27 Aug
|
Pump Academy
|
Bengaluru
27 Aug
Pump Academy
Bengaluru
About the Role iPUMPNET is migrating to a cloud-native SaaS architecture while scaling its core IT systems, hybrid environments, and enterprise infrastructure. We are seeking a Cloud Infrastructure, Systems & DevOps Engineer who combines hands-on cloud platform engineering expertise, deep systems administration experience, and strong DevOps engineering capability across CI/CD, automation, and observability.
This role spans four operational domains: cloud-native SaaS infrastructure engineering (primary mandate), DevOps engineering CI/CD pipelines, automation, and observability (co-primary mandate), enterprise IT systems administration supporting PAPL's internal team (secondary mandate), and field site IT support for iPUMPNET's live utility deployments at customer sites (tertiary mandate). Candidates must bring genuine depth across all four operational domains - cloud, systems administration, DevOps, and field site operations. This is not a role for a systems administrator who has touched CI/CD tools it requires a proven DevOps practitioner who is equally strong on cloud and infrastructure.
In this unified role, you will design, secure, operate, and maintain both our public cloud environments (AWS & Azure) and our enterprise systems infrastructureincluding Microsoft 365 administration, directory services, server environments, and adherence to PAPL's ISO 27001:2022 information security standards. You will serve as the technical backbone ensuring high availability, robust security posture, cost optimization, and seamless operational continuity across cloud platforms, enterprise IT, and IIoT edge infrastructure.
This is a hands-on senior technical role requiring strong proficiency across cloud-native tooling, DevOps engineering, cloud/hybrid system administration, enterprise governance, and security controls.
Key Responsibilities
1. Unified Cloud & Systems Administration (AWS, Azure & Windows/Linux)
- Cloud Platform Operations: Design, provision, monitor, and administer cloud resources across AWS and Azure, covering compute (EC2, Azure VMs), container environments (ECS, AKS, EKS), storage (S3, Azure Blob), and networking (VPCs, subnets, VPNs, WAF).
- Core Systems & Server Management: Administer, patch, configure, and maintain Linux and Windows Server environments across cloud and hybrid infrastructure.
- Directory Services & Identity (IAM): Manage Active Directory (AD), Microsoft Entra ID (formerly Azure AD), single sign-on (SSO), multi-factor authentication (MFA), role-based access control (RBAC), and privileged access management (PAM).
- Infrastructure-as-Code & Automation: Maintain and author Infrastructure-as-Code (IaC) using Terraform, CloudFormation, or Bicep alongside PowerShell and Python scripting for system automation.
- Financial Operations (FinOps): Implement resource tagging, cost allocation, monitoring, and optimization strategies to govern cloud spend.
- Network Administration: Manage VPN client and site-to-site VPN configurations for secure connectivity between PAPL's cloud environments and customer utility sites; administer DNS, DHCP, and firewall rules across hybrid infrastructure; configure and maintain network access controls for remote edge gateway connectivity at customer sites.
- Vendor & Licence Management: Manage cloud provider accounts (AWS, Azure), Microsoft 365 licences, GitHub, monitoring tool subscriptions, and any third-party SaaS tools used by the engineering organisation covering renewals, cost optimisation, and access governance.
2. Microsoft 365 Cloud Ecosystem Management
- Administer the end-to-end Microsoft 365 suite (Exchange Online, SharePoint Online, Teams, OneDrive, and Defender for Office 365).
- Configure and manage Microsoft Intune / Mobile Device Management (MDM) and Endpoint Manager for asset compliance, policy enforcement, baseline security, and remote device management.
- Oversee M365 security, conditional access policies, data loss prevention (DLP) rules, spam/phishing protection, and eDiscovery configurations.
- Manage user lifecycle management (onboarding/offboarding), license distribution, and cloud identity synchronization via Entra Connect.
- Manage end-to-end device lifecycle for PAPL's internal team — laptop provisioning, hardware asset register, software licence tracking, and Intune device enrolment for all new joiners and leavers.
- Provide Level 2/3 IT support escalation for the internal engineering team — covering M365, endpoint, identity, and connectivity issues — and maintain an escalation runbook for recurring issue categories.
3. ISO 27001 Compliance & Information Security Management
- Operate within PAPL's established ISO 27001:2022 ISMS — adhering to defined information security policies, controls, and procedures across all cloud, system, and endpoint activities. The candidate is expected to understand, follow, and uphold the controls in place.
- Conduct periodic vulnerability management, security baseline audits, system hardening, and patch compliance tracking across all server workloads and endpoints.
- Manage secrets and certificates via AWS Secrets Manager, Azure Key Vault, and PKI infrastructure (mTLS/TLS management).
