CareerPlanGet AI match score →

Infrastructure Engineer (Kubestronaut) -- SaaS Platform

💼 Full-time🗓 2026-06-25

Core

Design and implement a cloud-native, non-monolithic Kubernetes platform for a global SaaS platform with strict multi-region compliance requirements.

Role type

Senior Infrastructure Engineer (Kubernetes)

Builds

Cloud-native Kubernetes platform, GitOps pipelines, service mesh, and observability stack.

Domain

SaaS, Cloud Infrastructure, Compliance (GDPR, PIPEDA, CCPA, LGPD, POPIA)

Deliverable

production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work

Required skills

Kubernetes cluster design and operations, GitOps principles, Service mesh implementation, SOC2 Type II audit readiness, Multi-region data residency architecture, Zero-trust networking, Container image supply chain security

Preferred skills

eBPF-based networking, Sovereign infrastructure design, CNCF community contributions

Technologies

Kubernetes, Helm, ArgoCD, Istio, Cilium, Terraform, Prometheus, Grafana, OpenTelemetry, Vault, GitHub Actions, PostgreSQL, Kafka, Redis

Responsibilities

Design multi-region Kubernetes clusters with data residency compliance, Implement GitOps delivery pipelines with automated rollback, Configure service mesh for mTLS and traffic management, Build full-stack observability stack, Manage secrets with audit trails, Design CI/CD pipelines with no manual production access

Seniority

Senior, hands-on IC

Rewrite
## About the company We are building a next-generation SaaS platform for sports club and membership management, targeting an initial US launch with a staged global rollout. The platform is designed for global scale with strict compliance requirements across multiple regions and regulatory frameworks. Infrastructure is not an afterthought here. It is a first-class engineering concern from day one. We operate async-first with structured sprint delivery. The CTO is based in Canada (PST). Our project manager is based in Armenia (GMT+4). You will need meaningful daily overlap with both. ## About the role We are building our infrastructure team from the ground up. You will own the design and implementation of a cloud-native, non-monolithic Kubernetes platform built on open-source tooling with no vendor lock-in. You will work directly with the CTO to establish the infrastructure architecture, GitOps delivery pipeline, service mesh, observability stack, and secrets management layer. This is a greenfield build with real compliance requirements and real consequences if it is done wrong. ## What you will work on - Kubernetes cluster design and operations across multiple regions with data residency requirements - GitOps delivery pipeline using ArgoCD or Flux with declarative configuration and automated rollback - Service mesh implementation for mTLS, traffic management, and network-layer observability - Full-stack observability: metrics, logs, traces, and alerting across all services - Secrets management with audit trail requirements for SOC2 compliance - Container image supply chain security including signing and admission control - RBAC design and policy enforcement at the cluster level - Multi-region compliance architecture covering GDPR, PIPEDA, CCPA, LGPD, and POPIA - CI/CD pipeline design with environment promotion and no manual production access - Infrastructure-as-code with full auditability and change management through Git ## Tech stack (CNCF and open-source first) - Kubernetes - Helm - ArgoCD - Istio - Cilium - Terraform - Prometheus - Grafana - OpenTelemetry - Vault - GitHub Actions - PostgreSQL - Kafka - Redis - CKA - CKS ## Certification requirement - Active Kubestronaut status required. - All five CNCF Kubernetes certifications (CKA, CKAD, CKS, KCNA, KCSA) must be current and in good standing at time of engagement. ## What we are looking for - Demonstrated experience building and operating production Kubernetes infrastructure at scale - Deep understanding of GitOps principles and declarative infrastructure management - Hands-on experience with service mesh (Istio or Cilium) in a production environment - Ability to design for SOC2 Type II audit readiness from day one, not retrofitted after the fact - Familiarity with multi-region data residency architecture and the compliance frameworks that govern it - Zero-trust networking mindset: mTLS everywhere, least-privilege RBAC, secrets never in plaintext - Strong written English for async collaboration and documentation across time zones - You can explain and defend every architectural decision under direct questioning ## Nice to have - Experience with eBPF-based networking and observability - Familiarity with sovereign infrastructure design (no US-hosted certificate authorities, open-source trust chains) - Experience with container image signing and supply chain security - Contributions to CNCF projects or active participation in the CNCF community ## Engagement structure - Independent contractor engagement (Panama-incorporated company) - Full-time equivalent hours (40 hrs/week) - Paid trial period (1-2 weeks) with real project work before long-term commitment - Async-first environment with structured sprint cadence - Opportunity for a longer-term engagement based on performance ## Note on the application process Shortlisted candidates will be required to complete a structured technical assessment before any offer is made. The assessment includes scenario-based architecture questions covering multi-region cluster topology, secrets management, GitOps delivery, and compliance-aware infrastructure design. There is no boilerplate answer that passes. We are looking for engineers who have solved these problems in production and can walk us through exactly how they did it. ## To apply, please include - Your timezone and available overlap hours with PST - Your current CNCF certifications and their expiry dates - A description of a production Kubernetes platform you designed or operated, including scale, regions, and compliance requirements it had to meet - How you have approached multi-region data residency in a past project - Your preferred GitOps tooling and why you chose it over alternatives - How you think about secrets management in a SOC2 audit context
Sourced via wellfound · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.
Apply on Wellfound ↗