Provision AWS infrastructure with Terraform and configure Linux hosts in AWS and the external data center with Ansible, so every environment can be rebuilt from code.
Build and run a Kubernetes cluster for shared platform services (observability, Keycloak, HashiCorp Vault, web applications), delivered through GitOps with Argo CD and Helm.
Build and maintain GitLab CI pipelines for infrastructure and platform services.
Integrate corporate SSO through Microsoft Entra ID and keep user and group IDs consistent across all sites and compute pools.
Set up monitoring and alerting across compute pools and platform services with Prometheus and Grafana.
Implement encryption, key management, least-privilege access and audit logging, and support the client's security review.
Requirements
5+ years of experience in DevOps, Platform, or Cloud Engineering, including ownership of production environments.
Strong hands-on experience with AWS (VPC, IAM, EKS, EC2, S3, KMS) and Terraform.
Strong Linux administration skills and Ansible experience.
Production experience with Kubernetes, Helm, and Argo CD.
Experience building CI/CD pipelines with GitLab CI or GitHub Actions.
Experience with Prometheus and Grafana.
Experience with SSO integration (OIDC/SAML) using Keycloak and Microsoft Entra ID.
Experience with HashiCorp Vault for secrets management.