DevOps Engineer
About the role
You will own the security posture of a high-traffic, multi-country consumer platform from the internet edge inward. This is a hands-on engineering role, not an advisory one: detections, guardrails, and access controls all ship as code through the same review-and-deploy path as everything else. Alongside that, you'll pick up day-to-day DevOps work: CI/CD pipelines, infrastructure-as-code, and production deployments.
The scale you'd be working at
Dozens of EKS clusters and roughly 2,600+ nodes. Infrastructure partitioned per country across multiple African markets, each with its own regulatory surface. An in-house SIEM and bunch of security related detections.
If You
Are a self-driven DevOps Engineer with proven experience in large-scale micro-service systems hosted on AWS. Have a deep understanding of cloud architecture, AWS technologies and cloud security best practices. Follow the latest industry trends and are passionate about cloud computing and cybersecurity for large-scale systems
Key Responsibilities
- Platform and Delivery Work in a team of DevOps and DBA professionals.
- Improve existing infrastructure and CI/CD procedure.
- Holistically improve all aspects of our infrastructure: reducing cost, improving build and deployment times, streamlining environment provisioning, lowering load times, and incorporating new techniques and technologies.
- Take ownership of our cloud operations, including multi-account governance which account a resource belongs in, and how accounts reach each other safely.
- Help reconfigure existing architecture to allow rapid deployment to new countries.
Edge & network security: Own the edge protection layer. Own network segmentation and exposure control: what is reachable from the internet, from the VPN, and from inside the cluster. Own DNS and egress control: resolver query logging and DNS firewalling to detect and block command-and-control and data-exfiltration paths.
Detection & response: Own cloud security posture management, plus runtime and host detection. Detection engineering and security monitoring design. Security incident response. Contribute to the team's incident reporting cadence. Identity,
Access & secrets: Drive least-privilege across AWS IAM, SSO permission sets and Kubernetes RBAC Contribute to our zero-trust internal-access program. Own the secrets lifecycle. Vulnerability & compliance: Own vulnerability and patch management. Liaise with external security agencies for annual audits, and run our own internal security sweeps. Treat compliance and audit as engineering work.
Our Stack:
- Application Backend Framework: Spring Boot (Java Config + Embedded Tomcat)
- Frontend Framework: VueJS
- Micro Service Framework: Spring Cloud (Netflix Eureka + Ribbon + Feign)
- Distributed Scheduling: Elastic Job
Apply for this job
*
indicates a required field
