Lead Cloud Platform Engineer, Azure

Thomson ReutersToronto, ON
CA$140,600 - CA$190,600Hybrid

About The Position

You’ll own the Azure platform that Thomson Reuters product engineering teams build on: the infrastructure itself — networking, identity, AKS, deployment pipelines — and equally the experience of using it. How quickly a team can stand up a compliant service. How fast they find out when something breaks. How confident we are when an auditor asks how access control works. The role is based in Canada and supports infrastructure rollouts across multiple global regions, which means data residency, regional compliance obligations, and cross-region resilience are part of your daily thinking rather than edge cases. This is a hands-on senior individual contributor position with broad technical authority. You will write Bicep, operate and improve our AKS footprint, review other people’s infrastructure changes, sit in architecture discussions with product teams, and lead the platform’s technical response during compliance audits.

Requirements

  • 5+ years operating Microsoft Azure in production for cloud-native applications, including at least one environment with real availability and compliance obligations.
  • Production AKS or equivalent Kubernetes experience — you have run clusters, not just deployed to them: upgrades, node pool design, ingress and cluster networking, autoscaling, workload identity, and debugging failures under load.
  • Deep infrastructure-as-code practice with Bicep (or strong ARM/Terraform experience and readiness to work primarily in Bicep). Comfortable with modules, deployment stacks, what-if, and pipeline-driven deployment.
  • Hands-on Entra ID / Azure AD administration — RBAC, conditional access, PIM, service principals, managed identities.
  • A demonstrated role in a SOC 2, HIPAA, or ISO 27001 audit as a technical expert, not solely as an evidence provider.
  • Azure networking fluency — VNets, subnets, NSGs, private endpoints and Private DNS, hub-spoke topology, Front Door / Application Gateway / WAF, and cross-region connectivity.
  • Strong troubleshooting in Log Analytics and Application Insights, including writing your own KQL.
  • Practical knowledge of Azure scaling and resilience — autoscale, availability zones, paired-region strategies, and failover testing you have personally run.
  • Working proficiency in at least one programming language (Python, Go, C#, or similar) plus PowerShell or Azure CLI for automation.
  • CI/CD experience with Azure DevOps or GitHub Actions.
  • The ability to influence without authority — you can join another team’s design review, understand their constraints, and leave them with a better plan than they arrived with.

Nice To Haves

  • Azure Policy and landing zone or Cloud Adoption Framework implementation at enterprise scale
  • Experience with healthcare or other regulated data beyond HIPAA — PIPEDA, PHIPA, GDPR, or regional sovereignty requirements
  • GitOps tooling (Flux, Argo CD) and progressive delivery
  • FinOps or cost-optimization track record with measurable results
  • Multi-cloud exposure (AWS/GCP) or cloud migration experience
  • Infrastructure for AI/ML workloads — GPU capacity planning, Azure OpenAI, private model endpoint
  • Relevant certification (AZ-305, AZ-500, CKA) — useful signal, not a substitute for experience

Responsibilities

  • Own infrastructure as code. Define, extend, and maintain our Azure estate in Bicep, deployed through automated pipelines with peer review and preview gates. No untracked portal changes.
  • Operate Kubernetes at production scale. Own our AKS platform end to end — cluster architecture and upgrades, node pool strategy, networking (CNI, ingress, service mesh where applicable), workload identity, autoscaling (HPA/KEDA and cluster autoscaler), resource governance, and cost. Support the engineering teams running workloads on it and be their escalation path when clusters misbehave.
  • Run identity and access. Administer Entra ID (Azure AD) for engineering — RBAC design, least-privilege role assignments, PIM and just-in-time elevation, managed identities and workload identity federation, access reviews. Make the secure path the easy path.
  • Be the technical lead for compliance audits. Serve as the platform subject-matter expert for SOC 2, HIPAA, and ISO 27001: produce evidence, explain controls to auditors and assessors, and close findings. Encode controls as Azure Policy so compliance is enforced continuously rather than reconstructed at audit time.
  • Handle multi-region and data residency requirements. Design regional deployment patterns that satisfy residency and sovereignty obligations while keeping the platform coherent and operable from a single set of code and pipelines.
  • Consult engineering teams on infrastructure decisions. Partner with product teams early on service design, data store selection, network posture, scaling strategy, and cost. Advise and unblock rather than gatekeep.
  • Design for scale. Apply Azure’s scaling primitives — AKS autoscaling, App Service plans, autoscale rules, database tiers and read replicas, caching, queue-based load levelling — to help applications meet demand predictably and economically.
  • Own resilience. Design and test multi-AZ and multi-region architectures, define RTO/RPO with product owners, and build and actually rehearse disaster recovery and backup restore procedures.
  • Make the platform observable. Build and troubleshoot with Log Analytics, Container Insights, and Application Insights. Write KQL that answers real questions, design alerts that page on symptoms rather than noise, and help teams define meaningful SLOs.
  • Secure the estate. Manage secrets in Key Vault, drive Defender for Cloud and Defender for Containers findings to resolution, and keep patching, image hygiene, and vulnerability remediation moving
  • Manage cost. Maintain tagging and showback so teams see their spend, and drive right-sizing and commitment-based savings across regions.
  • Participate in incident response. Join the on-call rotation for platform services, lead or contribute to blameless postmortems, and turn findings into durable fixes.
  • Multiply other engineers. Write documentation people actually read, build reusable Bicep modules and golden-path templates, mentor engineers, and raise the bar in design and code review.

Benefits

  • flexible vacation
  • two company-wide Mental Health Days off
  • access to the Headspace app
  • retirement savings
  • tuition reimbursement
  • employee incentive programs
  • resources for mental, physical, and financial wellbeing
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service