Lead DevSecOps Engineer (Remote, Anywhere in Pakistan, USD Salary)
Requirements
- 7+ years of hands‑on DevOps / Infrastructure engineering experience with AWS
- Proven track record of redesigning and scaling production infrastructure for high‑growth companies
- Deep expertise in AWS services including RDS, EC2, ELB / ALB, Route53, VPC, IAM, and CloudFormation / Terraform
- Strong security background with experience in infrastructure hardening and compliance
- Experience migrating from traditional deployments to modern container orchestration (Kubernetes / ECS)
- Proficiency in infrastructure‑as‑code tools (Terraform preferred)
- Expert‑level scripting skills in Python, Go, or Bash
- Experience with GitLab CI / CD pipelines and GitLab‑based workflows
- Kubernetes expertise for container orchestration at scale
- Experience with monitoring / observability tools (Prometheus, Grafana, DataDog, ELK stack)
- Advanced GitLab experience including GitOps practices, GitLab Runner optimization, and GitLab security scanning
- Knowledge of serverless architectures and event‑driven systems
- Experience with compliance frameworks (SOC2, ISO 27001, etc.)
- Previous experience supporting AI / ML workloads and data pipelines
Responsibilities
Critically evaluate our existing AWS infrastructure setup including RDS configurations, EC2 instances, Nginx load balancing, Docker Compose deployments, Target Groups, and Route53 DNS managementIdentify security vulnerabilities and scalability bottlenecks in the current architectureDesign and implement infrastructure improvements with a focus on high availability, disaster recovery, and auto‑scaling capabilitiesModernize deployment strategies moving from Docker Compose to more scalable orchestration solutions where appropriateConduct security audits of existing infrastructure and implement security hardening measuresRedesign network architecture with proper VPC segmentation, security groups, and IAM policiesImplement secrets management and encryption at rest / in transit across all servicesEstablish compliance frameworks suitable for enterprise clients in manufacturing and aerospace sectorsArchitect auto‑scaling solutions to handle variable workloads and traffic spikesOptimize database performance and implement proper backup / recovery strategies for RDSDesign load balancing strategies that can handle global traffic distributionImplement caching layers and CDN strategies for improved performanceTake full ownership of infrastructure decisions and their implementationDrive initiatives from conception to completion with minimal supervisionEstablish infrastructure standards and best practices across the engineering organizationLead incident response and post‑mortem analysis for infrastructure‑related issues#J-18808-Ljbffr