Platform Engineer (Azure)
Gokool Digital
Job Description & Responsibilities
About the role
We are looking for an Azure specialist to own our cloud platform end to end: the infrastructure, the deployment path, the environments, and the identity and security that sit around them.
This is a hands-on engineering role rather than an advisory one. We want someone who defines infrastructure in code, verifies what they deploy, and wants complete ownership of the platform rather than shared responsibility for parts of it. You will take over infrastructure, deployment and environment work that currently sits with our engineering lead, and you will be the person the team relies on to get an environment stood up properly and quickly.
What you will do
The Azure estate
- Own our infrastructure as code: Azure Container Apps, Azure Database for PostgreSQL Flexible Server with Entra-only authentication, Key Vault, Azure Front Door with WAF, virtual networks, private endpoints and private DNS, and managed identity throughout.
- Keep the running estate aligned to the secure reference architecture as the product changes, rather than letting the two drift apart.
- Own sizing, capacity and cost.
Deployment and CI/CD
- Own the deployment path end to end through the Azure Developer CLI, from environment configuration through Bicep parameters to the settings the running application actually sees.
- Verify deployments by reading state back out of Azure. A command that exits cleanly is not evidence that a setting applied.
- Own build and release pipelines in Azure DevOps, including sharded test runs and Linux container images carrying native dependencies.
Environments
- Build and run the development, test and demonstration environments, and the sandbox tenants the product is tested against.
- Own the credentials and consent that make those environments reachable: Entra ID app registrations, service principals, app-only consent, and certificate and secret rotation, with Key Vault as the only place secrets live.
- Make standing up a fresh, working environment a routine act rather than a project.
Security and operations
- Own the security posture in practice: network isolation, least privilege, secret handling and tenant isolation. Support customer security questionnaires and security reviews with evidence rather than assertion.
- Own observability: Application Insights and Log Analytics, alerting that means something, and a health view somebody would actually look at.
- Write and maintain the runbooks, so that the platform does not depend on any one person.
Essential skills and experience
- Five or more years in Azure infrastructure and platform engineering, predominantly hands-on rather than advisory.
- Bicep as your primary tool. You define infrastructure in code and treat the portal as a place to look rather than a place to change things. Equivalent depth in Terraform or ARM is fine if you are ready to work in Bicep from day one.
- Azure Container Apps or AKS, Azure Database for PostgreSQL Flexible Server, Key Vault, Azure Front Door, Web Application Firewall, virtual networks, private endpoints and private DNS zones.
- Microsoft Entra ID in depth: app registrations, service principals, managed identity, app-only against delegated permissions, admin consent, and certificate credentials and their rotation.
- Azure DevOps YAML pipelines, or GitHub Actions with a willingness to work in Azure DevOps.
- Docker and Linux container builds, including images that carry native dependencies.
- Azure CLI, the Azure Developer CLI (azd), and PowerShell or Bash to a good standard.
- Enough TypeScript and Node to read the application, debug a configuration problem and make a small fix yourself. You will be working alongside the application, not around it.
- The habit of verifying. When you say something is deployed, it is because you have checked the running state, not because a pipeline went green.
Desirable
- Microsoft certifications: AZ-305 Azure Solutions Architect Expert, AZ-400 DevOps Engineer Expert, or AZ-104 Azure Administrator.
- Microsoft business platform administration: Power Platform and the pac command line, Dataverse environment management, Managed Environments, or Dynamics 365 Finance and Operations environments through LCS.
- Microsoft Graph app-only access and SharePoint tenant administration.
- Microsoft Fabric and Power BI workspace administration.
- FinOps and Azure cost management.
- A consultancy or software product background, where one platform serves several customers and isolation between them matters.
- Exposure to security questionnaires, penetration test remediation, the Essential Eight or ISO 27001.
What success looks like
3 months
You own the deployment path, you have rebuilt an environment from code end to end, and you have told us what in the current estate you would change and why.
6 months
Environments are stood up and proven without the engineering lead involved. Deployment is routine and evidenced.
12 months
The platform deploys into a new subscription from code alone, the security posture is demonstrable rather than described, and the runbooks are good enough for somebody else to run it while you are on leave.
About Gokool Digital
Required Skills
Job Details
Posted by
N/A
Posted on:
6 Oct 2026
About Gokool Digital
More open roles
- Frontend Engineer (React / TypeScript)Money Forward India · Chennai, Tamil Nadu, India
- Frontend Engineer (React / TypeScript)Money Forward India · Chennai, Tamil Nadu, India
- Frontend Developer React.js, TypeScript & Shopify (Gurugram)Aumraa · Gurugram, Haryana, India
- Frontend Developer React.js, TypeScript & Shopify (Gurugram)Aumraa · Gurugram, Haryana, India
- Frontend Developer React.js, TypeScript & Shopify (Gurugram)Aumraa · Gurugram, Haryana, India
- Frontend Developer React.js, TypeScript & Shopify (Gurugram)Aumraa · Gurugram, Haryana, India