> Markdown version of [/jobs/ext/267675-senior-platform-engineer](https://www.wearedevelopers.com/jobs/ext/267675-senior-platform-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Platform Engineer - **Company:** Bain & Co. - **Location:** Dallas, TX, United States - **Experience:** Expert - **Salary:** $140,875.0 - $192,250.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Microsoft Azure, Code Review, Information Systems, Data Stores, Cursor (Graphical User Interface Elements), Python (Programming Language), Key Management, PostgreSQL, OpenID, Performance Tuning, Query Optimization, Role-Based Access Control, Redis, Prometheus, Security Assertion Markup Language (SAML), Service Development Studio, Session Management, SQLAlchemy, Tripwire, Management of Software Versions, Data Logging, GitHub Copilot, Large Language Models, Multi-Agent Systems, Database Optimization, Kubernetes Helm Charts, Caching, Generative AI, Backend, Fastapi, Pytest, Integration Tests, Kubernetes, Information Technology, Hashicorp, Apache Kafka, Azure AKS, Restful APIs, Dynatrace, Docker, Microservices - **Published:** May 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=e3019f34dbd3931a ## About the Role * Bachelor's degree in Computer Science, Engineering, Information Systems, or a related field (or equivalent practical experience). * 6+ years of experience building and operating backend services, APIs, or platform components in production environments, including on-call responsibility. * Demonstrated experience owning production backend services end-to-end (design, build, test, deploy, monitor, and operate), including on-call operational responsibility. * Production experience building and operating REST and event-driven microservices at scale in a Kubernetes environment. * Experience designing and operating data stores in Postgres, including schema migration practices, query optimisation, and performance tuning. * Experience implementing authentication and authorization systems (JWT, refresh token rotation, RBAC, SAML/OIDC) in production environments. * Demonstrated ability to mentor other engineers and raise engineering standards through code review and shared conventions. ## Description Senior Platform Engineers design and build the shared services that every product and data squad depends on: Auth, RBAC, Session Management, Audit, Notifications, File handling, Search, and more. Our platform runs on Microsoft Azure and Azure Kubernetes Service (AKS). You own your services end-to-end: design, build, test, deploy, monitor, and operate them. You set the standard for how platform services are built and contribute to the engineering standards and conventions that govern the broader estate. You collaborate closely with Security and Infrastructure to ensure services are secure-by-default, observable from day one, and operable under production on-call expectations. WHAT YOU'LL DO Core Platform Service Development, Deployment, and Operations (80%) * Design, build, test, deploy, and operate core platform services to production quality standards (Auth, RBAC, Session, Audit, Notifications, File, Search). * Own service APIs and contracts end-to-end: versioning, backwards compatibility, and consumer impact management across product squads. * Write and maintain Postgres schemas and Alembic migrations using the expand/contract pattern; never ship a breaking schema change without a backwards-compatible transition. * Implement and enforce authentication and authorisation patterns: JWT, refresh token rotation, RBAC, SAML/OIDC, and service-to-service auth where required. * Design and operate Redis-backed patterns: caching, session storage, rate limiting, pub/sub, and distributed lock coordination where needed. * Build and operate event-driven capabilities using Kafka domain events (CloudEvents envelope, schema registry integration) where platform services publish and consume. * Instrument services with structured logs, distributed tracing, and Prometheus metrics from day one using OpenTelemetry and FastAPI instrumentation. * Write and maintain Helm charts for owned services; contribute to Kubernetes manifests in the platform-infra repository (health checks, resource limits, HPA readiness). * Participate in on-call rotation for platform incidents; drive incident response to resolution and maintain runbooks for owned services. Other (20%) * Set and enforce engineering standards for platform service development: testing, observability, security, reliability, and operational hygiene. * Conduct thorough code reviews; enforce standards on PRs and raise the bar for production practices across the