The Senior Cloud Platform Engineer designs, builds, and operates automated, secure, and scalable cloud platforms across AWS and Azure for enterprise clients. This is a hands-on engineering role — owning landing zone architecture, Infrastructure as Code, CI/CD pipelines, container platforms, and observability — with the technical depth to troubleshoot production issues and the maturity to mentor junior engineers and influence platform standards across client engagements.
KEY RESPONSIBILITIES
1. Platform & Landing Zone Engineering
- Design and build secure, multi-account/multi-subscription landing zones on AWS (Control Tower, Organizations) and Azure (Landing Zones, Management Groups).
- Implement network architecture — VPCs/VNets, transit gateways, hybrid connectivity, DNS, and security group / NSG design.
- Define and enforce account/subscription governance guardrails, tagging standards, and cost controls.
2. Infrastructure as Code & Automation
- Author and maintain infrastructure using Terraform (primary) and/or CloudFormation / ARM / Bicep, structured as reusable modules.
- Build and maintain CI/CD pipelines (GitHub Actions, Azure DevOps, GitLab CI, or Jenkins) for both infrastructure and application deployments.
- Drive GitOps practices for environment provisioning and change management.
3. Containers & Orchestration
- Deploy, operate, and troubleshoot Kubernetes clusters (EKS, AKS) including networking (CNI), ingress, autoscaling, and RBAC.
- Support containerization of legacy and modernized workloads in partnership with application and modernization teams.
- Implement service mesh, secrets management, and workload identity patterns where applicable.
4. Observability & Reliability
- Implement monitoring, logging, and alerting using CloudWatch, Azure Monitor, Prometheus/Grafana, or equivalent.
- Define and track SLIs/SLOs for platform services; participate in on-call rotation and incident response.
- Conduct root-cause analysis for production issues and drive permanent fixes, not just workarounds.
5. Security & Compliance
- Implement identity and access management (IAM roles/policies, Azure AD/Entra ID RBAC), least-privilege access, and secrets management (Secrets Manager, Key Vault, HashiCorp Vault).
- Embed security controls into pipelines (SAST/DAST, image scanning, policy-as-code with tools such as OPA/Sentinel).
- Support compliance requirements relevant to client engagements, including DPDP Act 2023, ISO 27001, and client-specific regulatory frameworks under Minfy's Kavach360 programme.
6. Cost & Operational Efficiency
- Monitor and optimize cloud spend using native cost tools (Cost Explorer, Azure Cost Management) and rightsizing recommendations.
- Identify automation opportunities to reduce manual operational toil across managed environments.
7. Client & Cross-Functional Engagement
- Work directly with client engineering and infrastructure teams as a trusted technical resource on managed services and migration engagements.
- Partner with the MiMo and Cloud Advisory teams to implement platforms that support migration and modernization roadmaps.
- Produce clear runbooks, architecture diagrams, and platform documentation.
8. Mentorship & Technical Contribution
- Mentor junior and mid-level platform engineers; review their IaC and pipeline contributions.
- Contribute reusable modules, scripts, and accelerators to Minfy's internal platform engineering toolkit.
- Participate in architecture reviews and champion platform engineering best practices across the BU.
REQUIRED QUALIFICATIONS
1. Experience
- 5–8 years of experience in cloud infrastructure, platform engineering, DevOps, or Site Reliability Engineering roles.
- Demonstrated hands-on experience operating production workloads on both AWS and Azure (multi-cloud experience required).
2. Core Technical Skills
- Strong hands-on expertise with Terraform for multi-cloud Infrastructure as Code.
- Production experience with Kubernetes (EKS and/or AKS) — deployment, troubleshooting, and day-2 operations.
- Strong CI/CD skills — designing and building end-to-end pipelines (GitHub Actions, Azure DevOps, GitLab CI, or Jenkins) with automated testing, security gates, and deployment strategies (blue-green, canary, rolling).
- Strong containerisation skills — Docker image build and optimization, multi-stage builds, container registries (ECR, ACR), and container security scanning.
- Scripting proficiency in Python, Bash, or Go for automation and tooling.
- Solid networking fundamentals — VPC/VNet design, routing, DNS, load balancing, and hybrid connectivity.
3. Security & Governance
- Working knowledge of IAM/RBAC design, secrets management, and policy-as-code.
- Familiarity with security and compliance frameworks relevant to enterprise cloud environments (Well-Architected Framework, ISO 27001, DPDP Act 2023 or equivalent).
4. Collaboration & Communication
- Comfortable working directly with client technical stakeholders and cross-functional Minfy teams (advisory, MiMo, security).
- Able to produce clear technical documentation and communicate incident/root-cause findings effectively.
PREFERRED QUALIFICATIONS
- Certifications: AWS Certified Solutions Architect / DevOps Engineer, Microsoft Certified: Azure Administrator / DevOps Engineer Expert, or CKA/CKAD.
- Experience with GitOps tooling (ArgoCD, Flux).
- Exposure to service mesh technologies (Istio, Linkerd).
- Prior experience in a partner/SI or managed services environment (AWS Premier/Advanced Partner or Microsoft Solutions Partner).
- Familiarity with FinOps practices and cloud cost optimization.
KEY COMPETENCIES
- Ownership — treats production platforms as their own; drives issues to permanent resolution.
- Automation-first mindset — defaults to codifying repeatable work rather than manual intervention.
- Technical depth with pragmatism — balances best practice with delivery timelines and client constraints.
- Collaboration — works effectively across client teams, internal BUs, and junior engineers.
- Continuous learning — stays current across a fast-moving, multi-cloud technology landscape.