- Follow and maintain ISMS documentation standards — including logging, access records,
and operational audit trails — in line with established policies and control registers already in place.
- Support periodic ISMS reviews by providing accurate operational data, system logs, and evidence as requested by the IT HOD or CISO — ensuring infrastructure activities remain aligned to established security controls.
- Oversee access reviews, privileged identity workflows, log retention policies, and SIEM integration to ensure continuous compliance and incident readiness.
- Lead disaster recovery (DR) planning, backup management, and periodic recovery drills to meet target SLA, RTO, and RPO requirements.
4. SaaS Infrastructure & IIoT Edge Operations Note: PAPL's SaaS infrastructure and IIoT edge platform are being actively built and scaled. This section reflects both the current operational responsibilities and the build-out mandate the role carries.
- Maintain multi-tenant SaaS environments, shared service components, and automated customer provisioning pipelines.
- Administer Kubernetes clusters (EKS/AKS) for microservices workloads, ensuring health monitoring, autoscaling, and service routing.
- Support cloud IoT infrastructure (AWS IoT Core / Azure IoT Hub) for secure field device connectivity, certificate management, MQTT messaging, and Over-The-Air (OTA) firmware/model deployment monitoring.
- Detect and remediate edge-to-cloud connection drops, data pipeline gaps, and network disruptions.
- Monitor OTA firmware and AI model update deployments to iPUMPNET edge gateways across customer sites — detecting failed updates, connectivity drops, and resync failures, and coordinating resolution with the IoT Systems Engineer.
- Provide field site IT support for iPUMPNET deployments at utility customer sites — including diagnosing WAN/LAN/VPN connectivity issues, supporting edge gateway commissioning, coordinating with customer IT and network teams on firewall rules and network access, and resolving connectivity incidents affecting live pump station telemetry streams.
5. CI/CD, DevOps & Observability
- Build and support CI/CD release workflows in Azure DevOps or GitHub Actions with proper environment promotion and approval gates.
- Establish comprehensive monitoring, logging, and tracing using CloudWatch, Azure Monitor, Prometheus, Grafana, or SIEM tools.
- Maintain operational runbooks, backup logs, incident management runbooks, and participate in on-call technical escalations.
- Design and maintain automated build, test, and deployment pipelines for iPUMPNET's software workstreams — covering C# / ASP.NET Core cloud application, Python AI/ML pipelines, and infrastructure change automation — using GitHub Actions or Azure DevOps with branch protection, PR gates, and environment promotion controls.
- Implement and manage GitOps workflows for Kubernetes workload deployment — using ArgoCD or Flux for declarative, version-controlled cluster state management across EKS / AKS environments.
- Own the secrets and configuration management pipeline — integrating AWS Secrets Manager and Azure Key Vault into CI/CD workflows to ensure no secrets are stored in code repositories or pipeline artefacts.
- Define and enforce pipeline security controls — dependency scanning (OWASP / Snyk), container image vulnerability scanning (Trivy or equivalent), and SAST integration — aligned to PAPL's ISO 27001 ISMS controls.
- Build and maintain the developer experience layer — standardised pipeline templates, reusable GitHub Actions workflows, and documentation enabling PAPL's engineering teams to onboard recent microservices and AI/ML pipelines without needing custom pipeline builds each time.
- Define release management practices — versioning conventions, changelog standards, rollback procedures, and blue-green or canary deployment patterns for zero-downtime production releases to iPUMPNET's live utility customers.
Required Qualifications & Experience Education & Certifications
- Bachelor’s or master’s degree in computer science, Information Technology, Cybersecurity, or a related field.
- AWS Solutions Architect (Professional/Associate) or Azure Administrator (AZ-104) — required. AWS DevOps Engineer Professional, Azure DevOps Engineer Expert (AZ-400), or GitHub Actions certification — required; at least one DevOps platform certification must be held at time of joining or demonstrated in interview through hands-on assessment.
- ISO 27001:2022 awareness — preferred but not required as a formal certification. Candidates should have basic familiarity with information security principles and be comfortable operating within an ISMS-governed environment.
- Microsoft 365 Certified: Enterprise Administrator Expert or MS-102 / MD-102 — strongly preferred.
- ITIL Foundation — preferred; relevant for incident management, change management, and service continuity practices aligned to PAPL's operational standards.
- CompTIA Network+ or equivalent networking certification — preferred.
- CKA (Certified Kubernetes Administrator) - strongly preferred
- 5–8 years of experience spanning Systems Administration, Cloud Infrastructure Engineering, and Enterprise IT Operations.
- Proven experience managing hybrid environments combining AWS/Azure cloud infrastructure and Microsoft 365 enterprise ecosystems.
