4 months ago
Responsibilities
- Operate and improve multi-region GKE clusters hosting hundreds of microservices across development, staging, and production environments.
- Manage Kubernetes platform components including Istio, cert-manager, external-dns, RBAC, HPA/KEDA, HashiCorp Vault secret injection, and Helm deployments.
- Develop and maintain Terraform modules for GKE, networking, Cloud SQL, Cloud Storage, Dataproc, Cloud Composer, Vault, and web hosting.
- Maintain Azure DevOps pipelines and shared Terraform templates supporting multi-environment deployments.
- Support Confluent Kafka infrastructure, Connect workers, JDBC source connectors, consumer group health, and Kafka-lag-based autoscaling.
- Manage Redis Enterprise clusters on Kubernetes with operator-managed lifecycle and replication.
- Operate the observability stack across Grafana Cloud, Prometheus, OpenTelemetry, Beyla, and Kubecost.
- Harden cluster security using NetworkPolicies, Pod Security Standards, admission policies, CrowdStrike Falcon, Lacework, kube-bench, and Let’s Encrypt ACME.
- Support Cloud SQL, Dataproc, Cloud Composer, Matillion CDC pipelines, Snowflake, and BigQuery infrastructure.
- Manage Azure DNS, Cloudflare, and GCP Cloud DNS through external-dns, and support Azure APIM and Cloudflare CDN/WAF.
- Troubleshoot deployment failures, resource limits, autoscaling, Kafka consumer lag, and connectivity issues with application teams.
- Contribute to the Backstage Internal Developer Portal and internal CLI tooling for product-engineering self-service.
Requirements
- At least 5 years of cloud or infrastructure engineering experience, including at least 3 years of hands-on GCP experience.
- Strong production experience with GKE, VPC networking, IAM, Cloud SQL, Cloud Storage, and Artifact Registry.
- Advanced Terraform experience covering reusable modules, state management, and multi-environment patterns.
- Production Kubernetes expertise including Helm chart development, RBAC, resource tuning, and large-scale workload troubleshooting.
- Hands-on Istio experience with sidecar injection, mTLS, VirtualServices, AuthorizationPolicies, and traffic management.
- Understanding of CNI fundamentals, including Cilium or Dataplane V2, east-west traffic flows, and network segmentation.
- Experience developing CI/CD pipelines with Azure DevOps YAML or an equivalent platform.
- Hands-on secrets-management experience with HashiCorp Vault and GCP Secret Manager.
- Proficiency in Bash, Python, or Go for production automation and tooling.
- Experience implementing least-privilege IAM, certificate management, and policy-driven security controls.
- Strong communication skills for collaboration across infrastructure and application development teams.
- Experience with Apache Kafka, Confluent Platform, Kafka Connect, consumer group management, and KEDA-based scaling is preferred.
- Experience with Redis Enterprise on Kubernetes and Active-Active replication is preferred.
- Familiarity with Grafana Cloud, OpenTelemetry, GCP data services, OPA/Rego or Kyverno, Azure APIM, Cloudflare, Matillion, Snowflake, Kubecost, or Backstage is preferred.
- Exposure to financial services or mortgage/loan servicing compliance requirements is preferred.
- GCP Professional Cloud Architect or Certified Kubernetes Administrator certification is preferred.
Benefits
- Remote/hybrid workplace options are available.
- Health benefits begin on Day 1.
- Unlimited flexible time off.
- Family planning services.
- Tuition reimbursement.
- Paid family leave.
- 401(k) matching.
- Pet insurance.
- In-person and virtual social experiences.
- Career pathing and Focus Time Fridays.
Tech Stack
Apache AirflowApache KafkaApache SparkBashCloudflareGoGoogle BigQueryGoogle Cloud PlatformHelmIstioKubernetesPostgreSQLPythonRedisSnowflakeTerraform
Categories
About Sagent
Sagent powers servicers to simplify and modernize the homeownership experience for millions of consumers. Our Dara platform increases servicer efficiency, lowers costs, ensures compliance, and increases servicing values throughout market cycles.