Senior Azure & Microsoft 365 Platform Engineer - London - Hybrid
Licensed sponsor London, England, United Kingdom Full-time Posted 1 hour ago
PBI's flagship products and services, PBI Axiom, PBI Vector, and PBI Stratus, enable alternative asset managers to address their data challenges in analytics, workflow, governance, and security.
We are looking for a Senior Azure & Microsoft 365 Platform Engineer.
The successful candidate will act as the technical owner of the Azure platform, working closely with external development and engineering partners. They will ensure that deployed systems align with the intended architecture, support secure and stable operations, and improve ownership across Identity and Access Management, Disaster Recovery, and Monitoring and Observability.
Main Responsibilities
Essential
You would be part of an international team of people, working on the latest technology and at the forefront of automation and innovation. We offer:
We are looking for a Senior Azure & Microsoft 365 Platform Engineer.
The successful candidate will act as the technical owner of the Azure platform, working closely with external development and engineering partners. They will ensure that deployed systems align with the intended architecture, support secure and stable operations, and improve ownership across Identity and Access Management, Disaster Recovery, and Monitoring and Observability.
Main Responsibilities
- Oversee Azure subscriptions, landing zones, networking, compute, databases and Microsoft 365 tenant configuration, including dependencies between current and legacy platforms
- Validate deployed infrastructure against documented architecture and security requirements, including ingress, DNS, certificates and platform access controls
- Review Entra ID, Conditional Access, authentication flows, RBAC, PIM, emergency access, service identities and guest/B2B and client-facing identities. Ensure least-privilege access, effective joiner/mover/leaver processes, recurring access reviews and removal of orphaned identities
- Reconcile permissions and access dependencies across Microsoft 365, Azure, Azure DevOps and applications; oversee Key Vault, secrets, certificates and rotation
- Assess and improve disaster recovery, including recovery units, shared dependencies, RTOs/RPOs, backups, database replication, point-in-time restoration and multi-region design. Run restore and failover exercises covering invocation, validation and return to primary, maintaining runbooks, responsibilities and test evidence
- Improve service-health monitoring using Azure Monitor, Log Analytics, KQL and Application Insights. Map services to monitoring signals, tune alerts for actionability, routing and ownership, and distinguish customer-facing status from operational diagnostics
- Troubleshoot production issues across infrastructure, applications, APIs and integrations, maintaining practical runbooks and technical documentation
- Maintain Terraform configurations, modules and state; detect configuration drift, support Azure DevOps pipelines and permissions, and develop PowerShell scripts and automation
- Apply Azure Policy and landing-zone guardrails, maintain tagging, naming and subscription standards, and improve cost management, including telemetry retention and access
- Act as the internal technical counterpart to external providers, constructively challenge proposed changes and communicate gaps, risks and recommendations clearly to technical and non-technical stakeholders
Essential
- Strong hands-on experience with both Microsoft Azure and Microsoft 365, including Azure platform engineering, Microsoft 365 tenant administration and security configuration, Active Directory servers, and email security/spam filtering (Mimecast)
- Experience spanning cloud architecture, engineering and operations in business-critical production environments
- Strong knowledge of Entra ID, Conditional Access, Azure RBAC, PIM, Key Vault and identity and access governance across connected platforms
- Practical knowledge of Azure networking, ingress, compute and databases, including backup, replication and restoration
- Experience assessing and validating disaster recovery, including dependency mapping, RTOs/RPOs, recovery procedures, restore testing and regional failover
- Experience with Azure Monitor, Log Analytics, KQL and Application Insights, including service-health monitoring, alert tuning and troubleshooting distributed, API-driven services
- Practical Terraform experience covering modules, state management and drift detection, alongside Azure DevOps CI/CD, access controls, PowerShell scripting and Azure Policy
- Strong technical documentation and runbook-development skills, with the ability to distinguish verified findings from assumptions and recommendations
- Ability to work independently, exercise sound technical judgement, collaborate with and challenge external providers, and communicate clearly with technical and non-technical stakeholders
- Familiarity with Bicep or ARM templates and cloud cost optimisation / FinOps
- Experience supporting security audits
- Familiarity with AI tools and their practical application in Microsoft 365 or IT operations
- Experience working with multiple external technology suppliers
You would be part of an international team of people, working on the latest technology and at the forefront of automation and innovation. We offer:
- Flexible working - hybrid mode
- Working on exciting cutting-edge technology projects
- Competitive salary
- Medical insurance package
- Generous paid time off
- Professional development and training
- Professional certification exams sponsored by the company