19 Sep
|
Swazei Tech
|
New Delhi
19 Sep
Swazei Tech
New Delhi
Job Brief:
We are hiring a mid-level DevOps engineer to become the second dedicated infrastructure person on the team. The ideal candidate will have a strong background in managing CI/CD pipelines, automating infrastructure, monitoring systems, automating deployments, and managing backups. You will take real, named ownership of parts of that surface, not just tickets. We expect you to have shipped production infrastructure before and to work independently on a well-scoped problem
What Youll Do:
- Own the container platform. Design, deploy and operate containerised services on ECS Fargate/EKS
- Make releases boring. Build and harden CI/CD pipelines so that every environment ships the same immutable artifact, promoted rather than rebuilt, with gates that fail before production does.
- Put the infrastructure in code. Write and review Terraform as reusable modules with per-environment state, and keep drift in check.
- Run the AWS foundations. Networking, IAM, load balancing, DNS, certificates, secrets and managed databases
- Operate the edge fleet. Ship versioned, gated deployments to Linux terminals running in live retail stores, held to the same release discipline as the cloud.
- Make production observable. Build the metrics, logs, traces and alerting that surface problems before a customer reports them.
- Hold the security line. No hardcoded secrets, least-privilege IAM, strict tenant isolation, scanned images, patched hosts.
Our Stack:
- Cloud: AWS
- Containers & compute: ECS Fargate, EKS, ECR, EC2, Docker, Docker Compose
- IaC: Terraform
- CI/CD: GitHub Actions
- Observability: Grafana Cloud, Alloy, Loki, Prometheus, Pyroscope, OpenTelemetry
- Data & storage: MySQL, S3, AWS Backup, MWAA, DMS
- Networking & edge: VPC, ALB, Route 53, CloudFront, ACM,
WAF, Traefik, Tailscale
- Security & secrets: IAM, IAM Identity Center, Secrets Manager, SSM Parameter Store, Session Manager, GuardDuty
- Identity: Keycloak (OAuth2 / OIDC)
- Edge & IoT: AWS IoT Greengrass v2
- Languages: Python, Bash
The unusual part:
- Most of this role is ordinary, well-run cloud platform work. One part is not: a meaningful slice of our production estate is Linux machines sitting in retail stores, managed as an AWS IoT Greengrass v2 fleet running components we build ourselves - kiosk hardening, printer and peripheral interfaces, on-device authentication and remote support. Those deployments are versioned and gated exactly like our cloud releases.
- You do not need prior Greengrass or IoT experience. What you do need is willingness to learn and the comfort with the idea that production includes hardware that goes offline
Qualifications:
- 3-5 years in DevOps, SRE, platform or infrastructure engineering, with at least 2 years on AWS in production
- Hands-on production experience with ECS (Fargate/EC2) or EKS - you have deployed, debugged and scaled real services on one of them, not just completed a tutorial. Be ready to talk about a deployment that failed and how you diagnosed it
- Strong Docker fundamentals: multi-stage builds, image size and layer caching, entrypoints, and debugging a container that will not start
- CI/CD ownership on GitHub Actions (or a comparable platform you can map across) - build matrices, artifact promotion, setting gating, secret handling
- Terraform in a team setting: modules, remote state, reading a plan and knowing what it will destroy
- Solid AWS core services: VPC, subnets, security groups, IAM roles and policies, ALB, Route 53, S3, CloudFront, ECR, Secrets Manager / SSM
- Linux administration and comfort living in a terminal
- Bash and Python scripting for automation - good enough to write a tool your teammates rely on
- Working knowledge of relational databases (MySQL/Aurora or PostgreSQL): migrating, backing up, restoring
Nice to Have: None of these are required. Any of them will make your application stand out.
- Kubernetes at depth - EKS, Helm, Argo CD (relevant to where our platform is heading)
- AWS IoT Greengrass v2, IoT Core, or any fleet/edge device management
- Grafana Cloud stack: Alloy, Loki, Pyroscope, OpenTelemetry instrumentation
- Keycloak, or OAuth2/OIDC and SSO integration generally
- Security tooling: Trivy, SonarQube, AWS WAF, GuardDuty
- AWS cost management: Cost Explorer, Savings Plans, rightsizing, tagging strategy
- AWS IAM Identity Center, multi-account or Organizations setups
- Running PHP or similar interpreted web stacks in production - application runtime tuning and reverse-proxy configuration (Nginx, Apache or Traefik)
- Data platform exposure: MWAA/Airflow, DMS, or similar pipelines
- Load and performance testing with k6 or JMeter
- Multi-tenant SaaS experience, especially where tenant isolation is a hard requirement
- Relevant AWS certification (Solutions Architect Associate, SysOps)
📌 Devops Engineer (New Delhi)
🏢 Swazei Tech
📍 New Delhi