
Application DevSecOps Engineer
Posted Sep 15

Posted Sep 15
This is a fully remote position, open to applicants in Germany.
• Assume responsibility for the technical operation of the openDesk managed service.
• Implement and update openDesk components using Helmfile/Helm-Diff through GitLab CI.
• Oversee releases and patches.
• Deploy supporting services via GitOps whenever feasible.
• Manage databases using CNPG and the MariaDB Operator, including tasks such as backup/restore, point-in-time recovery, and upgrades.
• Handle application-specific secrets through ExternalSecrets linked to OpenBao.
• Monitor the application by utilizing application-specific metrics and alerting rules, while contributing to the definition of SLIs/SLOs.
• Manage supporting services like Redis/Memcached, object storage, mail infrastructure, ClamAV/ICAP, and Coturn.
• Diagnose and resolve issues within openDesk components and the Kubernetes layer.
• Create and maintain runbooks.
• Automate operational and deployment processes.
• Collaborate with the Platform team.
• Participate in the on-call rotation alongside the team for 24/7 operations.
• Proficient in managing Kubernetes, encompassing workloads, networking, RBAC, storage, and troubleshooting.
• Experience with Helm; a willingness to work with, and ideally familiarity in, Helmfile and Helm-Diff.
• Hands-on experience with CI-driven rollouts, such as GitLab CI, and/or GitOps frameworks like Flux.
• Background in operating databases (PostgreSQL/MariaDB), preferably with CNPG/CloudNativePG or the MariaDB Operator.
• Familiarity with monitoring and observability tools (Prometheus/Grafana ecosystem) and alerting mechanisms.
• Strong Linux skills and an automation-focused mindset, including experience with Ansible and scripting.
• Willingness to engage in on-call support for the 24/7 service without shift work.
• Proficient in German and English (C1/C2), both written and spoken.
• Empirical and agile mindset coupled with robust problem-solving abilities.
• Demonstrated operational ownership and reliability in a 24/7 environment.
• Excellent communication skills, teamwork capability, and self-organization skills.
• Awareness of security principles (security by design, least privilege).
• Openness to give and receive 360-degree feedback.
• Nice to have: Familiarity with openDesk components.
• Nice to have: Experience with ExternalSecrets and Vault/OpenBao.
• Nice to have: Knowledge of Redis/Memcached, object storage, mail infrastructure, ClamAV/ICAP, and Coturn.
• Nice to have: Experience managing multi-tenant environments across various clusters.
• Nice to have: Certifications such as CKA/CKS.
• Nice to have: Background in IT operations for managed services or SaaS environments.
• Nice to have: Willingness to share knowledge within the team.
• Remote-first work model with the flexibility to choose between home, shared office, or a combination of both.
• Flexible working hours that promote personal accountability.
• Engaging projects with the freedom to select projects individually.
• Training and certification expenses covered, including time off for training sessions.
• Opportunities for internal knowledge sharing and professional/methodological growth.
• Provision of modern hardware, appropriate software, and all necessary equipment.
• Annual share in the company’s profits.
• Option for a company car, subject to the role.
• 30 days of annual leave that do not expire.
• Group accident insurance coverage.
• Frequent team-building activities, gatherings, workshops, and outings.
• Consistent feedback and development discussions.
FourEnergy GmbH
ICF
Mastercam
C&S Informática
Get handpicked remote jobs straight to your inbox weekly.