20 Aug
|
BlackRockIndia IT Solutions
|
Hyderabad
20 Aug
BlackRockIndia IT Solutions
Hyderabad
Role Summary
We're looking for a Systems Engineer to own the Linux, AWS, and network infrastructure that our delivery pipelines run on. You'll build and maintain CI/CD automation, manage secure site-to-site and client VPN connectivity, and keep multi-account AWS environments performant, cost-efficient, and compliant. This is a hands-on role for someone who is equally comfortable debugging an IPsec tunnel, tuning a build pipeline, and tracing a kernel-level performance issue.
Key Responsibilities
CI/CD & Automation
- Design, build, and maintain CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins, or AWS CodePipeline) covering build, test, artifact management, and deployment
- Implement blue/green and canary deployment strategies with automated rollback
- Manage container build and release workflows using Docker and ECR; deploy to ECS or EKS
- Codify infrastructure with Terraform and configuration with Ansible; enforce peer review and state management practices
- Integrate security and quality gates into pipelines — SAST/DAST, dependency scanning, image scanning, secrets detection
- Manage secrets and credentials via AWS Secrets Manager, Parameter Store, or HashiCorp Vault
Linux Systems
- Administer production RHEL/Amazon Linux/Ubuntu fleets: provisioning, patching, hardening, and lifecycle management
- Troubleshoot performance at the OS level — CPU, memory, I/O, filesystem, and network stack analysis
- Apply CIS benchmarks and security baselines; remediate findings from vulnerability scans
- Write and maintain automation in Bash and Python; manage systemd services, cron/timers, and log rotation
- Configure and tune services such as nginx, HAProxy, and application runtimes
Networking & VPN
- Design and operate AWS VPC architecture: subnets, route tables,
NAT gateways, security groups, NACLs, VPC peering, Transit Gateway, and PrivateLink
- Build and troubleshoot Site-to-Site VPN and AWS Client VPN — IKEv1/IKEv2 negotiation, phase 1/phase 2 mismatches, DPD, and tunnel flapping
- Configure and troubleshoot BGP route propagation, ASN configuration, and route priority over VPN and Direct Connect
- Manage DNS across Route 53 (public, private hosted zones, resolver endpoints and forwarding rules)
- Diagnose connectivity issues using tcpdump, VPC Flow Logs, Reachability Analyzer, traceroute, and packet capture
- Implement TLS/certificate management via ACM and internal PKI
AWS Platform
- Operate multi-account, multi-region environments with AWS Organizations, SCPs, and centralized logging
- Manage IAM roles, policies, and federation following least-privilege principles
- Build monitoring and alerting with CloudWatch, and centralize logs and metrics (ELK, Grafana, Datadog, or Prometheus)
- Own backup, snapshot, and disaster recovery strategy; define and validate RPO/RTO through restore testing
- Drive cost optimization: rightsizing, Savings Plans, storage tiering, and orphaned-resource cleanup
- Participate in on-call rotation, incident response, and root cause analysis
Required Qualifications
- 4+ years in a systems, infrastructure, DevOps, or SRE role
- Deep Linux administration experience in production environments
- Robust AWS experience across EC2, VPC, S3, IAM, RDS, CloudWatch, and Route 53
- Proven ownership of CI/CD pipelines from commit to production
- Hands-on VPN and network troubleshooting — able to read tunnel logs and isolate a fault without escalating
- Proficiency in Bash and Python
Pay: ₹200,000.00 - ₹600,000.00 per year
Work Location: In person
📌 Systems Engineer (Hyderabad)
🏢 BlackRockIndia IT Solutions
📍 Hyderabad