Senior Platform Engineer Kubernetes & AWS
Location SFO, CA (Onsite)
Role summary
Kubernetes/Helm deployments, environment management, secrets, networking, certificates, CI/CD, and enterprise identity/RBAC integrations.
Responsibilities
- Build and operate Kubernetes deployments across environments (dev/tst/prd): deployments/stateful services, ingress, scaling, upgrades, runbooks.
- Package and deploy via Helm / Helmfile with environment overlays and release ordering.
- Operate platform dependencies: PostgreSQL + PgBouncer, Redis/Valkey, S3/MinIO, Traefik ingress; support ClickHouse-based analytics where applicable.
- Own CI/CD and developer enablement using GitHub Actions and standard lint/test gates (TS/Python/Go).
- Manage secrets and certificates:
- AWS Secrets Manager configuration and access controls
- SSL certificate creation and lifecycle; upload/manage in AWS Certificate Manager (ACM)
- Artos (Gilead install) deployment ownership via Helm for:
- OnlyOffice, LiteLLM, PropelAuth, Redis, Artos Celery workers, frontend, backend API
- Inference profile configuration, DNS setup, rebranding, smoke tests
- Lead enterprise identity integration:
- Drive Okta onboarding/config, including custom authorization server discussions
- Implement Lambda-based sync AD groups into Artos RBAC/database
- Configure Proofpoint email integration
- Provide ongoing support for Artos integration and continuous performance improvements.
Required skills
- Kubernetes, Docker (multi-stage, non-root), Helm/Helmfile
- AWS IAM + Secrets Manager + ACM + DNS fundamentals
- Operating Postgres (and pooling), Redis, ingress/controllers
- CI/CD with GitHub Actions; strong operational ownership mindset
Nice to have
- Temporal cluster ops experience; observability/analytics stacks (ClickHouse/Langfuse/PostHog) familiarity