DevOps Engineers (AIOps) - API and Kubernetes
Summary
Own and maintain Azure infrastructure using Terraform/Bicep, AKS clusters, and CI/CD pipelines; implement AIOps monitoring, security policies, and disaster recovery for AI-driven products.
Infrastructure as code
Own and maintain all AWA Azure infrastructure in Terraform Bicep AKS 5-namespace cluster ADLS Gen2 accounts with WORM policies Azure AI Foundry APIM configurations Azure Firewall allowlists private endpoints Key Vault Container Registry ExpressRoute peering CI CD pipeline ownership Design and maintain Azure DevOps pipelines for all AWA components container image build ACR push Notary v2 signing AKS deployment Terraform plan policy check apply Agent Regression Testing gate on every PR AKS operations Manage the 5-namespace AKS cluster namespace isolation Network Policies Pod Disruption Budgets KEDA autoscaling rules based on Kafka consumer lag OPA Gatekeeper admission policies Workload Identity bindings for all agent pods Container governance Manage ACR enforce Notary v2 image signing configure vulnerability scanning maintain the approved-image ConfigMap used by OPA Gatekeeper admission control Secret and certificate management Own Azure Key Vault configuration access policies per managed identity automatic TLS certificate rotation secret rotation schedules audit of all secret access events Monitoring and alerting Configure Azure Monitor alert rules and Log Analytics KQL queries for SLA breach error rate spike pod crash loop token budget breach and Kafka consumer lag maintain PagerDuty escalation paths Security posture Work with the AI Security Engineer to implement Azure Policy assignments Defender for Cloud recommendations Firewall rule reviews and Private Endpoint configurations maintain the AWA network topology diagram Disaster recovery Maintain and test DR procedures failover to UAE South replica for ADLS Gen2 Azure AI Foundry PTU PAYG DR endpoint routing Orkes cluster recovery RTO RPO validation
Technical — Essential
5+ years DevOps/Platform Engineering; 2+ years on AzureTerraform or Bicep — production IaC, not just templatesKubernetes / AKS: namespaces, RBAC, Network Policies, Helm charts, KustomizeAzure DevOps or GitHub Actions — multi-stage pipelines, approvals, environmentsAzure Monitor, Log Analytics, KQL query languageContainer ecosystem: Docker, ACR, image signing, admission controlAzure networking: VNet, private endpoints, NSGs, Azure Firewall, ExpressRoute conceptsKEDA (Kubernetes Event-Driven Autoscaling) or equivalent autoscaling experience
Technical — Advantageous
Azure Key Vault, managed identity, Workload Identity for KubernetesOPA Gatekeeper or Kyverno for Kubernetes policy enforcementKafka / Azure Event Hubs — consumer group management, lag monitoringADLS Gen2, WORM immutable storage, lifecycle management policiesAzure AI Foundry / APIM — token quotas, rate limiting, backend routing configurationSecurity tooling: Defender for Cloud, Sentinel, Notary v2SkillsTerraformKubernetesAzure DevOps