4 months ago
Nottingham, United KingdomStaff+
Responsibilities
- Develop and maintain Terraform modules for Azure core services and enforce infrastructure-as-code standards across providers.
- Deploy and manage AKS clusters using GitOps, Istio, security hardening, and standardized Helm charts.
- Design Azure networking architectures covering hub VNets, firewall policies, DNS, and related documentation.
- Implement identity, access, container security, CI/CD credential management, and compliance preparation measures.
- Modernize CI/CD platforms with reusable workflows, template repositories, automated versioning, provider-agnostic tooling, and security scanning.
- Establish observability with Loki, Grafana Alloy, and tracing, while integrating FinOps and capacity-planning practices.
- Build developer-experience automation, onboarding resources, and internal CLI tools.
- Provide technical support, roadmap design, architecture leadership, stakeholder communication, and mentorship for engineering teams.
- Adopt and evaluate enterprise platform technologies including ArgoCD, Cilium, Argo Rollouts, KEDA, Falco, Kyverno, DAPR, and multi-tenant AKS designs.
Requirements
- Expertise designing Azure landing zones, multi-subscription architectures, hub-spoke networking, and Azure services including Firewall, Front Door, App Service, Key Vault, Entra ID, and PIM.
- Deep production experience managing AKS or similar Kubernetes platforms, including lifecycle management, upgrades, RBAC, network policies, and security hardening.
- Expert Terraform module development, state management, CI/CD integration, and multi-region or multi-provider codebase management.
- Hands-on experience with Istio or Cilium for mTLS, traffic management, Gateway API, and zero-trust networking.
- Experience with ArgoCD or an equivalent GitOps and continuous-delivery platform.
- Strong experience with GitHub Actions workflows, Azure DevOps Pipelines, and CI platform migrations.
- Expert Azure networking knowledge covering VNets, NSGs, DNS, hub-spoke topology, and firewall design.
- Practical shift-left security experience including container scanning, image signing, CIS benchmarks, and penetration-test readiness.
- Skilled in authoring and maintaining Helm charts for standardized application deployment.
- Strong Linux, container lifecycle, Dockerfile optimization, and registry-management skills.
- Proficiency in Bash and Python for automation and internal tooling.
- Experience producing high-level and low-level designs, architectural decisions, and technical trade-off discussions.
- Effective communication with audiences ranging from developers to C-suite stakeholders.
- Proven ability to act as a technical escalation point and mentor diverse engineering teams.
- Experience designing and delivering greenfield cloud platforms, ideally with regulatory or compliance considerations.
- Go programming and experience with Cobra or Kong are desirable.
- Experience with Argo Rollouts, KEDA, Karpenter, or similar autoscaling and cluster-right-sizing tools is desirable.
Benefits
- Salary is listed as £75,000–85,000 in the description and £70,000–80,000 in the benefits section.
- Company bonus.
- Comprehensive healthcare cash plan.
- 27 days of annual leave plus Bank Holidays.
- Two wellbeing leave days and two community-giving days.
- Birthday off.
- Employer pension contribution of 5%.
- Death-in-service benefit of four times salary.
- Annual award recognition and regular social events.
- Training and professional development opportunities.
- Flexible hybrid working arrangements.
