Principal / Staff / Senior Infrastructure Engineer
Summary
Build and secure the cloud infrastructure for a Git-friendly hardware design platform, migrating to Kubernetes and automating CI/CD while ensuring SOC 2 and ISO 27001 compliance.
Help define the future of hardware development by building a collaboration platform for circuit designs, enabling the next generation of smart vehicles, IoT devices, rockets, medical devices, robotics, and much more.
At AllSpice, we're building the agile development framework for hardware designers, including a Git-friendly translation layer and automated CI/CD framework for native circuit designs — think GitHub/GitLab + Copilot for electronics.
Read more about our latest Series A announcement here!
As a Sr./Principal Infrastructure Engineer, you will improve our cloud infrastructure architecture and security operations as we scale up our products and services.
If you are passionate about optimizing infrastructure at scale and have experience in security engineering, this role is for you.
What you'll do
This is a high-impact role that comes with lots of autonomy and requires a self-driven, collaborative person. You will own new server deployments and automation, and should be able to:
Work closely with a customer success manager to manage enterprise deployments and SSO integrations
Work closely with application developers to deploy infrastructure solutions to product problems
Document our security processes and identify opportunities for improvement
Manage the process for security compliance certification (ISO 27001 & SOC 2) and pentesting
Coordinate improvements to architecture and hosting services
Automate new software deployments, data backups, and data recovery
Monitor and improve the performance and availability of our cloud infrastructure
Take part in an on-call rotation and respond to incidents, driving blameless postmortems that prevent recurrence
Example projects
Scale out our infrastructure for zero-downtime software deployments
Identify opportunities to decrease cloud cost and increase performance
Conduct stress-testing for backups and establish disaster recovery processes
Manage process for ISO 27001 and SOC 2 audit
Work with the development team to support CI/CD workflows
detect security flaws, perform penetration testing, and conduct red team exercises
Our stack
Terraform & Docker Swarm for deployment, migrating to Kubernetes (K8s)
AWS for production
Grafana, Loki, and Prometheus for observability
GitHub Actions for CI/CD
Playwright for e2e testing
Gitea application fork
Go [server-side]
Rust back-end parsing layer for ECAD files
PostgreSQL
Expectations
Our ideal candidate has:
[Principal] 8+ years of cloud infrastructure and/or security engineering experience
[Staff] 6+ years of cloud infrastructure and/or security engineering experience
[Senior] 4+ years of cloud infrastructure and/or security engineering experience
Deep hands-on expertise with AWS services (IAM, GuardDuty, AWS WAF, etc.) and Linux administration
Experience managing security compliance programs (SOC 2, ISO 27001) and penetration testing
Strong project management skills with the ability to drive cross-functional initiatives
Comfort with ambiguity and a high degree of autonomy
Can think in terms of the big picture and deliver on the details
Fluency with AI tools — you use them day-to-day to debug, document, and reduce operational toil, and expect this to be a normal part of how the team operates
Bachelor's degree or higher in a technology-related field
Must be a U.S. Citizen or Lawful Permanent Resident (Green Card holder)
(preference, not required) Availability to work out of our flex offices in San Francisco or Boston 1–2 days per week
Relevant skills
You don't need to check every box, but the more of these you bring, the better:
AWS services, particularly security-focused services, such as IAM, GuardDuty, AWS WAF, etc.
Terraform, Ansible and infrastructure-as-code experience
SOC 2 and ISO 27001 process familiarity
Logging aggregation and metrics observability (e.g. Loki, Datadog)
Docker and Kubernetes and/or Helm experience
Distributed systems design and operation, including secure multi-tenant SaaS and self-hosted deployments
SBOM generation and audit
Bash and Python scripting; Go or Rust programming experience (our application back-end and parsing layer)
nginx and alternate reverse-proxy services
Documentation and project management
SSO, OIDC, and LDAP
Data lakes and high-availability services
Benefits
Opportunity to make a large impact
Supportive and smart colleagues
Flexible work
Competitive salary and equity
Health, dental, and vision benefits
Generous PTO
Home office stipend
Relocation package
As published by ashby
Full Name, Email, Resume
- Phone optional
- Why are you interested in this opportunity at AllSpice? written answer
- Are you authorized to work lawfully in the United States? yes / no
- Will you now or at any time in the future require sponsorship for employment visa status (e.g. H1B, OPT)? yes / no