Senior DevOps Engineer
Віддалений* формат співпраці з території - Україна
*Ви можете працювати віддалено з території країни (або країн), для яких відкрита ця позиція.
DevOps& інші навички
We are seeking an experienced Senior DevOps Engineer to design, build, and maintain scalable, secure, and highly available cloud infrastructure on AWS. In this role, you will drive automation, optimize deployment pipelines, and ensure operational excellence across production environments while collaborating with cross-functional teams to support business-critical systems.
Чим ви будете займатися у цій ролі
- Design IAM roles and policies based on the principle of least privilege, configure roles for EC2, ECS, and Lambda, and set up cross-account access, federation (SSO/SAML), environment-based access separation, and access auditing
- Architect VPC network topology with public/private subnets across Availability Zones, configure route tables, NAT Gateway, Internet Gateway, security groups, NACLs, VPC peering, and VPC endpoints for services such as S3 and ECR, ensuring proper CIDR planning and environment isolation
- Provision and maintain EC2 instances, work with Launch Templates, Auto Scaling Groups, scaling policies, AMI pipelines, and Spot/On-Demand strategies for cost optimization
- Configure load balancers (ALB/NLB), target groups, health checks, path-based and host-based routing rules, manage TLS termination, and integrate ACM certificates
- Deploy and maintain container clusters using ECS/Fargate or EKS, working with manifests, Helm, node groups, IRSA, task definitions, services, ALB integration, and autoscaling
- Manage ECR image repositories, lifecycle policies, vulnerability scanning, and access permissions for push/pull operations from pipelines and clusters
- Organize S3 buckets, configure access policies, versioning, lifecycle rules, archival strategies such as Glacier, encryption, static hosting, and artifact/backup storage
- Deploy RDS/Aurora databases with Multi-AZ, read replicas, backups, snapshots, point-in-time recovery, parameter groups, performance monitoring, and encryption
- Collect metrics and logs via CloudWatch, build dashboards and alarms, configure log groups, metric filters, and SNS-based alerting
- Manage encryption keys through KMS and secure sensitive data using Secrets Manager, integrating secrets into applications and pipelines without hardcoding
- Configure CloudFront CDN distributions, origins such as S3 or ALB, caching policies, TLS certificates, and cache invalidation
- Administer Route 53 DNS zones, record types, health checks, and routing policies such as weighted, latency-based, and failover, integrating with ALB and CloudFront using alias records
Навички
- 3+ years of experience in a DevOps, SRE, or cloud infrastructure engineering role
- Expertise in AWS IAM, VPC, and EC2 with Auto Scaling for secure, scalable, and cost-effective infrastructure
- Proficiency in AWS networking and delivery services, including ELB (ALB/NLB), CloudFront, and Route 53
- Background in container orchestration with ECS/Fargate or EKS, along with ECR for image management
- Skills in AWS data and storage services such as S3 and RDS/Aurora, including Multi-AZ, replication, and backup strategies
- Competency in AWS security and observability tooling, including KMS, Secrets Manager, and CloudWatch
- Knowledge of Infrastructure as Code using Terraform or CloudFormation, with modular design and state management
- Capability to build and maintain CI/CD pipelines using GitLab CI, GitHub Actions, or Jenkins
- Understanding of containerization and orchestration with Docker and Kubernetes in production environments
- Flexibility to use Bash and/or Python for automation and operational tasks
- Showcase of observability practices covering monitoring, logging, and alerting across infrastructure and applications
- Strong analytical and problem-solving skills with a structured and proactive approach to work
- Proficiency in English at an Upper-Intermediate level (B2) or higher
Буде перевагою
- Familiarity with EBS/EFS, DynamoDB, and ElastiCache (Redis or Memcached) for storage, database, and caching needs
- Experience with Lambda for building serverless functions, triggers, and integrations
- Understanding of hybrid connectivity via Direct Connect or Site-to-Site VPN, and perimeter protection with WAF/Shield
- Knowledge of SSM Parameter Store, AWS security best practices, and cost optimization techniques such as right-sizing, scheduling, and Spot instances
- Background in high availability, disaster recovery, and monitoring tools such as Prometheus, Grafana, or Datadog and ELK Stack