Backend & Infrastructure Engineer Expert SAP Green Token
Role details
Job location
Tech stack
Job description
At SAP, we keep it simple: you bring your best to us, and we'll bring out the best in you. We're builders touching over 20 industries and 80% of global commerce, and we need your unique talents to help shape what's next. The work is challenging - but it matters. You'll find a place where you can be yourself, prioritize your wellbeing, and truly belong. What's in it for you? Constant learning, skill growth, great benefits, and a team that wants you to grow and succeed.
What you`ll do
We are looking for a Backend & Cloud Infrastructure Engineer Expert (f/m/d) who brings deep backend development skills together with hands-on Infrastructure-as-Code expertise. You will own microservices end-to-end - from writing production-grade code to provisioning and operating the cloud platform that runs them. Your mission: make every deployment predictable, every environment reproducible, and every service production-ready.
You operate at the intersection of software engineering and cloud platform operations. On any given day you might be building a new microservice, tuning a Helm chart's rollout strategy, refactoring a Terraform module, or hardening a CI/CD pipeline. You are the person who ensures that what works locally works identically across all environments - from dev through production.
- Design and build microservices and REST APIs
- Write robust automated tests - unit, service-layer, and API-level
- Integrate with relational databases, optimizing queries and managing persistence layers.
- Participate in code reviews and uphold established coding guidelines.
- Own and evolve Terraform modules for the full platform topology: Kubernetes clusters, networking (VPC, NAT, DNS), managed databases, message brokers, CI/CD infrastructure, and cloud-provider services.
- Manage multi-environment deployments (dev, test, staging, production) with proper state management, secret handling, and drift detection.
- Maintain and extend Helm charts - service deployments, autoscalers (HPA), network policies, ingress/gateway routing, TLS certificates, PodDisruptionBudgets, and service accounts.
- Operate Kubernetes clusters - service mesh, certificate management, message queue operators, resource sizing, and zero-downtime rolling updates.
- Build and maintain CI/CD pipelines
- Implement and enforce security practices
- Automate cloud operations - environment provisioning, role/permission assignment, tenant onboarding, and landscape cloning via scripts.
Requirements
- 5+ years combining backend development and infrastructure/DevOps engineering.
- Strong proficiency in a modern Java/Spring Boot, transactional semantics, REST API design, automated testing.
- Production Terraform experience (3+ years) - modular architecture, remote state, per-environment configurations, plan/apply workflows, state migrations.
- Kubernetes - deployments, services, HPA, PDB, network policies, RBAC, service mesh concepts, cert-manager.
- Major cloud platform (GCP, AWS, or Azure) - managed Kubernetes, networking, IAM, container registries, DNS.
- CI/CD pipeline engineering - Jenkins, GitHub Actions; Docker image builds; automated quality gates.
- Secrets management - SOPS, Vault, Sealed Secrets, or similar encryption-at-rest tooling.
- Networking fundamentals - DNS, TLS/mTLS, ingress routing, network policy design.
What we consider beneficial:
- Experience with SAP BTP, Cloud Foundry
- HANA or other SQL DB
- RabbitMQ / Kafka - operator-based deployment on Kubernetes, messaging reliability.
- Istio or similar service mesh - traffic management, observability, mTLS policies.
- Gradle - multi-module build configuration at monorepo scale.
- Monitoring & observability - Prometheus, Grafana, cloud-native monitoring, structured logging, alerting.
- GitOps practices - declarative infrastructure, drift reconciliation, PR-based deployment workflows.
- Cost optimization - resource right-sizing, autoscaling strategies, committed-use planning.
- Compliance & security hardening - private endpoints, image scanning, supply-chain security tooling.