platform estate. * Mentor mid-level and junior platform engineers through pairing, design guidance, and ongoing review feedback. * Use AI coding assistants to accelerate service scaffolding, API/router generation, migration drafts, and test creation; review all generated code against production and security standards before committing. * Use LLMs to generate first-draft documentation (runbooks, service docs, API notes) and operational checklists; validate and refine outputs before publishing. * Collaborate with the Security Engineer on Vault integration (Vault Agent Injector) and/or Azure Key Vault, dynamic secrets usage, policy scoping, mTLS policy, and software supply chain security requirements., Backend/Platform Engineering * Strong Python proficiency: FastAPI, Pydantic v2, SQLAlchemy 2.0 async, Alembic, pytest, Ruff, mypy (strict). * Production microservices: REST APIs, event-driven patterns, idempotency, retries, backwards-compatible versioning, and consumer contract discipline. * PostgreSQL: query plan analysis, indexing strategies, partitioning approaches, and schema evolution patterns for high-availability systems. * Redis: caching strategies, session storage, pub/sub, and rate limiting patterns; understands operational trade-offs and failure modes. * Apache Kafka: producing/consuming domain events, CloudEvents envelope conventions, schema registry integration, and consumer group semantics. * Docker: multi-stage builds, non-root containers, image scanning (e.g., Trivy), and secure base-image practices. * Kubernetes: Helm charts, pod lifecycle, probes/health checks, resource requests/limits, and HPA concepts; comfortable operating services on-cluster. * Observability: OpenTelemetry instrumentation, structured logging (structlog), distributed tracing, and Prometheus metrics for FastAPI services; experience with Azure Monitor a plus. * Secrets and security: familiarity with HashiCorp Vault (Vault Agent Injector, dynamic secrets, policy scoping) and/or Azure Key Vault, and secure service-to-service patterns. Generative AI and agentic systems * Uses AI coding assistants (Cursor, GitHub Copilot, or equivalent) to accelerate feature development and reduce repetitive boilerplate; reviews all generated code against production and security standards before committing. * Uses agents to generate first-draft Pydantic schemas, SQLAlchemy models, and FastAPI router skeletons; refines outputs to match domain conventions and security requirements. * Uses LLM assistance to draft unit and integration test cases; validates coverage gaps and supplements with manually authored tests. * Understands how platform services (Auth, RBAC, Audit) interact with the Agent Gateway and what security constraints (permissions, auditability, data minimisation) that interaction requires. General * Treats every service as a production system from the first commit: tests, observability, documentation, and runbooks are not optional. * Communicates blockers early and escalates appropriately; does not quietly struggle for days before raising a risk. * Uses AI tooling to move faster, but applies critical judgement and rigorous review to all generated code and documentation before it enters the codebase. * Keeps runbooks and service documentation current as services evolve; treats operability as part of delivery. * This role follows a hybrid model, requiring in-office presence at least 1 day per week ## Related Videos - [Reducing LLM Calls with Vector Search Patterns - Raphael De Lio (Redis)](https://www.wearedevelopers.com/videos/1714-reducing-llm-calls-with-vector-search-patterns-raphael-de-lio-redis) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Empowering Thousands of Developers: Our Journey to an Internal Developer Platform](https://www.wearedevelopers.com/videos/1519-empowering-thousands-of-developers-our-journey-to-an-internal-developer-platform) - [Accelerating Authentication Architecture: Taking Passwordless to the Next Level](https://www.wearedevelopers.com/videos/733-accelerating-authentication-architecture-taking-passwordless-to-the-next-level) - [Platform Engineering vs. DevOps Why not both?](https://www.wearedevelopers.com/videos/885-platform-engineering-vs-devops-why-not-both) ## Related Articles - [20 Essential Tools For Backend Development](https://www.wearedevelopers.com/magazine/218-20-essential-tools-for-backend-development) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [The 7 Most Popular Backend Frameworks for Developers](https://www.wearedevelopers.com/magazine/403-the-7-most-popular-backend-frameworks-for-developers) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)