production environments.
2. Developand maintain infrastructure-as-code templates using tools such as Azure Bicep,Terraform or equivalent, enabling consistent and repeatable environmentprovisioning.
3. Buildself-service golden paths for product teams, including environmentprovisioning, application templates, deployment patterns, access requests andapproved tooling.
4. ImplementCI/CD pipelines using Azure DevOps, GitHub, ShipHATS or equivalent platforms toautomate build, test, release, promotion and rollback processes.
5. Embedsecurity, reliability and compliance controls into platform workflows throughpolicy-as-code, automated checks and guardrails.
6. Supportthe hardening of AI-generated or experimental applications into evaluable MVPsby applying secure-by-default architecture, containerization, API management,monitoring and deployment baselines.
7. Implementidentity and access controls using Microsoft Entra ID, role-based accesscontrol, Privileged Identity Management, Conditional Access and least-privilegepractices.
8. Developobservability capabilities using Azure Monitor, Log Analytics, dashboards andbusiness-relevant platform metrics covering cost, health, delivery, incidentsand compliance.
9. SupportFinOps and TCO transparency through resource tagging, budget alerts, costallocation, token-cost tracking and show back reporting to product owners.
10. Collaboratewith product owners, developers, security, audit, finance and leadershipstakeholders to ensure platform capabilities are practical, governed andaligned to business outcomes.
11. Documentreusable patterns, operating procedures and platform decisions to improveadoption, maintainability and knowledge retention.
Required Skills and Experience
1. 10+years of hands-on engineering experience, including significant experiencedesigning, building, managing and operating cloud infrastructure on MicrosoftAzure in enterprise or regulated environments.
2. Deephands-on experience with Azure platform services such as Azure Landing Zones,Azure Policy, Azure Container Apps, Azure App Service, API Management, AzureMonitor, Log Analytics, Defender for Cloud and Azure Cost Management.
3. Hands-onexperience operating in Government Commercial Cloud (GCC) environments,including working within government cloud governance, security, compliance,identity, network and operational controls.
4. Extensivehands-on experience with infrastructure-as-code, automated provisioning andconfiguration management using Azure Bicep, Terraform or equivalent tools.
5. Extensiveexperience designing and operating CI/CD and GitOps pipelines using AzureDevOps, GitHub, ShipHATS or similar platforms, including automated build, test,security scanning, deployment promotion, rollback and release quality gates.
6. Stronghands-on experience applying DevSecOps practices and implementing platformguardrails, including secure software delivery, automated quality checks,secrets management, vulnerability scanning, policy-as-code and compliancecontrols.
7. Stronghands-on experience in identity and access engineering using Microsoft EntraID, RBAC, Conditional Access, PIM, access reviews and least-privilege accessgovernance.
8. PracticalAI literacy and experience using AI-assisted development tools such as Claude,GitHub Copilot, Microsoft Copilot or equivalent tools to improve softwaredelivery, code quality, documentation, testing or developer productivity.
9. Experienceintegrating, securing and operating AI/ML platform services on Azure, includingaccess controls, network security, service configuration, monitoring andproduction-readiness controls for AI-enabled applications.
10. Workingknowledge of Active Directory and enterprise identity integration concepts,including directory services, group-based access, authentication flows andhybrid identity considerations.
11. Workingknowledge of modern authentication and authorization standards, including SAML,OpenID Connect, OAuth 2.0, JWT and related enterprise application integrationpatterns.
12. Workingknowledge of containerization, APIs, cloud-native application patterns andproduction-readiness practices.
13. Experiencesupporting at least one production cloud-native application or shared platformcapability, with responsibility for reliability, monitoring, deployment oroperational support.
14. Abilityto translate platform architecture into reusable engineering patterns,templates, developer self-service capabilities and platform services thatproduct teams can consume with minimal friction.
15. Strongdocumentation and communication skills, with the ability to explain technicalconcepts to both engineering and non-technical stakeholders.
16. Comfortableworking in an agile, product-oriented environment where platform capabilitiesare built incrementally and improved through adoption feedback.
Preferred Skills
1. Experiencewith AI application platforms, Azure OpenAI, Microsoft Fabric, Synapse, dataproducts or AI governance patterns.
2. Experiencebuilding developer portals, internal platforms, platform APIs, self-serviceworkflows or golden-path engineering templates.
3. Familiaritywith public sector cloud environments, government security requirements orregulated enterprise environments.
4. Experiencewith observability, SRE practices, incident response automation, MicrosoftSentinel, alert routing and service health dashboards.
5. Understandingof FinOps practices, cloud cost optimization, TCO modelling and costaccountability mechanisms.
6. Exposureto tools such as Jira, Confluence, GitHub, Azure DevOps, ShipHATS, Copilot orother modern engineering productivity tools.