- · Переглядає 1 шукач
- Дистанційна робота
- Повна зайнятість·Стандартний графік: 5/2
Про вакансію
We are looking for an Infrastructure / Platform Engineer to join our team and help us maintain, secure, and continuously improve our self-hosted infrastructure platform.
Our infrastructure consists of approximately 20 Linux and Windows hosts across four environments: PROD, STAG, TEST, and DEV. You will work closely with the current Infrastructure Lead, helping ensure reliable day-to-day operations, strengthen security, and reduce single-person dependency.
A significant part of the role will focus on security and CVE management, infrastructure automation, monitoring, patch management, and operational reliability.
Requirements
- 2+ years of professional experience in Infrastructure / Platform Engineering, DevOps, System Administration, or a similar role;
- Strong Linux administration skills, preferably Debian, with confidence working from the CLI;
- Solid experience with Windows Server administration;
- Hands-on experience with Ansible, including playbooks, roles, and inventories;
- Experience with an Ansible orchestration layer such as Semaphore;
- Practical experience with Docker and container operations, including image lifecycle, registries, networking, and Docker Compose-based stacks;
- Good understanding of networking and security fundamentals, including iptables/UFW, Windows Firewall, WireGuard, reverse proxies, and TLS/certificate management (ACME);
- Experience with database operations, preferably MariaDB/Galera clusters and/or Microsoft SQL Server, including backups, log shipping, maintenance, and patching;
- Experience with monitoring and logging, such as Prometheus, Grafana, Alertmanager, and Loki or similar solutions;
- Strong understanding of Git-based workflows and infrastructure changes managed through version control and pipelines;
- Security-minded approach and understanding of secure production practices;
- English — B2 or higher, with good written and spoken communication skills.
Responsibilities
- Infrastructure Operations: Maintain and support approximately 20 Linux and Windows hosts across PROD, STAG, TEST, and DEV environments;
- Security & CVE Management: Monitor, triage, and remediate vulnerabilities across OS packages, container images, and third-party applications;
- Vulnerability Management: Operate and maintain security tooling, including Harbor/Trivy for container scanning, Renovate for automated dependency updates, and Wazuh SCA/FIM for security and compliance findings;
- Patch Management: Plan and execute patch cycles safely using a test → staging → production approach, including kernel updates, database hosts, and clustered services;
- Infrastructure Automation: Develop and maintain Ansible playbooks, roles, inventories, and automated infrastructure workflows;
- Container Operations: Manage Docker-based infrastructure, including images, registries, networking, and Compose-based services;
- Networking & Security: Maintain firewalls, VPNs, reverse proxies, TLS certificates, and other core networking components;
- Database Operations: Support database infrastructure, including backups, replication/log shipping, maintenance, and patching;
- Monitoring & Logging: Maintain monitoring, alerting, and centralized logging using Prometheus, Grafana, Alertmanager, Loki, or similar tools;
- Documentation & Compliance: Keep infrastructure changes, patching evidence, operational decisions, and runbooks up to date in line with NIS2 and GDPR requirements;
- Reliability & Incident Management: Troubleshoot incidents, identify root causes, improve system reliability, and continuously automate and improve infrastructure processes;
- Cross-functional Collaboration: Work closely with the Infrastructure Lead and other technical specialists to maintain and improve the platform.
Soft skills
- Security-minded: follows the principles of least privilege, safe defaults, and avoids shortcuts in production;
- Structured problem-solving: stays calm under pressure and approaches incidents and technical issues systematically;
- Documentation-first mindset: keeps changes, decisions, runbooks, and handover documentation up to date;
- Proactive communication: works independently while clearly communicating risks, changes, and potential issues;
- Pragmatic approach: prefers proven, maintainable solutions over unnecessary complexity;
- Attention to detail: understands the importance of reliable infrastructure, accurate documentation, and safe production changes;
- Good written communication in English, especially for technical documentation and incident reports.
Would be a plus
- Experience with VMware, VMware Cloud Director, or NSX, or willingness to learn;
- Experience with Azure hybrid services, including Azure Arc, Managed Instance, or Blob Storage for offsite backups;
- Experience with SSO/IAM solutions, such as Authentik, OIDC/SAML, and secrets management;
- Scripting experience with Python and/or PowerShell;
- Familiarity with NIS2/GDPR operational requirements, including incident reporting, audit trails, and data classification;
- Experience with distributed systems and clustered infrastructure.
Availability & on-call
- Willingness to occasionally intervene outside office hours in case of incidents such as failed services, security events, or backup/replication failures;
- This is not a permanent 24/7 rotation, but responsiveness when critical issues occur is expected;
- As the team grows, participation in a shared standby/on-call arrangement is planned so that the out-of-hours workload is distributed across the team.
Our selection process includes
- HR interview;
- Technical interview;
- Interview with the client;
- Final interview with the founders of the company.
We offer
- Monday-Friday working schedule;
- Office / remote / hybrid work format;
- Medical insurance;
- No time trackers or unnecessary bureaucracy;
- Paid days off and sick days;
- Gifts for birthdays and professional holidays;
- The opportunity to test your ideas, lead initiatives, and try new approaches;
- Communication with experienced specialists who are willing to share their knowledge;
- Participation in internal and external events, with opportunities to build and promote your professional brand;
- The opportunity to work with modern infrastructure, security tooling, automation, and cloud/hybrid technologies;
- A role with a strong focus on infrastructure security, reliability, automation, and continuous improvement.
Ключові вимоги і навички
- Англійська — вище середнього, українська — вільно
- Досвід роботи від 1 року.
Схожі вакансії
-
Системний адміністратор мереж, Network Engineer
àбанк, АТ, Дистанційно -
Support Engineer
Ciklum, Дистанційно -
Middle, Senior QA Engineer
Dnipro-M, Дистанційно -
Senior Support Engineer
Ciklum, Дистанційно -
Інженер баз даних
CreditKasa, Дистанційно