Platform Engineer – Azure
- Location: Ontario, Ontario
- Type: Contract
- Job #35655
Platform Engineer – Azure
We are seeking a hands-on Platform Engineer to help build, secure, harden, and operate a secure Microsoft Azure cloud platform through to a stable and supportable steady state.
This is a highly hands-on engineering role. The successful candidate will be expected to perform the technical work directly, while also reviewing their own and adjacent work, identifying gaps, raising risks, and helping ensure the platform is secure, repeatable, maintainable, and operationally sound.
The two highest priorities for this role are Azure governance and policy enforcement and automated deployment pipelines / Azure DevOps.
Key Responsibilities
- Build, harden, operate, and continuously improve a secure Azure cloud platform.
- Review and safely implement Azure governance policies and controls without negatively impacting existing services.
- Develop, manage, and enforce Azure Policy initiatives and custom policy definitions.
- Manage the audit-to-enforce lifecycle, including policy remediation and exemptions.
- Build, support, and troubleshoot automated deployment pipelines using Azure DevOps YAML.
- Ensure deployment processes and evidence are reliable, repeatable, traceable, and supportable.
- Configure and support WIF/OIDC service connections and self-hosted or VMSS build agents.
- Diagnose failed, inconsistent, or misleading pipeline executions and implement appropriate corrections.
- Implement and maintain least-privilege access controls using Microsoft Entra ID and Azure RBAC.
- Support Privileged Identity Management (PIM) and just-in-time access/elevation.
- Identify and reduce excessive or unnecessary permissions across users, services, and workloads.
- Harden Azure infrastructure, endpoints, build agents, and network connectivity.
- Implement and review network egress restrictions, encryption controls, diagnostic logging, and audit logging.
- Develop and maintain reusable Infrastructure-as-Code (IaC) using Bicep.
- Create parameterized and modular Bicep templates and perform what-if, drift, and local build validation.
- Build and secure Azure environments using landing zones, hub-spoke networking, firewalls, NSGs, Key Vault, and customer-managed encryption keys (CMK).
- Review pull requests, infrastructure changes, policy changes, permissions, and what-if output to identify potential gaps or risks.
- Proactively flag configuration drift, overly broad access, missing controls, insufficient logging, or missing deployment evidence.
- Create and maintain technical documentation, operational procedures, and runbooks.
- Ensure platform changes are repeatable, reviewable, documented, and suitable for a clean operational handoff.
- Help transition the Azure platform into a stable, maintainable, and supportable ongoing capability.
Required Skills & Experience
- Strong hands-on experience with Microsoft Azure platform engineering / cloud infrastructure.
- Strong experience with Azure governance and Azure Policy, including initiatives, custom definitions, remediation, exemptions, and policy enforcement.
- Strong experience with Azure DevOps and YAML-based CI/CD deployment pipelines.
- Experience with Workload Identity Federation (WIF), OIDC service connections, and build/deployment agents.
- Experience supporting self-hosted and/or VM Scale Set (VMSS) build agents.
- Strong understanding of Microsoft Entra ID, Azure RBAC, least-privilege access, and PIM.
- Experience with Azure security hardening, including networking, endpoints, encryption, logging, and audit controls.
- Hands-on Infrastructure-as-Code (IaC) experience using Bicep.
- Experience developing modular and parameterized infrastructure templates.
- Experience with Azure landing zones and hub-spoke network architectures.
- Knowledge of Azure Firewall, Network Security Groups (NSGs), Key Vault, and customer-managed keys (CMK).
- Ability to review technical changes critically, identify gaps and risks, and recommend practical remediation.
- Strong troubleshooting skills across Azure infrastructure, deployment pipelines, identity/access, networking, and security controls.
- Ability to work independently in a hands-on engineering environment while collaborating effectively with adjacent technical teams.
- Strong documentation, operational handoff, and platform support practices.
Nice to Have
- Experience with Databricks or other cloud-based data and analytics platforms.
- Experience with Microsoft Defender for Cloud and cloud security monitoring.
- Comfortable working in CLI-driven environments, including Linux and/or Windows Subsystem for Linux (WSL).