Platform Engineer

Date: Sep 4, 2026

Location: MADRID, ES, 28037

Company: HOLCIM Group

Platform Engineer

Job Description

1. Objective

Deliver a multi-cloud and edge platform on which Holcim's business products are developed and run, at enterprise quality and startup efficiency.

The measurable outcome is product teams building, deploying and operating independently, on infrastructure that is secure, reliable, compliant and cost-effective.

The role sits within Group IT and delivers through the organisation, not around it: in close collaboration with product teams, corporate security, legal and data privacy, finance, and regional and global IT, and aligned with Holcim policies, standards and legal framework.

2. Scope

Cloud

GCP (primary), AWS

Edge

Industrial plant sites worldwide

Platform estate

~100 platform services across 10 technical domains, ~30 environments

Consumers

~55 business products, 30+ product teams operating in self-service

Platform framework

In-house engineering platform: policy-as-code provisioning across all managed services, self-service interfaces for product teams, safety gates, state verification and immutable audit evidence

Operating model

Architecture principles and reference designs, engineering standards and naming policy, specification and peer-review process, verification and validation records, document taxonomy, master data registries, multi-jurisdiction legal and compliance framework

Team

6 engineers

 

Technical domains: compute, networking, data storage, data pipelines, edge infrastructure, identity and access, security, secrets management, CI/CD, developer tooling, observability, cost engineering, platform framework.

3. Professional Standard

The role is defined for experienced engineers who work to a professional standard focused on results not tasks. These expectations apply at both levels and are assessed during selection and in the annual review.

Results

  • Delivers a predictable volume of work across the year, and holds it under pressure.

  • Measured by outcomes delivered, not activity performed.

  • Reduces the team's total workload through simplification and automation.

  • Unblocks colleagues rather than becoming a dependency.

Quality

  • Work is correct, verifiable and maintainable. Rework is the exception.

  • Non-trivial work is specified in writing and peer-reviewed before implementation.

  • Documented to the standard another engineer needs to operate and extend it.

  • Root causes are fixed in code and configuration. Alerts, workarounds and manual procedures are not permanent solutions.

Customer orientation

  • Product teams are the customer. Their ability to work independently is the measure of whether a service is finished.

  • Understands the business purpose of the work and challenges requests that would not achieve it.

  • Recurring support demand is a design defect to remove, not a workload to absorb.

  • Commits to timeframes and flags slippage before the deadline, not after.

Engineering practice

  • Applies established practice by default: infrastructure as code, policy as code, version control, testing, peer review, least privilege, defence in depth, documented decisions.

  • Keeps current with cloud platform and tooling evolution and brings improvements into the team.

  • Works within the standards framework and improves it. Working around it is not an alternative.

Original thinking

  • Proposes new approaches where existing ones are inadequate, and challenges solutions that no longer fit.

  • Ideas are anchored in the expected result, the real constraints and established practice — not novelty for its own sake.

  • Simplification counts. Removing a system, a step or a dependency is worth as much as adding a capability.

  • Innovation is delivered inside Holcim's standards and policy framework.

Proactive planning

  • Scopes ambiguous requirements, sequences the work, identifies dependencies and risks, and commits to deliverables and dates before starting.

  • Estimates against real available capacity, not optimistic capacity.

  • Raises capacity limits, expiring dependencies, security exposure and architectural risk before they become incidents.

  • Identifies what needs improving and drives it, rather than waiting to be assigned.

Professional maturity

  • Owns outcomes, not tasks. Where resolution depends on another team, drives it to closure there.

  • Communicates facts early and accurately, including when the news is bad.

  • Disagrees with reasoning, then commits to the decision taken.

  • Remains composed and methodical during incidents.

 

None of this is unusual at senior level. It is stated explicitly because the team is small, flat, and has no supervisory layer to compensate when any of it is missing.

4. Key Responsibilities

Platform Framework and Automation

  • Provision and manage cloud and edge infrastructure end to end as code — networking, compute, storage, databases, identity, secrets.

