16 days ago
Prague, CzechiaSenior
Responsibilities
- Engineer and scale cloud infrastructure supporting hybrid and BYOC delivery across AWS, GCP, and Azure.
- Design and maintain secure cloud networking architectures that connect company systems with customers’ private cloud environments.
- Drive infrastructure, networking, logging, and access-control practices required for FedRAMP, SOC2, and ISO27001 compliance.
- Provision, manage, and version complex infrastructure using Terraform or OpenTofu.
- Build automated delivery pipelines for multi-tenant SaaS, isolated customer VPCs, and disconnected deployments.
- Operate and improve Kubernetes-based, multi-tenant, and multi-cluster environments.
- Implement FinOps practices and architectural improvements to optimize cloud resource utilization and spend.
- Establish reliability practices involving SLAs, SLOs, error budgets, blameless post-mortems, and continuous improvement.
- Embed security practices into delivery pipelines, infrastructure modules, and platform defaults.
- Integrate enterprise identity providers and support SSO, SAML, OIDC, and SCIM in a B2B SaaS environment.
Requirements
- At least 5 years of experience in cloud infrastructure, platform engineering, or SRE as a high-impact individual contributor.
- Expert hands-on knowledge of multiple cloud providers, with primary expertise in AWS; GCP or Azure familiarity is preferred.
- Exceptional understanding of VPCs, Transit Gateways, peering, DNS, ingress and egress patterns, VPNs, and secure distributed cloud networking.
- Experience operating in highly regulated environments and implementing controls for certifications such as FedRAMP Moderate or High, SOC2, and ISO27001.
- Experience designing and deploying software to BYOC, on-premises, air-gapped, and highly secure GovCloud environments.
- Extensive hands-on experience with Terraform or OpenTofu for infrastructure provisioning and versioning.
- Understanding of Platform as a Product and experience building robust automated delivery pipelines.
- Hands-on experience with enterprise identity providers, SSO, SAML, OIDC, and SCIM.
- Production experience with Kubernetes, including EKS, Helm, cluster networking, RBAC, workload security, and multi-tenant or multi-cluster operations.
- Strong command of the OpenTelemetry observability stack and experience designing systems around SLOs, SLIs, and actionable alerting.
Tech Stack
Categories
About Aisle
TL;DR: we turn any marketing activation into an in-store purchase aka we help you PUMP units through the register.
