Infrastructure Engineer (Kubestronaut) -- SaaS Platform
💼 Full-time🗓 2026-06-25
Rewrite
## About the company
We are building a next-generation SaaS platform for sports club and membership management, targeting an initial US launch with a staged global rollout. The platform is designed for global scale with strict compliance requirements across multiple regions and regulatory frameworks. Infrastructure is not an afterthought here. It is a first-class engineering concern from day one.
We operate async-first with structured sprint delivery. The CTO is based in Canada (PST). Our project manager is based in Armenia (GMT+4). You will need meaningful daily overlap with both.
## About the role
We are building our infrastructure team from the ground up. You will own the design and implementation of a cloud-native, non-monolithic Kubernetes platform built on open-source tooling with no vendor lock-in. You will work directly with the CTO to establish the infrastructure architecture, GitOps delivery pipeline, service mesh, observability stack, and secrets management layer. This is a greenfield build with real compliance requirements and real consequences if it is done wrong.
## What you will work on
- Kubernetes cluster design and operations across multiple regions with data residency requirements
- GitOps delivery pipeline using ArgoCD or Flux with declarative configuration and automated rollback
- Service mesh implementation for mTLS, traffic management, and network-layer observability
- Full-stack observability: metrics, logs, traces, and alerting across all services
- Secrets management with audit trail requirements for SOC2 compliance
- Container image supply chain security including signing and admission control
- RBAC design and policy enforcement at the cluster level
- Multi-region compliance architecture covering GDPR, PIPEDA, CCPA, LGPD, and POPIA
- CI/CD pipeline design with environment promotion and no manual production access
- Infrastructure-as-code with full auditability and change management through Git
## Tech stack (CNCF and open-source first)
- Kubernetes
- Helm
- ArgoCD
- Istio
- Cilium
- Terraform
- Prometheus
- Grafana
- OpenTelemetry
- Vault
- GitHub Actions
- PostgreSQL
- Kafka
- Redis
- CKA
- CKS
## Certification requirement
- Active Kubestronaut status required.
- All five CNCF Kubernetes certifications (CKA, CKAD, CKS, KCNA, KCSA) must be current and in good standing at time of engagement.
## What we are looking for
- Demonstrated experience building and operating production Kubernetes infrastructure at scale
- Deep understanding of GitOps principles and declarative infrastructure management
- Hands-on experience with service mesh (Istio or Cilium) in a production environment
- Ability to design for SOC2 Type II audit readiness from day one, not retrofitted after the fact
- Familiarity with multi-region data residency architecture and the compliance frameworks that govern it
- Zero-trust networking mindset: mTLS everywhere, least-privilege RBAC, secrets never in plaintext
- Strong written English for async collaboration and documentation across time zones
- You can explain and defend every architectural decision under direct questioning
## Nice to have
- Experience with eBPF-based networking and observability
- Familiarity with sovereign infrastructure design (no US-hosted certificate authorities, open-source trust chains)
- Experience with container image signing and supply chain security
- Contributions to CNCF projects or active participation in the CNCF community
## Engagement structure
- Independent contractor engagement (Panama-incorporated company)
- Full-time equivalent hours (40 hrs/week)
- Paid trial period (1-2 weeks) with real project work before long-term commitment
- Async-first environment with structured sprint cadence
- Opportunity for a longer-term engagement based on performance
## Note on the application process
Shortlisted candidates will be required to complete a structured technical assessment before any offer is made. The assessment includes scenario-based architecture questions covering multi-region cluster topology, secrets management, GitOps delivery, and compliance-aware infrastructure design. There is no boilerplate answer that passes. We are looking for engineers who have solved these problems in production and can walk us through exactly how they did it.
## To apply, please include
- Your timezone and available overlap hours with PST
- Your current CNCF certifications and their expiry dates
- A description of a production Kubernetes platform you designed or operated, including scale, regions, and compliance requirements it had to meet
- How you have approached multi-region data residency in a past project
- Your preferred GitOps tooling and why you chose it over alternatives
- How you think about secrets management in a SOC2 audit context
Sourced via wellfound · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.