Route 101 Limited

Principal Cloud Infrastructure Engineer

Bristol BS16 1QG

Key information

Pay
£60,000 - £80,000
Hours
Full-time
Contract
Permanent
Remote working
Hybrid - 2 days remote
Posted date
11 Aug 2026
Closing date
10 Sep 2026

About this role

We are seeking a Principal Cloud Infrastructure Engineer to own and lead Route 101’s infrastructure strategy across AWS, Azure, and on-premise networking solutions, with a strong focus on security, monitoring, resilience, compliance, and operational excellence in a high-growth, high-profile, regulated environment.

This role will act as the senior technical authority for infrastructure design, delivery, governance, and continuous improvement, ensuring that platforms are secure by design, observable, resilient, cost-conscious, and aligned to customer, regulatory, and contractual expectations. The successful candidate will work across delivery, operations, security, architecture, customer-facing teams, and development teams to define infrastructure roadmaps, guide solution design, set platform guardrails, and ensure that monitoring, compliance, recovery, and operational-readiness controls are embedded without taking ownership of application delivery pipelines.

This is an ideal role for someone who combines deep hands-on infrastructure engineering capability with strategic judgement, strong security awareness, stakeholder confidence, and the ability to set direction in an AWS and Azure cloud-first business.

Key Responsibilities

Own and evolve Route 101’s infrastructure strategy across AWS and Azure with some light on-premise networking, ensuring alignment with business priorities, customer commitments, and government-facing delivery expectations

Act as the senior technical authority for secure, resilient, and scalable infrastructure architecture, standards, roadmaps, and platform guardrails across cloud and hybrid estates

Own cloud control-plane governance across AWS and Azure, including landing zones, tenant and account structure, privileged access, logging, policy guardrails, quotas, backup policies, lifecycle management, and recovery procedures

Prioritise security-by-design across infrastructure services, including IAM, encryption, secrets management, least privilege, network segmentation, vulnerability management, secure configuration, and zero-trust principles

Own infrastructure monitoring and operational readiness, including alert catalogues, severity mapping, dashboards, runbooks, SMC, Support and SOC routing, test evidence, customer communication paths, and exception tracking

Maintain infrastructure assurance evidence, including workload inventories, ownership maps, privileged-access evidence, monitoring coverage, backup and restore evidence, compliance exceptions, and audit-ready control documentation

Define and evidence infrastructure resilience controls, including backup policies, restore testing, RTO/RPO assumptions, disaster-recovery rehearsals, rollback paths, and service-continuity evidence

Ensure infrastructure services support compliance obligations and customer assurance requirements, including ISO 27001, Cyber Essentials Plus, CIS Controls, NCSC guidance, cloud well-architected principles, and public-sector security expectations

Lead Infrastructure as Code adoption in a stack including Pulumi, AWS CDK, and GitHub Actions to improve repeatability, governance, and delivery confidence

Partner with development teams on CI/CD and DevOps practices by defining infrastructure guardrails, monitoring standards, compliance evidence, release traceability, and operational-readiness requirements, while application delivery pipelines remain owned by development teams

Provide technical leadership on complex projects, customer engagements, estimations, migrations, service transitions, vendor selection, and senior 3rd/4th line escalation where required

Mentor engineers, raise infrastructure engineering standards, and promote a culture of automation, documentation, security awareness, evidence-led compliance, and continuous improvement