Cloud Platform Engineer

Il y a 1 jour

Brussels, Brussels-Capital, Belgique Atos Temps plein
Cloud Platform Engineer Contract One-year B2B contract Location 50% onsite Brussels or fully remote EU Position Summary We are seeking an experienced Cloud Platform Engineer to join the Cloud System Team. The Cloud System Team engineers, automates and continuously improves the organisation's cloud platform foundation, enabling secure, scalable and standardized cloud adoption across corporate, business-critical and highly critical operational workloads. The cloud platform is primarily based on Microsoft Azure and follows a landing zone model aligned with the Microsoft Cloud Adoption Framework. It relies heavily on Infrastructure as Code using Terraform, DevSecOps, policy-as-code, reusable platform services and self-service cloud consumption. The Cloud Platform Engineer develops and maintains reusable Terraform modules, landing zone and subscription automation, governance controls, networking services, observability capabilities and security guardrails. The role translates approved architecture, security and operational requirements into reusable cloud platform services that application teams can consume consistently, securely and compliantly. The role collaborates closely with Cloud Architects, Security teams, Cloud Run engineers and application teams. This includes hands-on application enablement where required and close cooperation with the Cloud Run Team on operational readiness, knowledge exchange, cross-skilling and potential rotation between engineering and run-support functions. The organisation also operates dedicated cloud environments for highly critical operational workloads, requiring enhanced security, resilience and Zero Trust controls implemented through code and reusable platform capabilities. Key Tasks and Responsibilities The scope includes, but is not limited to: Cloud Platform Engineering
• Engineer, automate and continuously improve the Azure cloud platform foundation and reusable platform services.
• Implement approved architecture, security and operational requirements and contribute to platform standards, lifecycle management and controlled technology adoption.
• Improve self-service cloud consumption, developer experience and delivery consistency through standardized platform products and automation. Terraform, Landing Zones and Automation
• Develop and maintain reusable Terraform modules, module standards and the approved module catalog, including testing, documentation, versioning and lifecycle management.
• Implement and automate platform and application landing zones, subscription provisioning, management-group placement, baseline controls and workload onboarding.
• Drive configuration consistency, automation and removal of manual provisioning through controlled code repositories and deployment pipelines. Governance, Security and DevSecOps
• Implement Azure Policy and governance controls as code, translating approved security and compliance requirements into enforceable platform guardrails.
• Develop secure Azure DevOps pipelines for Terraform validation, testing, scanning, quality gates, approvals and controlled environment promotion.
• Implement Zero Trust controls covering identity, managed identities, privileged access, certificates, Key Vault, private connectivity, network isolation and cloud-native security services. Cloud Networking and Connectivity
• Implement and maintain Virtual WAN, hub-and-spoke, ExpressRoute, VPN, Azure Firewall, Application Gateway, Private Link, DNS and third-party SD-WAN integrations.
• Support secure hybrid, partner and multi-region connectivity and troubleshoot routing, BGP, route propagation, segmentation, traffic inspection and name-resolution issues. Reliability, Resilience and Observability
• Implement reusable zone-redundant, multi-region, backup and disaster-recovery capabilities aligned with availability, RTO and RPO requirements.
• Develop Azure-native monitoring, logging and alerting capabilities using Azure Monitor, Log Analytics and Application Insights.
• Support resilience testing and ensure platform services are observable, supportable and operationally ready. Application Enablement and Collaboration
• Enable application teams to adopt approved landing zones, Terraform modules, Azure DevOps pipelines and secure platform patterns, including hands-on or temporarily embedded support where required.
• Work closely with Cloud Architects on feasibility and implementation, and with Security and Cloud Run teams on controls, operational readiness, incident analysis and service improvement.
• Contribute to peer reviews, technical documentation, knowledge transfer, cross-skilling and continuous improvement of the cloud platform. Job Requirements Technical Competencies and Experience
• Proven expertise in designing, implementing and operating enterprise-scale Microsoft Azure environments.
• Strong expertise in Terraform and Infrastructure as Code, including reusable module development, module lifecycle management and infrastructure automation at scale.
• Proven experience implementing and evolving Azure landing zones and cloud foundation services aligned with enterprise governance requirements.
• Strong expertise in Azure DevOps, Git-based workflows, CI/CD and DevSecOps practices for cloud infrastructure delivery.
• Proven experience implementing policy-as-code through Azure Policy and automated governance controls.
• Strong expertise in cloud networking, including Azure Virtual WAN, hub-and-spoke architectures, ExpressRoute, VPN, routing, segmentation and hybrid connectivity.
• Practical expertise in implementing and troubleshooting Azure Firewall, Application Gateway, Private Endpoints, Private Link and Private DNS services.
• Strong understanding of Zero Trust principles and proven experience implementing identity, networking and security controls in Azure.
• Proven experience implementing Microsoft Entra ID integrations, managed identities, privileged access controls, certificate management and Azure Key Vault.
• Proven experience implementing highly available, zone-redundant and multi-region cloud solutions.
• Strong understanding of disaster recovery, backup, resilience engineering and business continuity requirements.
• Proven experience implementing Azure-native observability using Azure Monitor, Log Analytics and Application Insights.
• Ability to troubleshoot complex issues spanning infrastructure, networking, security, identity and cloud delivery pipelines.
• Proven experience delivering reusable cloud platform products consumed by multiple application teams.
• Proven ability to collaborate effectively with architecture, security, operations and application teams in a cloud platform engineering context.
• Knowledge of AWS foundations and multi-cloud concepts is considered an advantage. Level of Education University degree of four years in a relevant domain, such as Computer Science or Information Technology, or equivalent professional experience. Professional Certifications and Training Preferred certifications
• Microsoft Certified: Azure Administrator Associate
• Microsoft Certified: DevOps Engineer Expert Considered an advantage
• Microsoft Certified: Azure Network Engineer Associate
• Microsoft Certified: Azure Security Engineer Associate
• HashiCorp Certified: Terraform Associate
• AWS Certified Solutions Architect
- Associate or Professional Behavioural Competences
• Strong engineering, automation and product-oriented mindset.
• Strong analytical and troubleshooting skills, with the ability to work independently in multidisciplinary teams.
• Strong collaboration, communication and knowledge-sharing capabilities.
• High attention to code quality, maintainability, security and documentation.
• Commitment to continuous improvement and professional development.
• Collaborative and communicative, with the ability to work effectively in multi-disciplinary and geographically distributed environments.