- Company Name
- Mindlapse
- Job Title
- Ingénieur·e SRE / DevOps
- Job Description
-
**Job Title**
SRE / DevOps Engineer
**Role Summary**
Design, build, and operate a secure, highly‑available multi‑cloud infrastructure (AWS, GCP, sovereign cloud) for an AI‑driven SaaS Cyber‑GRC platform. Drive architecture decisions, automate provisioning, enforce compliance, and enable developers through a self‑service platform.
**Expectations**
- 2‑5 years of hands‑on SRE/DevOps or Cloud Engineering experience.
- Ability to work autonomously in a small startup team and influence the technical roadmap.
- Strong focus on security, cost efficiency (FinOps), and regulatory compliance (ISO 27001, SOC 2, GDPR, DORA, NIS2).
- Collaborative mindset with developers, AI specialists, and cybersecurity experts.
**Key Responsibilities**
- **Infrastructure as Code & Cloud**: Design and maintain Terraform‑based environments across multi‑account, multi‑region landing zones; provision VPC, EKS/ECS, RDS, S3, IAM, and managed services; implement cost‑optimization strategies.
- **Kubernetes & Orchestration**: Operate EKS clusters for multi‑tenant SaaS; manage Helm/Kustomize charts, deployment patterns (blue/green, canary), HPA/KEDA autoscaling, NetworkPolicies, and service mesh.
- **CI/CD & Automation**: Build GitHub Actions pipelines for front‑end (React/Next.js), back‑end (AdonisJS), and AI micro‑services (Python); integrate testing, linting, SAST/DAST, automated rollbacks, feature flags, and secret management (Vault, AWS Secrets Manager).
- **Developer Experience & Platform Engineering**: Create an Internal Developer Platform for self‑service environment provisioning, preview environments, dev containers, and IaC documentation; reduce manual toil through automation.
- **Observability & Reliability**: Deploy monitoring (Prometheus/Grafana or Datadog), logging (Loki/CloudWatch), tracing; define SLI/SLO/Error Budgets; implement intelligent alerting, runbooks, blameless post‑mortems, and AIOps enhancements.
- **Security & Compliance**: Embed DevSecOps practices (image scanning, OPA/Gatekeeper policies); harden cloud resources per ISO 27001, SOC 2, GDPR; manage RBAC, least‑privilege IAM, encryption, and network segmentation.
**Required Skills**
- Terraform (IaC) and cloud‑native provisioning.
- Production‑grade Kubernetes (EKS/GKE or self‑managed) and Helm/Kustomize.
- Deep knowledge of AWS; familiarity with GCP and sovereign clouds (Scaleway/OVH).
- CI/CD tooling (GitHub Actions, GitLab CI) and pipeline automation.
- Scripting (Bash, Python) and containerization (Docker).
- Monitoring/observability stack (Prometheus, Grafana, Datadog, Loki, CloudWatch, distributed tracing).
- Secret management (HashiCorp Vault, AWS Secrets Manager).
- Cost‑optimization (FinOps) and multi‑cloud architecture.
- Security tooling (SAST/DAST, OPA/Gatekeeper, image scanning).
- Strong problem‑solving, communication, and teamwork abilities.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Engineering, or related field (or equivalent practical experience).
- Preferred certifications: AWS Certified Solutions Architect – Associate/Professional, Certified Kubernetes Administrator (CKA), Google Cloud Professional Cloud Architect, or similar.