DevOps Engineers (AIOps) - API and Kubernetes
DevOps Engineers (AIOps) - API and Kubernetes
dicetek llc5-7 Years
- Posted 5 hours ago
- Be among the first 10 applicants
Job Description
Role Overview
The DevOps Engineer owns the AWA platform's deployment, infrastructure-as-code, CI/CD, and operational reliability. You ensure that every AWA component — from AKS namespaces and KEDA autoscalers to ADLS Gen2 lifecycle policies and Azure Firewall allowlists — is deployed consistently, tested automatically, and operated reliably within THE BANK's Azure UAE environment. You are the guardian of the AWA infrastructure: nothing is deployed manually; everything is reproducible from code.
Key Responsibilities
Technical — Essential
The DevOps Engineer owns the AWA platform's deployment, infrastructure-as-code, CI/CD, and operational reliability. You ensure that every AWA component — from AKS namespaces and KEDA autoscalers to ADLS Gen2 lifecycle policies and Azure Firewall allowlists — is deployed consistently, tested automatically, and operated reliably within THE BANK's Azure UAE environment. You are the guardian of the AWA infrastructure: nothing is deployed manually; everything is reproducible from code.
Key Responsibilities
- Infrastructure as code: Own and maintain all AWA Azure infrastructure in Terraform/Bicep: AKS 5-namespace cluster, ADLS Gen2 accounts with WORM policies, Azure AI Foundry APIM configurations, Azure Firewall allowlists, private endpoints, Key Vault, Container Registry, ExpressRoute peering.
- CI/CD pipeline ownership: Design and maintain Azure DevOps pipelines for all AWA components: container image build → ACR push → Notary v2 signing → AKS deployment; Terraform plan → policy check → apply; Agent Regression Testing gate on every PR.
- AKS operations: Manage the 5-namespace AKS cluster — namespace isolation, Network Policies, Pod Disruption Budgets, KEDA autoscaling rules based on Kafka consumer lag, OPA Gatekeeper admission policies, Workload Identity bindings for all agent pods.
- Container governance: Manage ACR, enforce Notary v2 image signing, configure vulnerability scanning, maintain the approved-image ConfigMap used by OPA Gatekeeper admission control.
- Secret and certificate management: Own Azure Key Vault configuration — access policies per managed identity, automatic TLS certificate rotation, secret rotation schedules, audit of all secret access events.
- Monitoring and alerting: Configure Azure Monitor alert rules and Log Analytics KQL queries for SLA breach, error rate spike, pod crash loop, token budget breach, and Kafka consumer lag; maintain PagerDuty escalation paths.
- Security posture: Work with the AI Security Engineer to implement Azure Policy assignments, Defender for Cloud recommendations, Firewall rule reviews, and Private Endpoint configurations; maintain the AWA network topology diagram.
- Disaster recovery: Maintain and test DR procedures: failover to UAE South replica for ADLS Gen2, Azure AI Foundry PTU → PAYG → DR endpoint routing, Orkes cluster recovery, RTO/RPO validation.
Technical — Essential
- 5+ years DevOps/Platform Engineering; 2+ years on Azure
- Terraform or Bicep — production IaC, not just templates
- Kubernetes / AKS: namespaces, RBAC, Network Policies, Helm charts, Kustomize
- Azure DevOps or GitHub Actions — multi-stage pipelines, approvals, environments
- Azure Monitor, Log Analytics, KQL query language
- Container ecosystem: Docker, ACR, image signing, admission control
- Azure networking: VNet, private endpoints, NSGs, Azure Firewall, ExpressRoute concepts
- KEDA (Kubernetes Event-Driven Autoscaling) or equivalent autoscaling experience
- Azure Key Vault, managed identity, Workload Identity for Kubernetes
- OPA Gatekeeper or Kyverno for Kubernetes policy enforcement
- Kafka / Azure Event Hubs — consumer group management, lag monitoring
- ADLS Gen2, WORM immutable storage, lifecycle management policies
- Azure AI Foundry / APIM — token quotas, rate limiting, backend routing configuration
- Security tooling: Defender for Cloud, Sentinel, Notary v2
More Info
Key Skills
VNet
Kustomize
Log Analytics
KQL query language
Private endpoints
Helm charts
GitHub Actions
Azure Firewall
ExpressRoute
ACR image signing
Admission control
KEDA Kubernetes Event-Driven Autoscaling
NSGs
Network Policies
AKS namespaces
Bicep
Azure Monitor
Azure networking
