Senior DevOps Engineer (Spain/remote)
hace 9 horas
Barcelona
pSenior DevOps Engineer — sanctions.io (Spain / Remote-Friendly) /ppbr/pp--- /ppbr/pp We're hiring a Senior DevOps — a compliance SaaS company with ~300 customers in the financial sector. If Kubernetes, AWS, and security are your home turf, and you like real ownership over infrastructure, let's talk. /ppbr/pp--- /ppbr/ppAbout the Role /ppbr/ppAt sanctions.io, our infrastructure is the product. When screening latency spikes or a pipeline stalls, our customers notice — and in compliance, reliability isn't a nice-to-have. /ppbr/ppWe're looking for a Senior DevOps Engineer to own our cloud infrastructure end-to-end. You'll lead the migration from AWS ECS to Kubernetes, harden our security posture, and make sure our platform scales cleanly as we grow. This is a high-autonomy, high-ownership role — you'll make real decisions, not implement tickets. /ppbr/ppYou'll be the primary infrastructure owner, working closely with the Head of Engineering and development team, with occasional collaboration with external support. /ppbr/pp--- /ppbr/ppWhat You'll Do /ppbr/ppKubernetes Migration (near-term priority) /pp- Architect and execute the full migration of services from AWS ECS to Kubernetes (EKS) /pp- Design cluster topology, namespace strategy, network policies, and secrets management /pp- Validate rollout with proper testing, rollback planning, and documentation /pp- Set up GitOps workflows (ArgoCD or Flux preferred) /ppbr/ppInfrastructure Ownership /pp- Own all AWS infrastructure: networking (VPC, subnets, SGs), compute, storage (S3, RDS), IAM, ECR /pp- Manage Terraform configurations across staging and production environments /pp- Improve Docker image builds, optimise for size and scan for vulnerabilities /pp- Collaborate with engineers on infrastructure needs for new features (e.g. AI workloads, vector search, batch processing) /ppbr/ppCI/CD Automation /pp- Maintain and improve GitHub Actions workflows and deployment pipelines /pp- Implement blue/green or canary deployments where appropriate /pp- Introduce automation that reduces toil and human error /ppbr/ppMonitoring Reliability /pp- Own observability: Prometheus, Grafana, structured logging, and alerting strategy /pp- Ensure Sentry is properly integrated and actionable /pp- Define and own incident response procedures and on-call processes /pp- Think proactively about failure modes and disaster recovery /ppbr/ppSecurity /pp- Container security scanning and hardening /pp- Secrets management (external-secrets, sealed-secrets, or equivalent) /pp- Network segmentation, SSL/TLS, access controls, and IAM hygiene /pp- Stay current on AWS security best practices and act on them /ppbr/pp--- /ppbr/ppWhat We're Looking For /ppbr/ppMust-Have /ppbr/pp- 5+ years of DevOps/infrastructure engineering in production cloud environments /pp- Kubernetes (3+ years, production-grade) — EKS strongly preferred /pp - Helm, Kustomize or equivalent /pp - Ingress, network policies, HPA/VPA /pp - Experience migrating workloads Kubernetes (from ECS or Docker Compose) /pp - Real debugging and troubleshooting experience /pp- Strong AWS — ECS, EC2, S3, SQS, RDS (PostgreSQL), VPC, IAM, ECR /pp- Terraform — managing real multi-environment codebases, not just tutorials /pp- GitHub Actions and solid CI/CD fundamentals /pp- Docker image optimisation and container security awareness /pp- Spanish native or fluent (C1+), excellent English — our tech team is in Spain; our product and customers are international /pp- Based in Spain or willing to relocate — Tenerife preferred, but strong candidates in CET timezone are considered for remote /ppbr/ppStrong Plus /pp- GitOps (ArgoCD or Flux) in production /pp- AWS DevOps Agent /pp- Elasticsearch cluster management and scaling /pp- PostgreSQL administration under load (tuning, backups, replication) /pp- Redis and Celery worker infrastructure /pp- Familiarity with infrastructure needs for AI/ML workloads (GPU instances, batch inference pipelines) — not required, but we're moving in this direction /ppbr/ppNice-to-Have /pp- Experience in fintech, compliance, or regulated industries where security posture matters /pp- Incident commander experience or structured on-call process ownership /ppbr/pp--- /ppbr/ppOur Stack /ppbr/ppAWS (ECS → EKS migration in progress) · Kubernetes · Terraform · Docker · GitHub Actions · Prometheus · Grafana · Sentry · PostgreSQL (RDS) · Elasticsearch · Redis · Celery · SQS · Python/Django backend /ppbr/pp--- /ppbr/ppWhat We Value /ppbr/pp- Ownership: The infrastructure is yours. If something is broken or could be better, you don't wait to be asked. /pp- Pragmatism: You choose the right tool, not the trendiest. You balance ideal with shippable. /pp- Clear communication: You write down what you did and why. Async-first team. /pp- Reliability mindset: You think about failure modes before they become incidents, not after. /pp- Openness to new tech: We're actively exploring AI capabilities — you should be comfortable adapting infrastructure to support new workload types. /ppbr/pp--- /ppbr/ppAbout sanctions.io /ppbr/ppsanctions.io provides API and portal services for sanctions screening, PEP data, and adverse media monitoring — used by ~300 customers and 500 users in the financial compliance space. We're a small, focused team building infrastructure that keeps the financial system clean. /ppbr/pp Remote-friendly (Spain-based team, CET timezone) /pp Working language: Spanish (team) + English (product/customers) /pp HQ: Tenerife, Spain /ppbr/pp--- /ppbr/pp /ppbr/p