02 Sep
|
Thomson Reuters
|
Canada
02 Sep
Thomson Reuters
Canada
- You’ll own the Azure platform that Thomson Reuters product engineering teams build on: the infrastructure itself — networking, identity, AKS, deployment pipelines — and equally the experience of using it. How quickly a team can stand up a compliant service. How rapid they find out when something breaks.
How confident we are when an auditor asks how access control works
- The role is based in Canada and supports infrastructure rollouts across multiple global regions, which means data residency, regional compliance obligations, and cross-region resilience are part of your daily thinking rather than edge cases
- This is a hands-on senior individual contributor position with broad technical authority. You will write Bicep, operate and improve our AKS footprint, review other people’s infrastructure changes, sit in architecture discussions with product teams, and lead the platform’s technical response during compliance audits
- Own infrastructure as code. Define, extend, and maintain our Azure estate in Bicep, deployed through automated pipelines with peer review and preview gates. No untracked portal changes
- Operate Kubernetes at production scale. Own our AKS platform end to end — cluster architecture and upgrades, node pool strategy, networking (CNI, ingress, service mesh where applicable), workload identity, autoscaling (HPA/KEDA and cluster autoscaler), resource governance, and cost. Support the engineering teams running workloads on it and be their escalation path when clusters misbehave
- Run identity and access.
Administer
Entra ID (Azure AD) for engineering — RBAC design, least-privilege role assignments, PIM and just-in-time elevation, managed identities and workload identity federation, access reviews. Make the secure path the easy path
- Be the technical lead for compliance audits. Serve as the platform subject-matter expert for SOC 2, HIPAA, and ISO 27001: produce evidence, explain controls to auditors and assessors, and close findings. Encode controls as Azure Policy so compliance is enforced continuously rather than reconstructed at audit time
- Handle multi-region and data residency requirements.
Design regional deployment patterns that satisfy residency and sovereignty obligations while keeping the platform coherent and operable from a single set of code and pipelines
- Consult engineering teams on infrastructure decisions. Partner with product teams early on service design, data store selection, network posture, scaling strategy, and cost. Advise and unblock rather than gatekeep
- Design for scale.
Apply
Azure’s scaling primitives — AKS autoscaling, App Service plans, autoscale rules, database tiers and read replicas, caching, queue-based load levelling — to help applications meet demand predictably and economically
- Own resilience. Design and test multi-AZ and multi-region architectures, define RTO/RPO with product owners, and build and actually rehearse disaster recovery and backup restore procedures
- Make the platform observable. Build and troubleshoot with Log Analytics, Container Insights, and Application Insights. Write KQL that answers real questions, design alerts that page on symptoms rather than noise, and help teams define meaningful SLOs
- Secure the estate. Manage secrets in Key Vault, drive Defender for Cloud and Defender for Containers findings to resolution, and keep patching, image hygiene, and vulnerability remediation moving
- Manage cost. Maintain tagging and showback so teams see their spend, and drive right-sizing and commitment-based savings across regions
- Participate in incident response. Join the on-call rotation for platform services, lead or contribute to blameless postmortems, and turn findings into durable fixes
- Multiply other engineers. Write documentation people actually read, build reusable Bicep modules and golden-path templates, mentor engineers, and raise the bar in design and code review- The ability to influence without authority — you can join another team’s design review, understand their constraints,
and leave them with a better plan than they arrived with
- CI/CD experience with Azure DevOps or GitHub Actions
- Working proficiency in at least one programming language (Python, Go, C#, or similar) plus PowerShell or Azure CLI for automation
- Azure networking fluency — VNets, subnets, NSGs, private endpoints and Private DNS, hub-spoke topology, Front Door / Application Gateway / WAF, and cross-region connectivity
- Deep infrastructure-as-code practice with Bicep (or strong ARM/Terraform experience and readiness to work primarily in Bicep). Comfortable with modules, deployment stacks, what-if, and pipeline-driven deployment
- 5+ years operating Microsoft Azure in production for cloud-native applications, including at least one environment with real availability and compliance obligations
- A demonstrated role in a SOC 2, HIPAA, or ISO 27001 audit as a technical expert, not solely as an evidence provider
- Hands-on Entra ID / Azure AD administration — RBAC, conditional access, PIM, service principals, managed identities
- Strong troubleshooting in Log Analytics and Application Insights, including writing your own KQL
- Production AKS or equivalent Kubernetes experience — you have run clusters, not just deployed to them: upgrades, node pool design, ingress and cluster networking, autoscaling, workload identity, and debugging failures under load
- Practical knowledge of Azure scaling and resilience — autoscale, availability zones, paired-region strategies, and failover testing you have personally run
- Relevant certification (AZ-305, AZ-500, CKA) — useful signal, not a substitute for experience
- Infrastructure for AI/ML workloads — GPU capacity planning, Azure OpenAI, private model endpoint
- Multi-cloud exposure (AWS/GCP) or cloud migration experience
- FinOps or cost-optimization track record with measurable results
- GitOps tooling (Flux, Argo CD) and progressive delivery
- Experience with healthcare or other regulated data beyond HIPAA — PIPEDA, PHIPA, GDPR, or regional sovereignty requirements
- Azure Policy and landing zone or Cloud Adoption Framework implementation at enterprise scale- End Date: November 25, 2026
📌 Lead Cloud Platform Engineer (Azure) (Canada)
🏢 Thomson Reuters
📍 Canada