5 months ago
Toronto, CanadaStaff+
Responsibilities
- Lead and mentor a distributed DevOps team, including an infrastructure security-focused sub-team.
- Serve as the primary technical decision-maker for DevOps architecture, tooling, prioritization, and delivery standards.
- Own the self-hosted GitLab platform, including upgrades, runners, platform health, templates, security scans, merge request standards, branch protection, and CODEOWNERS governance.
- Own EKS operations, multi-cloud AWS and GCP infrastructure, cloud governance, cost optimization, and migration from legacy infrastructure.
- Maintain and improve the Terraform infrastructure-as-code estate, including modules, remote state, drift detection, and GitLab CI-driven workflows.
- Drive SSO federation and identity management across VMware vCenter, AWS IAM Identity Center, and Azure AD groups.
- Own vulnerability scanning, secrets management, SBOM/CVE reporting, container scanning, and related security automation.
- Build the internal developer platform vision and lead Grafana-based observability, alerting, and performance monitoring.
- Use DORA metrics and platform health indicators to guide roadmap and delivery improvements.
- Lead AI-enabled DevOps transformation, including AI-assisted code review, pipeline diagnostics, test selection, incident response, runbook generation, coding tools, cost optimization, and AI governance.
Requirements
- 5+ years of progressive DevOps or platform engineering experience, including at least 2 years in a technical lead or staff-level role.
- Deep hands-on experience administering self-hosted GitLab CI/CD, managing runners, and building shared templates and catalogs.
- Production Kubernetes experience, preferably EKS, including upgrades, node management, networking, RBAC, day-2 operations, and reliability engineering.
- Multi-cloud infrastructure experience across AWS and at least one of GCP or Azure, including IAM, Organizations, SSO/IAM Identity Center, VPC networking, EKS, ECR, and cost optimization.
- Strong Terraform experience covering module design, remote state, drift detection, and CI/CD-driven plan/apply pipelines.
- Experience with Azure AD/Microsoft Entra ID, SSO federation, group-based access, and federating VMware vCenter, AWS, or similar platforms with AD/LDAP.
- Experience with vulnerability scanning, secrets management, and SBOM/CVE pipeline integration.
- Fluency in Bash, Python, or a similar scripting language for automation and tooling.
- Strong written and verbal communication skills for design documentation, technical alignment, and leadership communication.
- Demonstrated use of AI tooling in engineering contexts and a clear perspective on practical AI leverage versus hype.
- Preferred experience with Yocto/BitBake, embedded Linux release pipelines, Concourse CI, Cloudflare Zero Trust/WARP/Tunnel, DataHub, Grafana Loki, industrial IoT, edge computing, GitLab at scale, AI-augmented DevOps workflows, MCP, or agentic AI tooling.
Benefits
- CA$145,000–CA$185,000 base salary, plus benefits, equity participation, and a professional development allowance.
- Inclusive workplace with accommodations available throughout the recruitment process.
