HYS Enterprise

Infrastructure, Platform Engineer

  • Дистанційна робота
  • Повна зайнятість·Стандартний графік: 5/2

Про вакансію

We are looking for an Infrastructure / Platform Engineer to join our team and help us maintain, secure, and continuously improve our self-hosted infrastructure platform.

Our infrastructure consists of approximately 20 Linux and Windows hosts across four environments: PROD, STAG, TEST, and DEV. You will work closely with the current Infrastructure Lead, helping ensure reliable day-to-day operations, strengthen security, and reduce single-person dependency.

A significant part of the role will focus on security and CVE management, infrastructure automation, monitoring, patch management, and operational reliability.

Requirements

  • 2+ years of professional experience in Infrastructure / Platform Engineering, DevOps, System Administration, or a similar role;
  • Strong Linux administration skills, preferably Debian, with confidence working from the CLI;
  • Solid experience with Windows Server administration;
  • Hands-on experience with Ansible, including playbooks, roles, and inventories;
  • Experience with an Ansible orchestration layer such as Semaphore;
  • Practical experience with Docker and container operations, including image lifecycle, registries, networking, and Docker Compose-based stacks;
  • Good understanding of networking and security fundamentals, including iptables/UFW, Windows Firewall, WireGuard, reverse proxies, and TLS/certificate management (ACME);
  • Experience with database operations, preferably MariaDB/Galera clusters and/or Microsoft SQL Server, including backups, log shipping, maintenance, and patching;
  • Experience with monitoring and logging, such as Prometheus, Grafana, Alertmanager, and Loki or similar solutions;
  • Strong understanding of Git-based workflows and infrastructure changes managed through version control and pipelines;
  • Security-minded approach and understanding of secure production practices;
  • English — B2 or higher, with good written and spoken communication skills.

Responsibilities

  • Infrastructure Operations: Maintain and support approximately 20 Linux and Windows hosts across PROD, STAG, TEST, and DEV environments;
  • Security & CVE Management: Monitor, triage, and remediate vulnerabilities across OS packages, container images, and third-party applications;
  • Vulnerability Management: Operate and maintain security tooling, including Harbor/Trivy for container scanning, Renovate for automated dependency updates, and Wazuh SCA/FIM for security and compliance findings;
  • Patch Management: Plan and execute patch cycles safely using a test → staging → production approach, including kernel updates, database hosts, and clustered services;
  • Infrastructure Automation: Develop and maintain Ansible playbooks, roles, inventories, and automated infrastructure workflows;
  • Container Operations: Manage Docker-based infrastructure, including images, registries, networking, and Compose-based services;
  • Networking & Security: Maintain firewalls, VPNs, reverse proxies, TLS certificates, and other core networking components;
  • Database Operations: Support database infrastructure, including backups, replication/log shipping, maintenance, and patching;
  • Monitoring & Logging: Maintain monitoring, alerting, and centralized logging using Prometheus, Grafana, Alertmanager, Loki, or similar tools;
  • Documentation & Compliance: Keep infrastructure changes, patching evidence, operational decisions, and runbooks up to date in line with NIS2 and GDPR requirements;
  • Reliability & Incident Management: Troubleshoot incidents, identify root causes, improve system reliability, and continuously automate and improve infrastructure processes;
  • Cross-functional Collaboration: Work closely with the Infrastructure Lead and other technical specialists to maintain and improve the platform.

Soft skills

  • Security-minded: follows the principles of least privilege, safe defaults, and avoids shortcuts in production;
  • Structured problem-solving: stays calm under pressure and approaches incidents and technical issues systematically;
  • Documentation-first mindset: keeps changes, decisions, runbooks, and handover documentation up to date;
  • Proactive communication: works independently while clearly communicating risks, changes, and potential issues;
  • Pragmatic approach: prefers proven, maintainable solutions over unnecessary complexity;
  • Attention to detail: understands the importance of reliable infrastructure, accurate documentation, and safe production changes;
  • Good written communication in English, especially for technical documentation and incident reports.

Would be a plus

  • Experience with VMware, VMware Cloud Director, or NSX, or willingness to learn;
  • Experience with Azure hybrid services, including Azure Arc, Managed Instance, or Blob Storage for offsite backups;
  • Experience with SSO/IAM solutions, such as Authentik, OIDC/SAML, and secrets management;
  • Scripting experience with Python and/or PowerShell;
  • Familiarity with NIS2/GDPR operational requirements, including incident reporting, audit trails, and data classification;
  • Experience with distributed systems and clustered infrastructure.

Availability & on-call

  • Willingness to occasionally intervene outside office hours in case of incidents such as failed services, security events, or backup/replication failures;
  • This is not a permanent 24/7 rotation, but responsiveness when critical issues occur is expected;
  • As the team grows, participation in a shared standby/on-call arrangement is planned so that the out-of-hours workload is distributed across the team.

Our selection process includes

  • HR interview;
  • Technical interview;
  • Interview with the client;
  • Final interview with the founders of the company.

We offer

  • Monday-Friday working schedule;
  • Office / remote / hybrid work format;
  • Medical insurance;
  • No time trackers or unnecessary bureaucracy;
  • Paid days off and sick days;
  • Gifts for birthdays and professional holidays;
  • The opportunity to test your ideas, lead initiatives, and try new approaches;
  • Communication with experienced specialists who are willing to share their knowledge;
  • Participation in internal and external events, with opportunities to build and promote your professional brand;
  • The opportunity to work with modern infrastructure, security tooling, automation, and cloud/hybrid technologies;
  • A role with a strong focus on infrastructure security, reliability, automation, and continuous improvement.

Ключові вимоги і навички

  • Англійська — вище середнього, українська — вільно
  • Досвід роботи від 1 року.
HYS Enterprise

Схожі вакансії

Усі схожі вакансії

Вакансії в категорії

Вакансії за містами

Вакансії за сферою діяльності