Principal Cloud Platform Engineer
Role details
Job location
Tech stack
Job description
As the Principal Cloud Platform Engineer, you will serve as the technical authority for Azure landing zones and platform modules, ensuring secure-by-default patterns are embedded throughout. You will design and implement reusable Infrastructure-as-Code (IaC) for Azure and develop automation for IaaS workloads (Windows, Linux, VMware) to meet resilience, security, and cost objectives. A key aspect of this role is providing operational support for both IaaS and cloud platform technologies, ensuring stability, performance, and compliance across environments. You will also set engineering standards, guide best practices, and collaborate with cross-functional teams to deliver a robust, scalable, and secure cloud platform that supports business growth and innovation., Azure Platform Design & Governance
- Define and maintain management group and subscription strategies to support scalability and compliance.
- Design and implement RBAC models, policy initiatives, and connectivity patterns aligned with security and regulatory requirements.
- Maintain standardized deployment paths ("paved roads") for application teams to ensure secure and efficient cloud adoption.
Infrastructure as Code & Automation
- Develop and publish reusable, versioned Bicep/Terraform modules for AKS, PaaS services, and Windows/Linux VM stacks.
- Enforce rigorous testing, promotion controls, and quality gates for infrastructure-as-code (IaC).
- Build and maintain landing zone automation, including hub-and-spoke/vWAN architectures, private endpoints, DNS, and hybrid connectivity via ExpressRoute/VPN.
Security, Observability & Cost Management
- Codify observability baselines, backup strategies, and disaster recovery patterns.
- Integrate security controls such as Microsoft Defender, PIM, and Conditional Access.
- Implement cost guardrails and deliver golden CI/CD templates with policy gates, SBOM generation, and secrets scanning.
Operational Support & Reliability
- Provide operational support for IaaS and cloud platform technologies, ensuring performance and stability.
- Create hardened VM images and configuration baselines aligned with CIS/STIG standards; implement automated patching and desired state configuration.
- Support migrations from VMware to Azure, including rollback and disaster recovery planning.
Technical Leadership & Governance
- Mentor engineers and promote cloud best practices across teams.
- Lead architecture reviews and technical governance forums to ensure alignment with enterprise standards.
- Approve major design decisions to ensure platform scalability, security, and compliance.
Requirements
Do you have experience in VPN?, Do you have a Bachelor's degree?, * Proven experience designing and operating Azure platforms (landing zones, shared services, IaaS/PaaS) in enterprise environments.
- Hands on expertise with IaC (Terraform/Bicep), CI/CD (GitHub Actions/Azure DevOps), and platform automation.
- Strong background in identity and access management (AAD, RBAC, PIM), policy as code, and Zero Trust principles.
- Practical knowledge of network architecture (VNets, vWAN, ExpressRoute, private endpoints, DNS) and secure connectivity patterns.
- Experience codifying observability, backup/DR, and SRE practices (SLOs, error budgets).
- Exposure to FinOps practices and cost guardrails for cloud optimization.
- Operational support of Windows/Linux VM estates including hardened baselines (CIS/STIG), patch orchestration, and desired state.
- Track record migrating workloads from VMware to Azure, including rollback and DR strategies.
Education:
- Bachelor's degree in Computer Science, Engineering, or related field (or equivalent experience
- Any of the following certifications would be advantageous: Azure (AZ 305, AZ 500, AZ 400) and Kubernetes (CKA/CKAD), FinOps Certified Practitioner, ITIL 4 Foundation