Platforms/Infrastructure Engineer
We are looking for an experienced Platforms/Infrastructure Engineer to join a global technology environment and take responsibility for the design, operation, security, and continuous improvement of Microsoft Azure and hybrid infrastructure platforms. The role combines strong Microsoft Azure, Entra ID, Windows/Linux Server, Infrastructure as Code, automation, security, observability, and platform operations expertise. The engineer will help design and maintain secure Azure landing zones, support global infrastructure services and business-critical environments, and act as an escalation point for complex platform issues.
Key Responsibilities:
Design, build, maintain, and optimise Microsoft Azure infrastructure and hybrid cloud environments.
Design and maintain secure Azure landing zones, platform guardrails, policies, subscription structures, naming standards, and access controls.
Manage and improve Microsoft Entra ID services, including RBAC, PIM, Conditional Access, MFA, SSO, SCIM, administrative units, and identity governance.
Build, harden, patch, maintain, and decommission Windows Server and Linux workloads across Azure, VMware/ESXi, Azure Local/HCI, colocation, and on-premises environments.
Support patching and lifecycle management, including virtual patching approaches for legacy operating systems where standard patching is not possible.
Design and deploy infrastructure using Infrastructure as Code, primarily Terraform and Bicep, as well as ARMtemplates.
Develop and maintain infrastructure automation using PowerShell, Azure Automation Runbooks, JSON, andYAML.
Support Azure Automation Runbooks across cloud and hybrid environments, including Hybrid Worker configurations.
Monitor platform health, capacity, availability, and performance using Azure Monitor, Log Analytics, Azure Managed Grafana, and related observability solutions.
Ensure platform security and compliance through security hardening, CIS baselines, vulnerability remediation, identity controls, and certificate lifecycle management.
Manage patching, upgrades, and infrastructure lifecycle activities using Azure Update Manager and automation.
Participate in incident and problem management, including troubleshooting, root cause analysis, and implementation of long-term solutions.
Act as an escalation point and subject-matter expert for Azure, Entra ID, and server infrastructure.
Support highly available and resilient platforms using SRE principles, including HA, load balancing, resilience engineering, and continuous improvement.
Participate in an on-call rotation and occasional out-of-hours support for critical global services.
Must-Have Technical Skills:
Microsoft Azure
Microsoft Entra ID / Azure AD
Conditional Access, MFA, PIM, RBAC, SSO, SCIM, and identity governance
Windows Server 2016-2025
Linux - RHEL / Ubuntu
Terraform and Bicep
ARM templates
PowerShell
Azure Automation Runbooks and Hybrid Worker environments
Azure governance, secure landing zones, and platform security
Azure Monitor, Log Analytics, and Azure Managed Grafana
Server and cloud security hardening
Patch and lifecycle management, including legacy OS / virtual patching scenarios
Hybrid cloud / on-premises infrastructure
Experience Requirements:
5+ years of professional IT experience.
3+ years of hands-on cloud and infrastructure engineering experience, particularly with Microsoft Azure and hybrid environments.
Proven experience supporting large and complex enterprise environments.
Experience working across distributed/global teams.
Experience with ITIL-aligned operations, including Incident, Problem, Change, Request Fulfilment, and Service Transition.
Strong troubleshooting and root cause analysis capabilities.
Ability to work independently in a remote environment and manage priorities with minimal supervision.
Strong written and verbal English communication skills.
Experience in financial services, insurance, or a similarly complex enterprise environment is preferred.
Relevant Microsoft Azure certification(s) are required.
Nice to Have:
Azure networking: VNets, NSGs, firewalls, private endpoints, and routing.
VMware / ESXi and Azure Local / HCI.
Azure DevOps and GitHub Enterprise.CI/CD pipelines for infrastructure deployment.
Jira and Confluence.
Experience with cloud cost optimisation, forecasting, and consumption management.