DevOps Engineer
We are looking for an Infrastructure / Platform Engineer to join our team and help us maintain, secure, and continuously improve our self-hosted infrastructure platform.
Our infrastructure consists of approximately 20 Linux and Windows hosts across four environments: PROD, STAG, TEST, and DEV. You will work closely with the current Infrastructure Lead, helping ensure reliable day-to-day operations, strengthen security, and reduce single-person dependency.
A significant part of the role will focus on security and CVE management, infrastructure automation, monitoring, patch management, and operational reliability.
About project:
An online portal for mobile virtual network operators and providers of TV and internet services, that helps regular and business customers manage mobile numbers and control expenses, to block, resume, change or buy subscriptions, renew contracts, and activate SIM cards.
Requirements
— 2+ years of professional experience in Infrastructure / Platform Engineering, DevOps, System Administration, or a similar role;
— Strong Linux administration skills, preferably Debian, with confidence working from the CLI;
— Solid experience with Windows Server administration;
— Hands-on experience with Ansible, including playbooks, roles, and inventories;
— Experience with an Ansible orchestration layer such as Semaphore;
— Practical experience with Docker and container operations, including image lifecycle, registries, networking, and Docker Compose-based stacks;
— Good understanding of networking and security fundamentals, including iptables/UFW, Windows Firewall, WireGuard, reverse proxies, and TLS/certificate management (ACME);
— Experience with database operations, preferably MariaDB/Galera clusters and/or Microsoft SQL Server, including backups, log shipping, maintenance, and patching;
— Experience with monitoring and logging, such as Prometheus, Grafana, Alertmanager, and Loki or similar solutions;
— Strong understanding of Git-based workflows and infrastructure changes managed through version control and pipelines;
— Security-minded approach and understanding of secure production practices;
— English — B2 or higher, with good written and spoken communication skills.
Responsibilities
— Infrastructure Operations: Maintain and support approximately 20 Linux and Windows hosts across PROD, STAG, TEST, and DEV environments;
— Security & CVE Management: Monitor, triage, and remediate vulnerabilities across OS packages, container images, and third-party applications;
— Vulnerability Management: Operate and maintain security tooling, including Harbor/Trivy for container scanning, Renovate for automated dependency updates, and Wazuh SCA/FIM for security and compliance findings;
— Patch Management: Plan and execute patch cycles safely using a test → staging → production approach, including kernel updates, database hosts, and clustered services;
— Infrastructure Automation: Develop and maintain Ansible playbooks, roles, inventories, and automated infrastructure workflows;
— Container Operations: Manage Docker-based infrastructure, including images, registries, networking, and Compose-based services;
— Networking & Security: Maintain firewalls, VPNs, reverse proxies, TLS certificates, and other core networking components;
— Database Operations: Support database infrastructure, including backups, replication/log shipping, maintenance, and patching;
— Monitoring & Logging: Maintain monitoring, alerting, and centralized logging using Prometheus, Grafana, Alertmanager, Loki, or similar tools;
— Documentation & Compliance: Keep infrastructure changes, patching evidence, operational decisions, and runbooks up to date in line with NIS2 and GDPR requirements;
— Reliability & Incident Management: Troubleshoot incidents, identify root causes, improve system reliability, and continuously automate and improve infrastructure processes;
— Cross-functional Collaboration: Work closely with the Infrastructure Lead and other technical specialists to maintain and improve the platform.
Soft skills
— Security-minded: follows the principles of least privilege, safe defaults, and avoids shortcuts in production;
— Structured problem-solving: stays calm under pressure and approaches incidents and technical issues systematically;
— Documentation-first mindset: keeps changes, decisions, runbooks, and handover documentation up to date;
— Proactive communication: works independently while clearly communicating risks, changes, and potential issues;
— Pragmatic approach: prefers proven, maintainable solutions over unnecessary complexity;
— Attention to detail: understands the importance of reliable infrastructure, accurate documentation, and safe production changes;
Would be a plus
— Experience with VMware, VMware Cloud Director, or NSX, or willingness to learn;
— Experience with Azure hybrid services, including Azure Arc, Managed Instance, or Blob Storage for offsite backups;
— Experience with SSO/IAM solutions, such as Authentik, OIDC/SAML, and secrets management;
— Scripting experience with Python and/or PowerShell;
— Familiarity with NIS2/GDPR operational requirements, including incident reporting, audit trails, and data classification;
— Experience with distributed systems and clustered infrastructure.
Availability & on-call
— Willingness to occasionally intervene outside office hours in case of incidents such as failed services, security events, or backup/replication failures;
— This is not a permanent 24/7 rotation, but responsiveness when critical issues occur is expected;
— As the team grows, participation in a shared standby/on-call arrangement is planned so that the out-of-hours workload is distributed across the team.
Our selection process includes
— HR interview;
— Technical interview;
— Interview with the client;
— Final interview with the founders of the company.
We offer
— Monday—Friday working schedule;
— Office / remote / hybrid work format;
— Medical insurance;
— No time trackers or unnecessary bureaucracy;
— Paid days off and sick days;
— Gifts for birthdays and professional holidays;
— The opportunity to test your ideas, lead initiatives, and try new approaches;
— Communication with experienced specialists who are willing to share their knowledge;
— Participation in internal and external events, with opportunities to build and promote your professional brand;
— The opportunity to work with modern infrastructure, security tooling, automation, and cloud/hybrid technologies;
— A role with a strong focus on infrastructure security, reliability, automation, and continuous improvement.