Platform Engineer (Azure)

Ascend AnalyticsBoulder, CO
$85,000 - $115,000Hybrid

About The Position

The Platform Engineer is responsible for the design, build, and day-to-day operation of Ascend Analytics' Azure cloud platform, working in conjunction with the Senior Platform Engineer to support production and development environments for PowerSIMM, PowerVAL, SmartBidder, BatterySIMM, and Market Intelligence. This role sits at the intersection of cloud infrastructure, DevOps, and identity/security administration. An individual in this position will partner closely with Development, Model Support, and client-facing teams to deliver reliable hosted environments, support the ongoing migration of clients from on-premises hosting into Azure, and help maintain the company's security and compliance posture. A successful Platform Engineer should have strong hands-on Azure skills, a habit of automating and documenting everything they build, and the communication skills to work effectively with both technical teams and non-technical stakeholders.

Requirements

  • Bachelor's degree in computer science, Information Technology, or a related field.
  • Azure certifications: AZ-104 or similar intermediate level required.
  • 4+ years in cloud platform, DevOps, or infrastructure engineering, with at least 3 years hands-on in Microsoft Azure.
  • Strong working knowledge of Azure IaaS and PaaS: VMs, App Services, Storage, Key Vault, Container Apps, Azure Batch.
  • Strong working knowledge of Terraform and infrastructure-as-code practices.
  • Demonstrated Azure networking experience: VNet design, VPN gateways, private endpoints, NAT, DNS, and firewall rules.
  • Hands-on Entra ID administration: conditional access, MFA, SSO, app registrations, PIM.
  • Proficiency with PowerShell and KQL for automation and reporting.
  • Experience building CI/CD pipelines in Azure DevOps.
  • Ability to write clear technical documentation and communicate with non-technical stakeholders.
  • Certifications: AZ-104 or any similar intermediate level certificate.

Nice To Haves

  • Experience supporting a SOC 2 Type II audit cycle.
  • Azure Virtual Desktop administration at scale.
  • Bicep infrastructure-as-code experience.
  • Power BI Embedded capacity management.
  • Oracle Database or Autonomous Database on Azure.
  • Background supporting SaaS products in energy, utilities, or another regulated industry.
  • Expert Certifications: AZ-305, AZ-400, or SC-300.

Responsibilities

  • Design, deploy, and maintain Azure resources, including virtual machines, App Services and deployment slots, container apps, batch accounts, storage accounts, file shares, and key vaults.
  • Build and maintain Azure networking, including VNets and subnets, site-to-site and point-to-site VPN, private endpoints, NAT gateways for static IP requirements, and Front Door routing.
  • Develop and maintain infrastructure as code with Terraform, delivered through Azure DevOps pipelines.
  • Configure and manage Azure Virtual Desktop host pools, images, scale plans, auto-shutdown policies, and published applications for analyst and developer workstations.
  • Maintain VM backup, monitoring, and alerting coverage across development and production environments.
  • Build and maintain Azure DevOps pipelines for application build, versioned deployment, and environment promotion, including service connections, self-hosted agents, and federated identity credentials.
  • Support development teams in moving build and test workloads from legacy on-premises environments into Azure.
  • Administer Entra ID, including user and group provisioning, conditional access, MFA, SSO integrations, and app registrations, with automated monitoring of expiring secrets and certificates.
  • Manage Privileged Identity Management role eligibility, access reviews, and approval of elevation requests.
  • Administer role-based access and permissions for client-facing platforms and resolve customer authentication and MFA issues escalated through the IT case queue.
  • Deploy and maintain endpoint security tooling, including Microsoft Defender for Endpoint.
  • Provide evidence, control descriptions, and technical clarification for SOC 2 Type II audits and customer security assessments and advise on audit scope for newly production-hosted systems.
  • Support client onboarding and migration activities, including storage access, VPN connectivity, and third-party integrations.
  • Serve as an escalation point for platform-related incidents affecting internal users and hosted clients.
  • Produce and maintain network diagrams and platform documentation, keep hosting documentation current as environments change, and lead internal cross-training sessions on Azure architecture.
  • Provide weekly status reporting on priorities, progress, and blockers.

Benefits

  • Medical, dental, and vision coverage.
  • Life and disability insurance.
  • Parental leave for growing families.
  • FSA, HSA, and dependent care accounts.
  • 401(k) with 3% non-elective contribution.
  • Flexible PTO to take time when you need it.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service