JJobsSonar

DevOps / Platform Engineer (Cloud)

VM.PL Software House · Wrocław, Dolnośląskie, Poland

Remote
About the job About The Project You will join a project delivered for a client from the DACH region that is developing a compliance services platform for telecommunications companies. We are building a greenfield, multi-tenant, cloud-native SaaS platform that will support the processing of data production and preservation orders in accordance with the EU e-Evidence Regulation. The system will process sensitive data related to criminal proceedings, which means that it must meet strict security, data immutability, and EU data residency requirements from day one. Your main responsibility will be to build the project’s entire infrastructure layer from scratch before the development team begins its core work. This will include setting up the Kubernetes cluster, infrastructure as code, Keycloak, secure S3 WORM storage, and CI/CD pipelines with automated security controls. The role will be most intensive during the first four weeks of the project. Once the infrastructure foundations have been established, the allocation will decrease to approximately half-time and will focus on platform maintenance and supporting the development team. Allocation: full-time during the first 4 weeks of the project approximately 0.5 FTE during the following 11 weeks Working model: remote, with the option to work from or occasionally visit the VM.PL office in Wrocław Project start: July/August 2026 Duration: approximately 15 weeks, with the possibility of further cooperation Responsibilities As part of the project, you will be responsible for designing, implementing, and maintaining the entire infrastructure layer and DevOps processes, including: building and configuring a cloud-based Kubernetes environment using OVHcloud or IONOS, including dev, test, staging, and sandbox environments implementing infrastructure as code using Terraform or Pulumi and eliminating manual resource configuration configuring secure S3-compatible storage, including Object Lock and WORM mechanisms implementing and configuring an identity and access management system using Keycloak, including multi-tenant support and application integrations designing and implementing CI/CD pipelines covering build, test, security scanning, and deployment processes integrating SAST and SCA tools and implementing mechanisms that block deployments when critical vulnerabilities are detected configuring a container registry and processes for building and signing container images ensuring secure access to external services, such as AWS Bedrock, in line with project requirements maintaining infrastructure stability and availability, including resource management, scaling, and environment isolation implementing security policies at the network and cluster levels, such as Network Policies managing secrets and configuring tools such as HashiCorp Vault or equivalent cloud-based solutions maintaining and developing CI/CD pipelines and supporting the development team with environments, containerization, and deployment processes monitoring platform performance and costs, including configuring alerts and basic system monitoring Requirements Minimum 4 years of experience in DevOps or Platform Engineering Hands-on experience administering Kubernetes clusters Experience with managed Kubernetes services such as GKE, EKS, OVHcloud Managed Kubernetes, or IONOS Very good knowledge of Terraform or Pulumi Experience designing complete CI/CD pipelines in GitLab CI or GitHub Actions Experience managing S3-compatible storage Knowledge of S3 Object Lock or WORM mechanisms Very good knowledge of Docker, container registries, and multi-stage builds Experience integrating security scanning tools for source code and dependencies Knowledge of at least some of the following tools: Semgrep, CodeQL, SonarQube, Snyk, Trivy, or OWASP Dependency Check Experience configuring Keycloak or another identity provider based on OIDC and OAuth 2.0 Knowledge of secure secrets management practices Experience with HashiCorp Vault, AWS Secrets Manager, or a similar solution Very good English and Polish Independence and readiness to take ownership of the entire infrastructure layer of the project Nice to have Experience with European sovereign cloud providers such as OVHcloud, IONOS, or Hetzner Hands-on knowledge of AWS Bedrock and regional API endpoint configuration Experience with Kubernetes Network Policies Knowledge of Istio, Cilium, or other service mesh solutions Experience working in environments subject to ISO 27001, BSI C5, or similar standards Knowledge of eBPF-based security tools such as Falco or Tetragon Experience with GitOps and tools such as ArgoCD or Flux Knowledge of Prometheus and Grafana German language skills, which may be helpful when communicating with cloud provider support teams What we offer A remote project with occasional visits to our office or the client’s location Clear communication and a flat organizational structure, as well as a close-knit team — we value openness, mutual support, and trust in our projects The opportunity to join future projects and work on interesting and meaningful solutions across different industries, including e-learning, energy, finance, manufacturing, and logistics International teams and clients, allowing you to develop your English or German skills in real project situations Language classes — we provide our project teams with English and German lessons, including classes with native speakers
Ready to apply?Apply now

Similar jobs

Browse all

Cloud Platform Engineer

ASE (Analysis Simulation Engineering) AG · Zurich, Zurich, Switzerland

On-siteEasy apply2w ago

DevOps Engineer

Sundayy · United States

RemoteEasy apply401(k), Medical2w ago