- Basic awareness of ISO 27001:2022 information security principles — sufficient to understand and follow established ISMS policies and controls in day-to-day infrastructure operations.
- Deep proficiency in Windows Server and Linux administration, PowerShell/Bash scripting, and active directory infrastructure.
- IaC & Container Platforms (required): Hands-on production experience with Terraform and container platform administration — Docker, Kubernetes (EKS and/or AKS) — including cluster health management, autoscaling configuration, and Helm-based workload deployment.
- CI/CD Engineering (required): Has built and operated CI/CD pipelines in GitHub Actions, Azure DevOps, or equivalent — covering build automation, test integration, environment promotion gates, approval workflows, and rollback procedures in production environments.
- Observability (required): Has integrated monitoring and alerting tooling — Prometheus, Grafana, CloudWatch, Azure Monitor, or equivalent — into production infrastructure, including defining alert thresholds, dashboards, and on-call escalation paths.
- Experience providing IT systems support in a startup or fast-scaling technology environment — comfortable building processes, writing runbooks, and handling Level 2/3 support escalations as an individual contributor alongside infrastructure responsibilities.
- Experience supporting IT connectivity and endpoint management for geographically dispersed teams or field sites — including remote troubleshooting of VPN, network, and device issues.
Technical Skills
- Cloud & Edge Platforms: AWS (EC2, ECS, EKS, RDS, S3, IoT Core), Azure (VMs, AKS, IoT Hub, Key Vault)
- M365 & Endpoint: Microsoft Entra ID, Intune (MDM/MAM), Exchange Online, SharePoint, Teams, Defender
- System Administration: Windows Server (2016–2022), Linux (RHEL/Ubuntu), Active Directory, DNS, DHCP, Group Policy (GPO), Backup & DR
- Security & Compliance: ISO 27001 ISMS Controls, Vulnerability Management, Zero-Trust Architecture, IAM, Conditional Access, WAF, SIEM
- IaC & Scripting: Terraform, PowerShell, Python, Bash, Azure Bicep / CloudFormation
- CI/CD & Release Engineering: GitHub Actions, Azure DevOps, ArgoCD / Flux (GitOps), blue-green and canary deployment patterns, environment promotion gates, release versioning
- Observability & Monitoring: CloudWatch, Azure Monitor, Prometheus, Grafana, OpenTelemetry, SIEM integration, structured logging, distributed tracing
- Pipeline Security (DevSecOps): OWASP dependency checking, Trivy / container image scanning, SAST integration, secrets management in pipelines (AWS Secrets Manager, Azure Key Vault)
What Success Looks Like
- Within 60 days: Complete a hands-on audit of cloud platforms, enterprise IT, and M365 environments; produce a prioritised gap and risk register; and achieve operational familiarity with PAPL's established ISMS controls, runbooks, and CI/CD pipeline architecture.
- Within 6 months: Standardize device management and access policies via Microsoft Intune and Entra ID, streamline IaC for multi-tenant SaaS environments, and enforce zero-trust security controls across all edge, system, and cloud interfaces.
- Within a year: Operate a fully resilient, compliant hybrid infrastructure with automated provisioning, established uptime SLA monitoring and reporting, optimised cloud spends, and a mature security posture — with all infrastructure activities consistently aligned to PAPL's ISO 27001:2022 ISMS controls.
What We Offer
- Build Something That Matters — Design and operate the cloud and IT backbone of a platform that monitors water supply infrastructure serving millions of people across multiple cities.
- Greenfield Infrastructure Ownership — PAPL's cloud infrastructure and ISMS are being built from the ground up. You will make foundational architecture decisions, not inherit someone else's technical debt.
- ISO 27001 Certification Journey — Join at a meaningful point in PAPL's ISO 27001:2022 certification programme. The ISMS framework is established and controls are in place — your role is to embed them into day-to-day infrastructure operations and help carry the programme through to certification.
- Full-Stack Infrastructure Exposure — Operate across cloud (AWS & Azure), enterprise IT (M365, Entra ID, Intune), edge IoT (AWS IoT Core, Azure IoT Hub), and field site connectivity — all within one role at one company.
- Direct Technology Leadership Access — Work alongside PAPL's CTO and engineering leads with genuine influence over infrastructure, security, and platform architecture decisions.
- Competitive Compensation — Aligned with seniority and the breadth of responsibility this role carries.
- Real-World Utility Impact — Your infrastructure decisions directly affect the reliability of live pumping stations. When uptime matters, your work is visible and valued.
📌 Cloud Infrastructure, Systems & DevOps Engineer (Bengaluru)
🏢 Pump Academy
📍 Bengaluru