Principal Cloud Platform Engineer

Moneycorp
Charing Cross, United Kingdom
4 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English

Job location

Charing Cross, United Kingdom

Tech stack

Microsoft Access
Microsoft Windows
Azure
Continuous Integration
Linux
Disaster Recovery
DNS
Github
Infrastructure as a Service (IaaS)
Identity and Access Management
Virtual Private Networks (VPN)
Network Architecture
Platform as a Service (PAAS)
Role-Based Access Control
Azure
Cloud Platform System
Kubernetes
Information Technology
Bicep
Cloud Optimization
Terraform
VMware

Job description

As the Principal Cloud Platform Engineer, you will serve as the technical authority for Azure landing zones and platform modules, ensuring secure-by-default patterns are embedded throughout. You will design and implement reusable Infrastructure-as-Code (IaC) for Azure and develop automation for IaaS workloads (Windows, Linux, VMware) to meet resilience, security, and cost objectives. A key aspect of this role is providing operational support for both IaaS and cloud platform technologies, ensuring stability, performance, and compliance across environments. You will also set engineering standards, guide best practices, and collaborate with cross-functional teams to deliver a robust, scalable, and secure cloud platform that supports business growth and innovation., Azure Platform Design & Governance

  • Define and maintain management group and subscription strategies to support scalability and compliance.
  • Design and implement RBAC models, policy initiatives, and connectivity patterns aligned with security and regulatory requirements.
  • Maintain standardized deployment paths ("paved roads") for application teams to ensure secure and efficient cloud adoption.

Infrastructure as Code & Automation

  • Develop and publish reusable, versioned Bicep/Terraform modules for AKS, PaaS services, and Windows/Linux VM stacks.
  • Enforce rigorous testing, promotion controls, and quality gates for infrastructure-as-code (IaC).
  • Build and maintain landing zone automation, including hub-and-spoke/vWAN architectures, private endpoints, DNS, and hybrid connectivity via ExpressRoute/VPN.

Security, Observability & Cost Management

  • Codify observability baselines, backup strategies, and disaster recovery patterns.
  • Integrate security controls such as Microsoft Defender, PIM, and Conditional Access.
  • Implement cost guardrails and deliver golden CI/CD templates with policy gates, SBOM generation, and secrets scanning.

Operational Support & Reliability

  • Provide operational support for IaaS and cloud platform technologies, ensuring performance and stability.
  • Create hardened VM images and configuration baselines aligned with CIS/STIG standards; implement automated patching and desired state configuration.
  • Support migrations from VMware to Azure, including rollback and disaster recovery planning.

Technical Leadership & Governance

  • Mentor engineers and promote cloud best practices across teams.
  • Lead architecture reviews and technical governance forums to ensure alignment with enterprise standards.
  • Approve major design decisions to ensure platform scalability, security, and compliance.

Requirements

Do you have experience in VPN?, Do you have a Bachelor's degree?, * Proven experience designing and operating Azure platforms (landing zones, shared services, IaaS/PaaS) in enterprise environments.

  • Hands on expertise with IaC (Terraform/Bicep), CI/CD (GitHub Actions/Azure DevOps), and platform automation.
  • Strong background in identity and access management (AAD, RBAC, PIM), policy as code, and Zero Trust principles.
  • Practical knowledge of network architecture (VNets, vWAN, ExpressRoute, private endpoints, DNS) and secure connectivity patterns.
  • Experience codifying observability, backup/DR, and SRE practices (SLOs, error budgets).
  • Exposure to FinOps practices and cost guardrails for cloud optimization.
  • Operational support of Windows/Linux VM estates including hardened baselines (CIS/STIG), patch orchestration, and desired state.
  • Track record migrating workloads from VMware to Azure, including rollback and DR strategies.

Education:

  • Bachelor's degree in Computer Science, Engineering, or related field (or equivalent experience
  • Any of the following certifications would be advantageous: Azure (AZ 305, AZ 500, AZ 400) and Kubernetes (CKA/CKAD), FinOps Certified Practitioner, ITIL 4 Foundation

About the company

In the last decade, Moneycorp has transformed from a largely domestic, consumer-focused provider of foreign exchange to an end-to-end global payments' ecosystem. With two banking licenses and operations across the entire value chain of the international payments and foreign exchange sectors, we enable businesses, institutions, and individuals to thrive beyond borders. We help our clients realise their growth ambitions by providing them with worldwide reach, relentless regulatory excellence, and tailored, relevant solutions that resiliently optimise their financial operations. We're fervent about pursuing our goals, making substantial contributions to the payments industry, and consistently offering unwavering support to our clients at every stage of their journey. Moneycorp is a place where energy, commitment to our shared success and collaboration are core to our DNA. We're restless in our drive to surpass the expectations of our clients and unlock opportunities to support them at every stage of their journey. The foundation of our success is our people, and nurturing a culture of belonging for all of our colleagues is central to our journey as a global business. Find out more about Moneycorp's offering, global footprint and capabilities here: About Us | moneycorp Your Next Challenge Our Technology Journey: We're at an exciting stage in our evolution. Having built strong foundations in traditional infrastructure and networking, we're now moving towards a cloud-native future - re-imagining how we design, build, and run platforms that scale with the business. This is more than a technology shift - it's a strategic transformation. We're modernising core services, adopting automation and DevOps practices, and building resilient, secure platforms ready for the future. Why This Matters For You: Joining us now means you'll help shape our direction, not just maintain it. You'll influence how we evolve from IaaS to cloud-native, work with modern technologies, and contribute to a collaborative team driving change. This journey will bring challenges, but with challenge comes opportunity - for innovation, for growth, and for making a lasting impact., Fostering a culture of belonging and inclusivity We're committed to creating a workplace where every individual feels valued, respected, and included. As an Equal Opportunity Employer, we actively cultivate an inclusive culture where diversity thrives, and we empower our colleagues to drive meaningful change within our organisation through initiatives like our DE&I focus groups and value champion network. Like many of our peers, we recognise that fostering inclusivity is an ongoing journey, and we remain steadfast in our commitment to progress. By measuring our efforts through regular assessments and listening to the feedback of our employees, we strive to ensure that our initiatives are impactful and responsive to the evolving needs of our workforce. Together, we want to build a workplace where everyone can bring their authentic selves to work, as we believe this is the foundation of innovation, creativity, and collective success.

Apply for this position