Sr. Azure Cloud Platform Engineer – AKS, JBoss EAP, PostgreSQL
Astra North Infoteck Inc.
- Toronto, ON
- Permanent
- Temps-plein
Experience: 6 - 8 yearsRole DescriptionAzure Kubernetes Service (AKS) Infrastructure / Cluster Management:Architect and manage secure AKS clusters, including upgrades, node scaling, and networking configurations (VNet integration, Azure CNI).Deployment Automation:Design and maintain Helm charts to deploy the vendor’s JBoss-based application. Manage separate Dev, QA, and Prod environments using Helm values and versioning.Ingress & Networking:Configure Azure Application Gateway (AGIC) or NGINX ingress controllers to securely expose AML services, including management of WAF policies to mitigate web vulnerabilities.Application Runtimes (JBoss / Java)JBoss Administration:Tune JBoss EAP configuration for containerized deployments. Optimize heap size, garbage collection, and thread pools for high-throughput transaction workloads.Observability:Implement monitoring via Azure Monitor and Prometheus/Grafana to track JVM metrics (heap usage, active threads) and pod health.Database Management (PostgreSQL)Database Deployment:Manage PostgreSQL instances (Azure DB for PostgreSQL or HA clusters such as Patroni / Crunchy Data).Performance Tuning:Optimize database performance including PgBouncer connection pooling, vacuum tuning, and query analysis for large AML datasets.Resiliency:Design and test Backup/Restore and Disaster Recovery strategies to ensure zero data loss.Security & ComplianceSecrets Management:Replace hardcoded credentials by integrating Azure Key Vault with AKS (CSI drivers, Workload Identity) to secure JBoss data sources and DB passwords.Network Security:Implement strict Network Policies to isolate AML workloads and restrict pod-to-pod communication.Compliance:Ensure adherence to banking regulatory requirements including encryption at rest/transit, RBAC, and audit logging.Technical Stack
- JBOSS EAP
- Azure Kubernetes Service (AKS)
- Helm
- Postgres
- Experience supporting AML platforms such as Name Screening, Actimize, Watchlist Management, etc.
- Knowledge of Azure Service Bus or Kafka for message handling
- Scripting proficiency in Bash or Python for automation
- Experience working with vendors on Kubernetes containerized delivery models
- Excellent communication and negotiation skills
- Deep middleware knowledge of JBoss EAP, including data source configuration, JMS queue setup, and JVM tuning
- Experience handling new data sources for transformation/mapping
- Knowledge of storage technologies (Azure Managed Disks, NetApp NFS)
- Experience with PV-Blob, file disk (TD storage patterns)
- JBOSS EAP
- Azure Kubernetes Service (AKS)
- Helm
- Postgres
- Digital: Kubernetes
- JBOSS Application Server