Cloud Platform Engineer

Vari — United States · Posted ~21 hours ago

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Description

About the Company Vari, originally known as VariDesk®, started the standing desk revolution. Now in its 13th year, Vari’s mission is to create workspaces that elevate people. With millions of fans and a complete line of over 400 office furniture products in the market today, Vari is continuing to simplify and disrupt the office furniture industry by pioneering a direct B2C and B2B business model, reimagining how workspaces are defined, designed, and delivered. About the Role Vari is building the next generation of its IT function around a small, senior team and a growing portfolio of internally built applications and AI agents — software we expect to keep expanding. We’re hiring a Cloud Platform Engineer to own and grow the cloud infrastructure that portfolio runs on: the compute, networking, data, deployment, and security foundations in Azure that let internal apps and agents ship quickly, run reliably, and scale as we build more of them. This is a build-first role with real operational ownership — you’ll design and ship the platform, and you’ll also be one of the people we trust to approve and safeguard changes to production. You’ll partner with the Director of Technology Operations & Support, the Endpoint & Security Operations lead, and the data engineers and software developers building on the platform. Above all, we want someone who is genuinely AI-native and forward-thinking — quick to reach for AI as a force multiplier, curious about where the technology is heading, and eager to expand what it can do for Vari. Why This Role Exists Vari’s technology footprint is shifting decisively into Azure, and our in-house engineering — the applications and AI agents we build internally — keeps growing. We’re investing in cloud and platform engineering to give that portfolio a solid, scalable home rather than backfilling traditional systems administration. The legacy, on-premises footprint is being deliberately retired; the opportunity is to build the cloud platform those apps and agents depend on — hosting, deployment, observability, and the guardrails that keep a growing fleet secure and reliable — and to help decide how far to take practices like infrastructure-as-code. Responsibilities Own the cloud platform for internal apps and agents — design, build, and operate the Azure foundations our growing portfolio of internally built applications and AI agents runs on: compute (Azure Functions, Container Apps, and container platforms as they’re needed), networking, data services, and the paths that get software to production.Make shipping and scaling routine — establish deployment pipelines, environment and release patterns, and observability so new apps and agents can be built, deployed, and monitored quickly and consistently as the portfolio keeps growing.Design for reliability and scale — plan capacity, performance, and resilience for a fleet of services we expect to expand, so the platform stays healthy as more is built on top of it.Provide sensible guardrails — per-app and per-agent identities with least-privilege access, secrets in Azure Key Vault, structured logging, and lightweight approval and safety controls for automation that changes state.Bring infrastructure-as-code where it’s the right path — help us evaluate and, where it earns its keep, adopt IaC (Bicep or Terraform) and source-controlled configuration to make the estate reproducible and reviewable. This is a space we’re ready to invest in and mature, not one we consider finished.Work AI-natively — use agentic development tooling (for example, Claude Code) as a primary way of building, actively seek out new places AI can remove toil or unlock capability, and design LLM-in-the-loop workflows where agents propose, deterministic code executes, and humans approve. What You'll Own Approve and safeguard change — serve as a primary approver for standard production changes and a second approver for security-, identity-, and network-impacting ones, alongside the Director and the Endpoint & Security Operations lead.Own reliability — join an on-call and escalation rotation with the Director and our external MSP backstop; own root-cause analysis on issues the platform surfaces.Operate the platform — the health of hosted apps and agents, monitoring (Site24x7), patch and update evidence, backup-and-restore verification, and certificate lifecycle — increasingly automated, always evidenced.Partner on security — work with the Endpoint & Security Operations lead on Sentinel operations and cloud security posture, complementing rather than duplicating endpoint and L1 ownership. What You'll Drive Over Time Simplification is part of the mandate: consolidating identity onto Entra ID, modernizing file storage to cloud-native services, and retiring the remaining on-premises servers. We remove work before we automate it — the best outcome is often an entire category of maintenance that no longer exists. Qualifications 5+ years in cloud infrastructure, platform, or DevOps engineering, with deep hands-on Azure.AI-native and forward-thinking — AI and agentic tools (for example, Claude Code) are a natural part of how you build, and you actively look for responsible new ways to apply AI as the technology advances.Hands-on building and operating application hosting on Azure — serverless (Functions) and containers (Container Apps or AKS) — with networking, deployment, and production observability.Establishing CI/CD and, ideally, infrastructure-as-code (Bicep and/or Terraform) — the ability to bring these practices to an environment still maturing in them.Strong command of Entra ID (identity, RBAC, PIM, conditional access), Azure Key Vault, and Azure Monitor / Log Analytics.Automation scripting in Python and/or PowerShell, with the discipline to write maintainable, tested code rather than one-off scripts.Security instincts (least privilege, secrets hygiene, change control, audit trails) and comfort operating with high autonomy on a lean team. Preferred Skills Microsoft 365 tenant administration — Exchange Online, Teams, SharePoint / OneDrive, groups, and licensing.Depth in the Microsoft 365 E5 security stack: Sentinel, Defender, Intune, and Purview.Experience designing and shipping AI or agentic systems in production, with a clear point of view on doing it safely.Networking fundamentals (Ubiquiti / UniFi), DNS (Akamai), and certificate lifecycle (DigiCert / ACME).Decommissioning legacy on-premises infrastructure (Active Directory, file servers) and running cloud migrations.Azure and/or security certifications; experience operating under insurer- or audit-driven change control. What Success Looks Like — First 12 Months Internal apps and agents have a consistent, well-understood path to production — new ones ship faster and run more reliably than they do today, and the platform scales cleanly as the portfolio grows.Sensible guardrails and observability are in place across hosted apps and agents; you’re a trusted approver for production change.A deliberate infrastructure-as-code direction is set and underway, adopted where it earns its keep.Operational knowledge and architecture are no longer concentrated in one person, with measurable simplification progress — identity consolidated toward a single platform, on-premises servers trending to zero. How We Work Deterministic where possible, AI where judgment is needed, human where the stakes are high.Every automation runs as its own least-privileged identity — never a person’s credentials.Small, reviewable changes; everything in source control; autonomy earned by evidence, not granted by optimism. Why Vari: Short-term and long-term incentive plan401k and profit-sharing planOn-site gym, spa-like locker roomEnhanced paternity, maternity, and adoption programsPersonal and volunteer time offTeam building events on and off-siteMentoring and career developmentEducation reimbursementWellness program and insurance premium discountsAt-home work set-up **Visa Sponsorship: At this time, we are unable to provide visa sponsorship, including H-1B sponsorship, for this position. Candidates must be authorized to work in the United States without current or future sponsorship