Mid DevOps Engineer (Security and Reliability)
6000 - 8000 EUR/ mies.B2B
MidFull-time·B2B
#435436·Dodano wczoraj·1
Źródło: PhysitrackTech Stack / Keywords
AWSEnvoyWAFnginxCloudflareModSecurityCorazaKubernetesEKSTerraform','PostgreSQL','RDS','Typesense','MongoDB','ElastiCache','Grafana','Loki','Prometheus','Sentry','PagerDuty
Firma i stanowisko
Physitrack PLC builds digital health software used by clinicians, physiotherapists and employers in over 100 countries. Their two product lines, Physitrack (exercise prescription, telehealth and patient engagement) and Champion Health (workplace wellbeing), run on a multi-region AWS platform serving Europe, the UK, North America, Australia and the Middle East. The company is ISO 27001:2022 certified and holds clinical data and a large proprietary content library.
Wymagania
Essential:
- 5+ years of experience in infrastructure, SRE, or security engineering with strong AWS expertise
- Real experience with edge, WAF, or reverse proxy technologies such as Envoy, nginx, Cloudflare, ModSecurity, or Coraza
- Production experience with Kubernetes, ideally EKS, and strong experience with Terraform
- Experience operating PostgreSQL at scale, including upgrades and performance optimization
- Practical observability experience including building effective alerting systems
- Security engineer mindset focused on anticipating attacker behavior
- Professional working proficiency in English
Nice to have:
- Experience with search infrastructures such as Typesense, Elasticsearch, OpenSearch, or vector search
- Experience with content protection and anti-scraping measures
- Experience supporting ISO 27001, SOC 2, or similar audits from the technical side
- Experience in healthcare, fintech, or other regulated domains
- Polish language skills, as much of the engineering team is in Poland (company works in English)
Obowiązki
Edge and network security:
- Own the Envoy based edge, including WAF rules, rate limiting, and bot management across cloud and CDN layers
- Design and tune protections against abuse such as content scraping, credential attacks, and traffic anomalies
- Build detection systems for important traffic patterns and continuously improve signal to noise ratio
Cloud security posture:
- Harden the AWS estate covering IAM boundaries, least privilege access, threat detection, and runtime monitoring on EKS
- Manage secrets, certificates, and token lifecycle across the platform
- Produce infrastructure evidence to support ISO 27001 audits, penetration tests, and enterprise security reviews
Data platform:
- Run PostgreSQL and RDS in production across regions including upgrades, performance, encryption, and access control
- Own search infrastructure including Typesense and vector search end to end
- Work with MongoDB and ElastiCache alongside primary data stores
Observability:
- Own the monitoring platform: Grafana, Loki, Prometheus, Sentry, and PagerDuty
- Build trusted alerting with meaningful thresholds, low noise, and clear runbooks
- Improve log and metric flow from edge and application into the observability stack
Benefity
- Fully remote work while based in Poland
- Participation in 24/7 on-call rotation via PagerDuty with separate compensation
- Flexible working hours and autonomy to set own schedule and tools
- Documentation practices including threat models, decision records, and runbooks
- Small, autonomous team environment with wide scope and minimal process
Elastyczne godziny
Physitrack
3 aktywne oferty