logo[мetahunt]
> DOU
senior

DevOps Engineer

Evoverse
format:Remotecompany:Outsource
kubernetesawsgoogle cloudlinuxdockerterraformargocdfluxany one ofargocdhelmgithub actionsci/cdopenid connectdnstlsvpcpostgresqlredisnatsbashpython
cloudflaretailscalegoogle workspacesamlclickhouseterragrunt
englishB2
experience5+ years
domainCloud
> full description

We build and run web platforms for several clients across multiple clouds. Each client gets its own environments, often inside the client’s own cloud account. You will own the infrastructure end to end: provisioning, delivery pipelines, access, security and observability, and you will help turn our setup into a repeatable standard for new clients.

What you will do

• Provision and operate staging and production environments on AWS and GCP, and dev environments and sandboxes on Hetzner and OVH.

• Run container platforms: Kubernetes (EKS, some GKE), ECS/Fargate, Cloud Run and Docker Compose on VMs.

• Keep all infrastructure as code (Terraform / Terragrunt) with reusable modules,

plan/apply in CI.

• Deliver applications through GitOps (Argo CD, Helm) and CI/CD (GitHub Actions, GitLab CI, Cloud Build), including production releases with approvals and rollback.

• Manage secrets, identity and access as code: SSO, SAML, role-based access, least privilege, access to client-owned accounts.

• Protect environments: CDN/WAF at the edge, zero-trust access to non-public services, private connectivity and fixed egress IPs for allowlists.

• Operate data stores and messaging: PostgreSQL, Redis, ClickHouse, NATS (JetStream); migrations, backups, connection pooling.

• Build and maintain monitoring, logging, tracing and alerting; respond to production ncidents (best-effort on-call).

• Support developers: unblock builds and deploys, dev and sandbox environments, localto-cloud workflows.

• Write clear runbooks and documentation so others can repeat and audit your work.

Our stack

• AWS: EKS, ECS/Fargate, EC2, Lambda, ALB/NLB, RDS PostgreSQL + RDS Proxy,

ElastiCache/MemoryDB, S3, CloudFront (+ functions), ECR, Route 53, ACM, SQS/SNS, EventBridge, Cognito, IAM Identity Center, SSM / Secrets Manager, WAF, CloudWatch.

• GCP: Cloud Run, Cloud SQL, Cloud Build, Artifact Registry, Secret Manager, Pub/Sub, GKE, Compute Engine, Cloud Storage, Workload Identity Federation

• Hetzner Cloud and OVH: VMs with Docker Compose for dev environments and

sandboxes

• Cloudflare: DNS, CDN/proxy, WAF, Zero Trust Access, Tunnels, Workers/Pages, R2

• Vercel for some frontends

• Kubernetes: EKS, Karpenter, AWS Load Balancer Controller, external-dns, External Secrets, KEDA, Helm

• IaC: Terraform / OpenTofu, Terragrunt (incl. Stacks), policy checks with OPA / conftest

• GitOps / CI/CD: Argo CD, GitHub Actions (OIDC to AWS and GCP, reusable workflows, hosted and self-hosted runners), GitLab CI, Docker / BuildKit (multi-arch, arm64)

• Secrets: Doppler, AWS SSM / Secrets Manager, GCP Secret Manager

• Data: PostgreSQL, Redis, ClickHouse, Prisma migrations, PgBouncer / RDS Proxy

• Messaging & queues: NATS (JetStream), BullMQ on Redis, AWS SQS/SNS, GCP Pub/Sub

• Observability: Grafana, VictoriaMetrics, VictoriaLogs, Tempo, Prometheus exporters, OpenTelemetry, Sentry, CloudWatch; alerting to chat

• Networking & access: Tailscale (policy as code, app connectors, subnet routers), Nginx / Caddy, Google Workspace (SSO, SAML, groups)

• Applications we run: Node.js (NestJS, Prisma), Next.js, React/Vite, WebSocket

services, pnpm / Turborepo monorepos

Requirements

• 5+ years in DevOps / SRE / platform engineering, 3+ years with production Kubernetes.

• Strong AWS, including multi-account setups and IAM; solid hands-on GCP.

• Comfortable with plain Linux VMs and Docker Compose for dev and sandbox setups (Hetzner, OVH or similar).

• Solid Terraform: modules, remote state, import and refactoring without downtime.

• Hands-on GitOps (Argo CD or Flux) and Helm.

• CI/CD design in GitHub Actions or similar, with keyless (OIDC) access to the clouds.

• Networking: DNS, TLS, load balancers, VPC design, private connectivity.

• Running PostgreSQL, Redis and a message broker (NATS or similar) in production.

• Scripting in Bash and Python.

• You write things down: runbooks, PR descriptions, post-incident notes.

• English B2+.

Nice to have

• Cloudflare (Zero Trust, Tunnels, Workers) and Tailscale.

• Identity and access as code with Google Workspace or another IdP (SAML, group-based access).

• NATS / JetStream operations (clustering, streams, consumers), ClickHouse operations.

• Terragrunt Stacks, OPA / conftest.

• Experience with multi-tenant SaaS or online entertainment platforms.

• Using AI coding assistants in infrastructure work.

What we offer

• Fully remote (Ukraine or CET timezone).

• Real ownership of a multi-cloud platform and its standards.

• Best-effort on-call only, no formal rotation.

Відгукнутись на вакансію