  • Develop and extend the in-house platform framework that provisions, configures and governs every platform service: policy enforcement at authoring time, safety gates and dry-run control ahead of destructive operations, verification of intended against actual state, and immutable audit evidence.

  • Encode standards and procedures as executable controls, so non-compliant configurations cannot be created rather than being detected afterwards.

  • Build and maintain the self-service interfaces through which product teams provision and configure their own resources, without a ticket and without platform-team involvement.

  • Contribute reusable tooling, templates and shared components that other engineers and product teams adopt.

  • Peer-review other engineers' specifications and code.

Architecture

  • Design platform architecture and capacity across cloud and edge.

  • Design network architecture: VPC, DNS, load balancing, NAT, VPN, interconnect, private connectivity, firewall rules.

  • Design identity and access architecture: IAM model, service account governance, access enforcement.

  • Design security architecture: WAF, key management, secrets, endpoint protection, vulnerability management.

  • Evaluate and select cloud services and technologies; maintain the platform technology stack.

  • Produce and maintain architecture documentation and decision records.

Operations

  • Operate the services you design and build, across their full lifecycle.

  • Lead infrastructure incident response: diagnosis, root cause analysis, resolution, post-incident review.

  • Design and maintain monitoring, logging, tracing and alerting across all environments.

  • Plan and execute preventive maintenance, patching, upgrades and security remediation.

  • Manage platform cost: sizing, optimisation, cost reporting per product.

Product Team Enablement

  • Act as technical contact for assigned product teams.

  • Onboard product teams onto platform services and self-service capabilities.

  • Diagnose and resolve platform-side integration issues.

Standards, Governance and Compliance

  • Apply and maintain the engineering standards, procedures and templates that govern all platform work.

  • Produce and maintain architecture documentation, runbooks, playbooks and service documentation.

  • Maintain traceability from ticket to implementation to audit record.

  • Support audit and compliance evidence across GDPR, NIS2, ISO 27001 and local regulatory requirements.

  • Work with corporate security, legal, data privacy and global IT on controls that span organisational boundaries.

5. Additional Responsibilities — Lead Platform Engineer

The Lead level additionally carries the product-facing engineering scope.

Product Architecture and Standards

  • Define product architecture standards, patterns and reference implementations.

  • Review and approve product architecture at the architecture review gate, before development starts.

  • Own the approved technology catalogue for product teams: technologies, versions and configurations supported.

  • Define coding standards, design patterns and CI/CD pipeline patterns used by product teams.

  • Define and validate the resource and access model for each product workload.

Technical Leadership

  • Act as primary technical reference for platform architecture decisions.

  • Set direction for platform operations, performance, security posture and cost.

  • Coach product teams on engineering quality and secure development practice.

  • Mentor engineers through architecture, worked example and peer review.

6. Required Qualifications

  • Planning and foresight. Takes an ambiguous requirement, determines what it actually requires, sequences the work, identifies dependencies and risks, and commits to deliverables and dates before starting. Assessed explicitly during selection.

  • Production software development in Python. Maintained, peer-reviewed modules that other engineers depend on.

  • Production ownership of cloud infrastructure, including accountability for incident response and root cause resolution.

  • Infrastructure and policy as code across the full delivery path — provisioning, configuration, deployment, verification, evidence.

  • Breadth across technical domains. No single-domain specialisation, and no second-line team to escalate to.

  • Written technical communication that product owners, security architects and peer reviewers can act on without rework.

7. Preferred Qualifications

  • GCP at design depth: IAM, networking, data services, security and cost modelling.

  • Network architecture: VPC design, DNS, load balancing, private connectivity, firewalling.

  • Linux and container operations at diagnostic level.

  • CI/CD pipeline design and implementation.

  • AWS, edge computing, or industrial/OT environments.

  • Manufacturing, plant or industrial context.

  • Regulated or multi-jurisdiction environments (GDPR, NIS2, ISO 27001).

  • Terraform, Ansible or equivalent infrastructure-as-code tooling.