Senior/Staff DevOps Engineer
Manifest
As a Senior/Staff Platform Engineer, you will:
- Be deeply experienced with developing and deploying IaC and automation (Terraform, Ansible, Helm, Python, etc.) on a routine basis to support platform and customer requirements with a focus towards automation as much as practicable.
- Have operated and sustained cloud-based CI/CD pipeline and components utilizing DevSecOps principles, a strong eye on shift left mindset, and best practices including reducing human involvement through automation and similar.
- Automated application deployment leveraging container technology in a cloud-based environment through tools such as Kubernetes, Github, and other CI/CD tools and technologies
- Built tools and packaging to allow Manifest to be deployed in varied runtime environments - Cloud (AWS 1st, Azure/GCP secondary) on-prem, air gapped, FedRamp, etc.).
- Dogfood our own software supply chain product
- Integrate DevSecOps tools and services to enable an automated pipeline that supports customer applications throughout their SDLC.
- Research and use the latest in open-source tools to help build and secure our development pipeline
- Implement and improve observability starting with data gathering for MELT (Metrics, Events, Logs, Traces) and implementing presentation and alerting within our applications and infrastructure.
- Have deep experience deploying and operating applications with Kubernetes in a Cloud environment.
- Have strong verbal and written communication skills including production of design and other technical documents.
- Understand how to expose public endpoints including UI and APIs using load balancers, CDNs, and other tools do deliver robust, secure, highly available services.
- Be strong at networking and runtime troubleshooting experience including the challenges in debugging lights out, dynamic, complex, remote environments including Kubernetes and airgapped.
- Previous experience with commercial software products (SaaS and on-prem) that support 3rd party/external customers.
- Be well versed in Secure SDLC practices including external bug reports and SVM (software vulnerability management) lifecycle tools and processes.
Desirable skills and experience to increase your impact:
- Be capable at assisting application and backend developers on delivering secure applications including appropriate resource polices (CORS headers, etc) and supporting API security engineering by contributing to design and review.
- Experience with Kubernetes in edge environments including bare VM and bare metal.
- Packaging software for on-prem and edge environments using form factors like virtual appliances and containers using tools like Helm charts, Packer, etc.
- Securing clouds (AWS), containers, and Kubernetes
- Securing SDLC pipelines (e.g. using SCA/SAST/DAST tools)
- Experience supporting infrastructure deployed in US Government networks (FedRAMP, CMMC, etc.)
- Experience with SBOM generation tools and formats including Syft, Trivy, CycloneDX, and related vulnerability scanners such as Grype and Trivy.
- Experience with other FOSS and Commercial SDLC security and DevSecOps tooling including SCA, DAST, SAST, etc.
- Experience deploying and supporting self hosted LLMs.
- Understand how to safely expose public endpoints including UI and APIs using load balancers, CDNs, and other tools do deliver robust, secure, highly available services.
- Strong networking and runtime troubleshooting experience including the challenges in debugging lights out, dynamic, complex, remote environments including Kubernetes and airgapped.
Benefits of working @ Manifest
- 🔍 Help organizations get new-found visibility into their software, and be more secure!
- 🌎 Fully remote work (with potential for hybrid co-working)
- 🌴 Unlimited PTO (which we take seriously)
- 🏥 Medical/dental/vision insurance coverage for you and your dependents paid at 100%!
- 💵 Competitive salary & meaningful stock options
- 🏦 401(k) and retirement options
- ⚒️ Help get in at the ground floor of a well-funded, early stage startup!
- 🦄 Additional benefits to come (retirement, holiday gifts, etc.)