Senior DevOps Engineer (KLI-77)
- Manage and continuously improve the Terraform monorepo and module library to keep seven environments consistent and drift-free.
- Maintain and optimize GitLab CI/CD pipelines including buildah image builds, security scanning (Trivy/DeepSource), promotion and deployment across environments.
- Operate and optimize AWS services such as ECS (Fargate), Aurora Postgres, MSK Kafka, Redis, S3, IAM, and KMS with a focus on reliability, right-sizing, and cost efficiency (FinOps).
- Run Kafka operational tasks including topic and dead-letter queue design, consumer-group health monitoring, and message replay/reprocessing.
- Support and manage application database schema migrations using Prisma and Liquibase during safe deployments.
- Own secrets management, secrets rotation, TLS/mTLS client certificates, and set up egress/IP whitelisting for external partners' connections.
- Administer Keycloak realms, OAuth2 clients, secrets, and service-to-service authentication.
- Build and maintain observability platforms utilizing Graylog, Prometheus/Grafana, CloudWatch, OpenSearch, and OpenTelemetry; lead incident response and root cause analysis across full request paths (app to vendor).
Responsibilities
- Manage and continuously improve the Terraform monorepo and module library to keep seven environments consistent and drift‑free.
- Maintain and optimize GitLab CI/CD pipelines including buildah image builds, security scanning (Trivy/DeepSource), promotion and deployment across environments.
- Operate and optimize AWS services such as ECS (Fargate), Aurora Postgres, MSK Kafka, Redis, S3, IAM, and KMS with a focus on reliability, right-sizing, and cost efficiency (FinOps).
- Run Kafka operational tasks including topic and dead‑letter queue design, consumer‑group health monitoring, and message replay/reprocessing.
- Support and manage application database schema migrations using Prisma and Liquibase during safe deployments.
- Own secrets management, secrets rotation, TLS/mTLS client certificates, and set up egress/IP whitelisting for external partners' connections.
- Administer Keycloak realms, OAuth2 clients, secrets, and service‑to‑service authentication.
- Build and maintain observability platforms utilizing Graylog, Prometheus/Grafana, CloudWatch, OpenSearch, and OpenTelemetry; lead incident response and root cause analysis across full request paths (app to vendor).
Qualifications
- 5+ years of DevOps, Site Reliability Engineering (SRE), or Platform Engineering experience with senior‑level ownership of infrastructure and pipelines.
- Deep practical AWS experience, especially ECS (Fargate), including task and service definitions, load balancer integration, auto‑scaling, and capacity providers.
- Expertise in Terraform including module development, multi‑environment structuring, remote state management, and safe plan/apply workflows.
- Strong background in CI/CD with hands‑on experience in GitLab CI pipelines, container image builds using Docker or Buildah, and private registry management.
- Solid knowledge of AWS data services and messaging systems, e.g., Aurora PostgreSQL, Kafka (MSK or self‑managed), Redis, and S3 buckets.