Senior Cloud Engineer (Azure)
Summary
Senior Cloud Engineer owning Azure Kubernetes Service (AKS) for Cazoo's UK online used car marketplace, leading VM-to-container migration, designing Azure hub-and-spoke networks, and building IaC with Terraform/Helm/Azure DevOps while driving observability and cost efficiency.
What is Cazoo? 😊
Cazoo is an online used car marketplace, built around a simple ambition: to reclaim consumer trust in the used car market. We believe the system is broken for buyers and dealers, with many people having come to accept anxiety, confusion, and stress when searching for a used car.
The first step is to reclaim consumer trust, which is why we’ve built our new brand platform around complete transparency. We’ve not fixed the market yet. But we’re committed to building, step by step, a platform with nothing to hide.
Cazoo was founded in 2018 as an online car retailer, but we've changed quite a bit since then!
Cazoo was acquired by Motors.co.uk in June 2024, and rather than remaining a direct-to-consumer retailer, the brand was relaunched as an online used car marketplace connecting used car dealers with buyers across the UK! An app went live in July 2024 and in 2025 we became the lead sponsors of Brentford Football Club!
About the role:
Cazoo is looking for a Senior Cloud Engineer to take ownership of Azure Kubernetes Service
(AKS) and help shape the next phase of our cloud journey.
You’ll be a hands-on technical leader, setting the direction for AKS while working closely with our
Cloud team and cross-functional engineering teams. You’ll improve the resilience, scalability and
developer experience of our high-traffic platform, establish strong engineering standards and turn
our cloud strategy into working technology.
This is an opportunity to own a critical part of Cazoo’s platform: making decisive technical
improvements, solving complex challenges and helping the engineers around you do their best
work.
Main responsibilities:
This is not a keep-the-lights-on role. You’ll take technical ownership of AKS and the Azure
network beneath it, helping us move decisively from a VM-heavy estate to a modern, secure and
scalable platform.
You’ll have the authority to set direction, make pragmatic engineering decisions and deliver
improvements, not simply recommend them.
What you’ll be doing:
● Own the design, operation and evolution of our AKS platform, making it secure, resilient,
observable and straightforward for engineers to use.
● Lead the migration of business-critical workloads from Azure VMs to AKS and modern
Azure services, deciding what moves, what changes and what should remain where it is.
● Design and build sophisticated Azure networks using technologies such as Hub-and-
Spoke, Virtual WAN, private connectivity and hybrid networking.
● Own our network security and segmentation across firewalls, NSGs, private endpoints
and Zero Trust controls.
● Diagnose difficult problems: cluster instability, unreliable connectivity, routing failures,
application performance, capacity constraints and anything else that crosses the
boundaries between infrastructure, networking and software.
● Build reusable infrastructure with Terraform and Helm, improving how quickly and safely
teams can provision and deploy services.
● Raise the operational standard of the platform through better monitoring, alerting,
capacity planning, performance tuning and incident response.
Keep the parts of our VM estate that still matter reliable and secure while creating a
sensible path away from them.
● Work directly with engineering teams to improve architecture, deployment patterns and
operational readiness.
● Make pragmatic trade-offs between speed, reliability, cost and technical debt, then take
responsibility for the outcome.
● Improve cloud efficiency and cost visibility, making sure we spend money where it
creates genuine value.
● Share what you know, challenge weak assumptions and help establish strong cloud,
Kubernetes and networking practices across engineering.
● Join the cloud on-call rotation and help us remove recurring problems that generate
avoidable incidents.
What you’ll bring:
We’re looking for someone who has built, evolved and owned production cloud platforms, not
someone who has simply operated an existing platform or whose experience ends at the
architecture diagram.
You’ll need:
● Deep, hands-on experience with Microsoft Azure and Azure Kubernetes Service.
● Strong networking expertise, including routing, DNS, load balancing, firewalls, VPNs,
hybrid connectivity and Hub-and-Spoke architectures.
● A track record of taking meaningful ownership of production Kubernetes platforms.
● Experience migrating business-critical workloads from VMs or legacy infrastructure to
containers and managed cloud services.
● Strong Terraform skills and a clear view of what good infrastructure-as-code looks like.
● Practical experience with Helm, CI/CD and Azure DevOps.
● A solid understanding of Azure identity and security, including Entra ID, RBAC, managed
identities and Key Vault.
● Experience building useful observability with tools such as Azure Monitor, Application
Insights, Prometheus and Grafana.
● Knowledge of Azure traffic and networking services such as Application Gateway and
Front Door.
● The judgement to balance engineering ambition with business reality, and the confidence
to make decisions when there is no perfect answer.
...and of course, your benefits:
- 20 fully paid business days of vacation
- 15 fully paid sick leaves
- 11+ fully paid public holidays
- compensation for health insurance and sport club membership
- ability to work from home or remotely
- flexible working hours without time trackers 😊