Cognizant→
Full Stack Developer at Cognizant in Hybrid - Chennai
Skills
Job Description
Please use the below link to apply for the position - https://forms.cloud.microsoft/r/D3yY12Kvh9?origin=lprLink
Full Stack Engineer - Platform Apps & Developer Experience
Role title: Full Stack Engineer Platform Applications & Developer Experience
Seniority: Senior Full Stack Engineer (hands-on build + operations, automation-first)
Platform: ChocoMake” (internal codename) — governed data mesh platform on Microsoft Fabric with Azure services, platform apps, and IaC automation
1) Context & Mission
ChocoMake is Barry Callebaut’s enterprise data platform, designed to scale analytics, BI, and AI through a governed data mesh. It provisions standardized data product zones (Dev/Test/Prod) for decentralized Data Product Teams and provides shared services, guardrails, automation, monitoring, and a self-service experience through a Global Management Zone. A critical part of this platform is the platform application layer: the portal, documentation site, and supporting APIs/automation that expose platform inventory, onboarding information, environment visibility, and cost transparency. As a Full Stack Engineer, your mission is to build and operate ChocoMake’s platform-facing applications so that platform usage is intuitive, self-service, secure-by-default, and observable.
You’ll work closely with Platform Engineers (IaC/blueprints) and Cloud Engineers (operations/SRE-style) to ensure that platform apps are:
- Secure (identity, least privilege, private networking)
- Reliable (monitoring, incident readiness)
- Automated (CI/CD, IaC-aligned deployment)
- Aligned with platform reality (pulling inventory from Terraform state and Azure resources)
2) What You Will Build & Operate (Core App/UX Scope)
You will support both global shared components and per-platform application components, aligned to the platform’s architectural patterns.
A. ChocoMake Portal (Core Internal Product)
- Full stack development for the ChocoMake Portal, including:
- Frontend UX for platform self-service views and inventory
- Backend APIs supporting portal features
- Data layer design and performance tuning
- Integration pattern: Terraform-state extraction SQL inventory portal views (platform inventory derived from IaC outputs/state).
- Runtime hosting:
- Azure App Service (including containerized deployment patterns)
- Azure SQL Database for portal persistence/inventory views
- Azure Container Registry for application images
B. Documentation Site (Docs-as-Code)
- Build and operate the platform documentation site using:
- MkDocs (docs-as-code)
- Azure Static Web Apps hosting
- CI/CD pipelines that publish documentation reliably and securely
C. APIs, Sidecars, and Automation Services
- Build services/sidecars that:
- Extract or interpret platform metadata (e.g., Terraform outputs/state, environment definitions)
- Populate portal SQL tables and platform inventory views
- Support self-service onboarding workflows and platform status visibility
D. Observability & Cost Transparency Surfaces
- Contribute to “ChocoMake Insights” type experiences by:
- Integrating cost exports / cost reporting outputs into portal views
- Surfacing health/status signals (alerts, dashboards summaries) in a product-friendly way
E. Security & Networking Constraints You Must Respect
- Platforms patterns include:
- Private endpoints, private DNS zones, and disabling public network access via IaC/variables
- Key Vault with private endpoints and secret lifecycle
- Entra ID / RBAC group patterns and least privilege
- Your applications must function correctly in private networking contexts and support secure identity flows.
3) Key Responsibilities
A. Build Product-Grade Platform Applications
- Deliver high-quality frontend and backend features for the ChocoMake Portal.
- Design APIs and services with clean contracts and good performance.
- Implement robust data models and query patterns in Azure SQL DB to support inventory and reporting needs.
B. Operate What You Build (DevOps + SRE Discipline)
- Own production readiness for platform apps:
- Monitoring, alerting, logging, dashboards
- Incident response participation, RCA contributions, and remediation
- Maintain availability and reliability for platform apps across Dev/Test/Prod.
C. Automation-First Delivery (CI/CD)
- Maintain Azure DevOps pipelines for:
- Container build/push (ACR)
- App Service releases (including webhook/continuous deployment patterns where applicable)
- Static Web Apps publication for docs (MkDocs)
- Ensure versioned releases, rollback strategies, and safe config management.
D. Secure-by-Default Engineering
- Implement identity and access patterns aligned with platform standards:
- Entra ID groups and RBAC
- Managed identities where appropriate
- Secrets via Key Vault (never in code/pipelines)
- Ensure compliance with private endpoint/DNS patterns (no “works only on public internet” shortcuts).
E. Platform Alignment and Cross-Team Enablement
- Work with Platform Engineers to ensure the portal reflects the actual IaC truth (inventories, environments, standards).
- Work with Cloud Engineers to align operational monitoring, alerts, and incident handling.
- Create documentation and developer guidance to reduce support load and accelerate adoption.
4) Must-Have Technical Skills (Selection Criteria)
Full Stack Engineering (Senior Level)
- Strong experience delivering modern web applications end-to-end:
- Frontend: React/TypeScript (or equivalent enterprise-grade SPA stack)
- Backend: Node.js/.NET/Java (any is acceptable if you demonstrate strong API engineering)
- API design discipline (REST, auth, pagination, error models, idempotency).
Azure Application Hosting & Cloud Operations
- Hands-on experience with:
- Azure App Service (including containerized deployments)
- Azure Container Registry
- Azure Static Web Apps
- Azure SQL Database
- Comfortable troubleshooting real production issues (latency, connectivity, auth, DNS/private endpoints).
DevOps & Automation
- Azure DevOps pipelines (build/release), Git workflows, PR reviews.
- Container build and deployment pipelines.
- Comfort working in IaC-driven environments (understanding Terraform outputs/state usage even if not a primary Terraform author).
Security Foundations
- Entra ID concepts (app registrations/service principals), RBAC, managed identities.
- Secure secrets management with Key Vault.
- Strong awareness of private networking implications (private endpoints, private DNS).
Observability
- Azure Monitor + Log Analytics fundamentals, structured logging, alert tuning.
5) Strong Advantages (Nice-to-Have)
- Experience building internal developer platforms or self-service portals that integrate with IaC inventories.
- Familiarity with data platform concepts (Fabric workspaces/capacities, OneLake, ADF) to better present platform status and inventory.
- Experience in cost transparency UX (tagging, cost exports, chargeback views).
- Experience building secure apps in “no public endpoint” enterprise environments.
6) Ways of Working & Expectations
- You work in an engineering-first, automation-first culture: PR-based changes, repeatable deployments, clear ownership.
- You care about operability as much as features: if it can’t be monitored and supported, it’s not done.
- You collaborate effectively across platform engineering, cloud operations, and data product teams to keep the platform experience coherent and trustworthy.
7) Deliverables You’ll Be Accountable For (First 6–12 Months)
- Improved ChocoMake Portal capabilities (inventory accuracy, onboarding UX, platform insights).
- Stable CI/CD pipelines for portal, APIs, and docs-as-code.
- Hardened security posture for platform apps (Key Vault, MI, RBAC alignment, private networking).
- Improved observability: dashboards, alerts, and runbooks that reduce MTTR for platform-app incidents.
8) Interview Focus Areas (How We Will Assess Fit)
- System design: design a portal feature that reads platform inventory from IaC outputs/state and serves it reliably.
- Azure operations scenario: diagnose a production issue involving private endpoints/private DNS and App Service connectivity.
- CI/CD: propose a pipeline approach for container build/push + App Service release + rollback.
- Security: identity model choice (service principal vs managed identity), Key Vault integration, least privilege.
- Quality: testing strategy, API error contracts, performance approach for Azure SQL queries.