|
Azure Cloud Platform Engineer.
Purpose of the role
Build, configure, and operate the Azure platform for Spectra network, compute, storage, identity, observability, implementing repeatable patterns across up to several instances, with strong focus on containerisation, Azure DevOps, IaC bicep and terraform.
Key responsibilities
- Design, implement, and operate Azure platform foundations, including hub-and-spoke or Virtual WAN networking, subnetting, routing, private endpoints, firewall/NVA integration, and DNS
- Build and standardise compute and container platforms (AKS, Azure Container Apps, App Service), including container registries (ACR) and ingress using Application Gateway / WAF
- Provision and operate data and storage platforms, including PostgreSQL Flexible Server, Azure Files and Blob storage tiers, backup, and restore strategies
- Establish observability and platform security controls, including Azure Monitor, Log Analytics, alerting, dashboards, Key Vault integration, and policy enforcement
- Define and maintain repeatable platform patterns and infrastructure standards to support programme-by-programme deployments at scale
- Support proof-of-concepts, pilots, and wave-based migrations, owning cutover planning, runbooks, rollback strategies, and operational readiness
- Troubleshoot complex platform, networking, and performance issues, working closely with internal application teams, DevOps engineers, and external vendor technical teams to diagnose and resolve problems
- Act as a technical point of contact for platform-related discussions, providing guidance, design assurance, and escalation support to stakeholders
Experience & skills
- Proven senior-level Azure platform engineering experience delivering complex, regulated workloads at scale
- Proven ability to design repeatable Azure landing zone patterns across multiple subscriptions, environments, or tenants.
- Strong hands-on experience with Azure networking and security architecture, including hub-and-spoke or centralised networking models and private connectivity.
- Practical experience enabling and operating container and PaaS platforms (AKS, Azure Container Apps, or App Service) for application teams
- Solid infrastructure-as-code experience, with responsibility for structuring, maintaining, and evolving IaC modules (Terraform and/or Bicep)
- Strong understanding of availability, resiliency, and operational readiness for systems requiring near-continuous uptime
Technology & Tooling
- Azure Networking: hub and spoke, Virtual WAN, Private Endpoints, Firewall/NVA, DNS.
- Identity/Security: Microsoft EntraID, Key Vault, policies/baselines, NHS Digital/NCSC alignment.
- Compute/Containerisation: AKS, Azure Container Apps, App Service, App Gateway/WAF, ACR.
- Data/Storage: PostgreSQL Flexible Server, Azure Files/Blob (including premium tiers).
- Observability: Azure Monitor/Log Analytics.
- Integrations: API Management
- Hybrid Connectivity: VPN via VWAN; migration utilities
- Automation: Terraform/Bicep, Azure DevOps/GitHub Actions.
Preferred certifications
- Azure Administrator (AZ104),
- Azure Developer (AZ204), CKA/CKAD.
|