Senior DevOps Engineer
joindevops
Job Description
Cloud Infrastructure (Azure)
- Design, provision, and maintain Azure infrastructure using Bicep/Terraform — modular, parameterized, environment-aware
- Manage AKS clusters: node pools, upgrades, RBAC, network policies, CNI (Azure CNI / Overlay), ingress (NGINX/AppGW), HPA, pod security standards
CI/CD & Automation
- Author and maintain multi-stage Azure Pipelines (YAML) with reusable templates, variable groups, environments, and approval gates
- Write PowerShell automation for provisioning, release rollout, and environment management (non-negotiable)
Security & Compliance
- Triage and remediate CVEs; track and close VAPT findings within agreed SLAs
- Apply pod security standards, network policies, and least-privilege RBAC across Kubernetes namespace.
Observability & Reliability
- Build and maintain KQL-based alerts, dashboards, and workbooks in Log Analytics
- Manage Prometheus + Grafana stacks for Kubernetes workload observability.
Docker & Container Management
- Author optimized multi-stage Dockerfiles; enforce image size and vulnerability standards
- Manage image lifecycle in ACR (tagging strategy, retention policies, geo-replication)
Nice to Have
- MLOps experience: vLLM deployment on Azure ML, LoRA adapter management, LiteLLM proxy configuration
- Familiarity with AI/ML model gateway patterns (OpenAI - compatible APIs, model routing).
Skills, Knowledge, and Experience:
- 4+ years of experience in DevOps.
- Azure — AKS, Azure DevOps (Pipelines, Repos, Boards), Key Vault, ACR, Monitor, Log Analytics, App Configuration.
- Kubernetes — workload deployment, RBAC, network policies, ingress, HPA, pod security, troubleshooting.
- Docker — multi-stage builds, image optimization, registry management.
- Bicep / Terraform — authoring modular, parameterized IaC; ARM comprehension at minimum.
- Azure Pipelines — multi-stage YAML, templates, variable groups, environments, approval gates
- PowerShell — release automation, provisioning scripts (non-negotiable); Bash for Linux containers.
- Security (critical) — container image scanning (Trivy/Veracode/Defender), CVE triage and remediation, VAPT awareness.
- Secrets management — Azure Key Vault, Managed Identity.
- Observability — KQL, Log Analytics alerts, Prometheus + Grafana, Application Insights.
- Networking — VNets, NSGs, private endpoints, AKS CNI models, TLS/cert-manager
- Agile/ADO — sprint ceremonies, Boards, runbook authoring
- Nice to have — MLOps (vLLM, Azure ML)