DevOps Engineer
We’re hiring a Senior DevOps Engineer for SaaS/PaaS products running across varied client infrastructure. The role focuses on stabilizing and automating dev/QA environments, improving CI/CD, and cutting delivery delays from environment issues and manual deploys. You’ll also contribute to company-wide infra practices, security hardening, and compliance readiness.
This is a lead-style, self-managed role across multiple client projects: you own the DevOps direction end-to-end, drive work without waiting for task assignments, and act as the primary infrastructure contact for clients. Hands-on engineering is only part of the job — a significant share of time goes into policing standards, communication, and process organization.
Responsibilities
- Own and evolve GitLab CI/CD pipelines (build/test/package/deploy): runners, artifacts, permissions, governance.
- Own Kubernetes delivery: Helm/manifests, GitOps (FluxCD preferred), release and rollback strategies.
- Stabilize and improve test/staging environments used by devs and QA; reduce env-related delivery delays.
- Troubleshoot complex deployment and environment issues (pipelines, cluster/app config, networking, access).
- Coordinate deployments and access-dependent tasks with client-side engineers when admin access is limited.
- Maintain environment and operational runbooks (deploys, rollbacks, debugging, access) to production-grade standards.
- Drive automation-first delivery: IaC and workflow automation for provisioning, deploys, and ops across projects.
- Contribute to company initiatives: infra standardization, security hardening, secrets management, access controls, logging/monitoring baselines.
- Lead by influence: define DevOps standards, mentor engineers, and be ready to scale DevOps practices and teams.
- Build and support MLOps capabilities for ML/LLM-based services (model serving, pipelines, observability, governance).
- Self-manage the DevOps workstream across multiple projects: plan, prioritize, and drive work without day-to-day task assignments.
- Proactively chase access and setup with client CTOs/sysadmins/IT: accounts, permissions, credentials — and document everything.
- Own client communication on infra topics, including tough conversations: stay professional under pressure; escalate internally when blocked instead of disengaging.
Requirements
- 5+ years in DevOps/SRE/platform engineering with hands-on production delivery.
- Expert-level Kubernetes (deployments, debugging, cluster ops, networking, reliability).
- Strong GitLab CI/CD (pipelines, runners, artifact management, approvals, RBAC/permissions).
- Hands-on Helm and Kubernetes manifests; reusable deployment patterns across envs/customers.
- GitOps (FluxCD preferred) with safe promotion/release processes.
- Strong experience with AWS and/or other major cloud platforms (Azure, GCP); ability to design cloud-agnostic architectures.
- Solid Linux; familiarity with Java service runtime/deployment basics.
- Strong automation and tooling (IaC + workflow automation); repeatable delivery across domains (fintech, healthcare, construction, machinery, legal).
- Hands-on Ansible experience (playbooks, roles, inventories) for configuration management and provisioning.
- Proven infra security hardening (IAM, secrets, least privilege, vuln management, baseline controls).
- Compliance knowledge and hands-on experience with compliant infrastructure:
- SOC 2 controls and audit evidence collection;
- GDPR / CCPA privacy-aligned infrastructure practices;
- HIPAA-aligned safeguards (where applicable);
- Penetration test preparation and remediation.
- Strong ownership and prioritization; works cross-functionally with developers and QA.
- Proven self-management across multiple client projects in parallel: sets priorities, drives delivery, and ships without being chased.
- Strong stakeholder management and soft skills: leads conversations with client CTOs/engineers, handles pushback constructively, stays engaged under pressure.
- Ownership of access/account setup, documentation, and process hygiene — not only hands-on engineering. A “tasks-handed-to-me” or client-avoidant mindset is not a fit.
- Upper-Intermediate or higher English level.
- Flexibility to travel internationally for client meetings, as needed.
Nice to have
- Hands-on MLOps: model serving, training/inference pipelines, experiment tracking, model registry, LLM deployment, monitoring/drift.
- RPM packaging and Linux-based installers.
- Keycloak and OAuth2/SSO operations.
- Mixed integration landscapes (REST/SOAP/Kafka/FTP/RPC).
- Oracle/PostgreSQL/MySQL operationally.
- Track record of passing external audits end-to-end (SOC 2 / ISO-related).
We offer
- Competitive compensation based on your skills, experience, and performance.
- Experienced colleagues with 95% of middle and senior engineers.
- Possibility to work from anywhere in the world.
- Exciting projects involving the newest technologies.
- Flexible working approach.