Lead Cloud Platform Engineer, Azure

6 days ago

Toronto ON, Toronto Census Division, ON; Ontario, Canada Thomson Reuters Full-time €140,600 - €190,600 Temporary

About The Role

You’ll own the Azure platform that Thomson Reuters product engineering teams build on: the infrastructure itself – networking, identity, AKS, deployment pipelines – and equally the experience of using it. How quickly a team can stand up a compliant service. How fast they find out when something breaks. How confident we are when an auditor asks how access control works.

You’ll own the Azure platform that Thomson Reuters product engineering teams build on: the infrastructure itself – networking, identity, AKS, deployment pipelines – and equally the experience of using it. How quickly a team can stand up a compliant service. How fast they find out when something breaks. How confident we are when an auditor asks how access control works.

The role is based in Canada and supports infrastructure rollouts across multiple global regions, which means data residency, regional compliance obligations, and cross-region resilience are part of your daily thinking rather than edge cases.

This is a hands‑on senior individual contributor position with broad technical authority. You will write Bicep, operate and improve our AKS footprint, review other people’s infrastructure changes, sit in architecture discussions with product teams, and lead the platform’s technical response during compliance audits.

What You’ll Do

  • Own infrastructure as code. Define, extend, and maintain our Azure estate in Bicep, deployed through automated pipelines with peer review and preview gates. No untracked portal changes.
  • Operate Kubernetes at production scale. Own our AKS platform end to end – cluster architecture and upgrades, node pool strategy, networking (CNI, ingress, service mesh where applicable), workload identity, autoscaling (HPA/KEDA and cluster autoscaler), resource governance, and cost. Support the engineering teams running workloads on it and be their escalation path when clusters misbehave.
  • Run identity and access. Administer Entra ID (Azure AD) for engineering – RBAC design, least‑privilege role assignments, PIM and just‑in‑time elevation, managed identities and workload identity federation, access reviews. Make the secure path the easy path.
  • Be the technical lead for compliance audits. Serve as the platform subject‑matter expert for SOC 2, HIPAA, and ISO 27001: produce evidence, explain controls to auditors and assessors, and close findings. Encode controls as Azure Policy so compliance is enforced continuously rather than reconstructed at audit time.
  • Handle multi‑region and data residency requirements. Design regional deployment patterns that satisfy residency and sovereignty obligations while keeping the platform coherent and operable from a single set of code and pipelines.
  • Consult engineering teams on infrastructure decisions. Partner with product teams early on service design, data store selection, network posture, scaling strategy, and cost. Advise and unblock rather than gatekeep.
  • Design for scale. Apply Azure’s scaling primitives – AKS autoscaling, App Service plans, autoscale rules, database tiers and read replicas, caching, queue‑based load levelling – to help applications meet demand predictably and economically.
  • Own resilience. Design and test multi‑AZ and multi‑region architectures, define RTO/RPO with product owners, and build and actually rehearse disaster recovery and backup restore procedures.
  • Make the platform observable. Build and troubleshoot with Log Analytics, Container Insights, and Application Insights. Write KQL that answers real questions, design alerts that page on symptoms rather than noise, and help teams define meaningful SLOs.
  • Secure the estate. Manage secrets in Key Vault, drive Defender for Cloud and Defender for Containers findings to resolution, and keep patching, image hygiene, and vulnerability remediation moving.
  • Manage cost. Maintain tagging and showback so teams see their spend, and drive right‑sizing and commitment‑based savings across regions.
  • Participate in incident response. Join the on‑call rotation for platform services, lead or contribute to blameless postmortems, and turn findings into durable fixes.
  • Multiply other engineers. Write documentation people actually read, build reusable Bicep modules and golden‑path templates, mentor engineers, and raise the bar in design and code review.

About You

  • 5+ years operating Microsoft Azure in production for cloud‑native applications, including at least one environment with real availability and compliance obligations.
  • Production AKS or equivalent Kubernetes experience — you have run clusters, not just deployed to them: upgrades, node pool design, ingress and cluster networking, autoscaling, workload identity, and debugging failures under load.
  • Deep infrastructure‑as‑code practice with Bicep (or strong AR