> Markdown version of [/jobs/ext/2711273-infrastructure-engineer](https://www.wearedevelopers.com/jobs/ext/2711273-infrastructure-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Infrastructure Engineer - **Company:** BlackSky Technology Inc. - **Location:** Herndon, VA, United States (Remote available) - **Experience:** Expert - **Salary:** $135,000.0 - $150,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Bash Shell, Continuous Integration, DevOps, Elasticsearch, Identity and Access Management, Python (Programming Language), Key Management, Linux System Administration, Octopus Deploy, OpenShift, Public Key Infrastructure, Role-Based Access Control, Logstash, Prometheus, Runbook, Tripwire, Ceph (Software), Data Logging, Scripting, Fluentd, Istio, Grafana, Kubernetes Helm Charts, Kubernetes, Rancher, Terraform - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/senior-infrastructure-engineer-blacksky-8408796 ## About the Role * At least five years years in infrastructure, platform, DevOps, or SRE engineering, with at least 3 years running Kubernetes in production. * Bachelor's degree in a relevant field of study or equivalent experience (four years). * Strong hands-on AWS experience across networking, compute, storage, and IAM, including hybrid/on-prem connectivity patterns. * Production experience operating Kubernetes in one or more enterprise distributions - Amazon EKS, Rancher/RKE2, or OpenShift 4. * Demonstrated GitOps experience with Argo CD (or Flux) as the primary deployment mechanism. * Proficiency authoring and maintaining Helm charts, and a solid grasp of Kubernetes primitives (workloads, networking, RBAC, storage, CRDs/operators). * Experience with the Kubernetes Operator deployment model - deploying and managing workloads via operators and CRDs (OLM/OperatorHub). * Strong infrastructure-as-code skills, ideally with Terraform. * Comfort with Linux systems administration and scripting (Bash, plus Python or Go). * Experience building on hardened, non-CVE / zero-known-vulnerability base images (e.g., Chainguard, Iron Bank, or distroless/minimal baselines) and supply-chain security practices. * Production monitoring and observability with Prometheus and Grafana (exporters, PromQL, alerting, dashboards). * Clear written and verbal communication, and the ability to work independently across the full lifecycle of a platform component., * Breadth across all three of EKS, Rancher/RKE2, and OpenShift 4, with the ability to move fluidly between them. * Experience running Kubernetes in edge / resource-constrained environments (e.g., k3s), including the operational tradeoffs of lightweight and disconnected deployments. * Direct experience packaging and deploying into air-gapped / disconnected environments using Zarf, image mirroring, and private registries. * Container and image scanning experience (Trivy, Grype, Clair, or equivalents) integrated into CI/CD and registry workflows. * Familiarity with secrets management (Vault, External Secrets Operator) and PKI/certificate automation. * Experience with persistent storage at scale (Ceph, EBS/EFS-backed storage classes). * Hands-on OpenTelemetry (OTEL) experience - instrumenting services, running the OTEL Collector, and standardizing traces, metrics, and logs across the platform. * Centralized log aggregation and analysis with Elasticsearch / OpenSearch (and shippers such as Fluent Bit, Fluentd, or Logstash). * Background supporting regulated, government, or other compliance-driven programs. * Service mesh experience with Istio (traffic management, mTLS, ingress/egress gateways, and observability integration). * Relevant certifications (CKA/CKAD/CKS, AWS Solutions Architect / DevOps Engineer, Red Hat OpenShift, Rancher). ## Description * Design and operate AWS infrastructure (VPC, subnets, NLB/ALB, IAM, EKS, EC2, S3, Route 53) and the hybrid connectivity that ties cloud to on-premises and private/air-gapped networks. * Stand up and run production-grade Kubernetes clusters on EKS, Rancher (RKE2) and/or Red Hat OpenShift 4, including upgrades, capacity planning, networking, storage, and day-2 operations. * Implement and own GitOps workflows with Argo CD - declarative cluster and application state, app-of-apps patterns, sync policies, drift detection, and progressive rollout strategies. * Author, version, and maintain Helm charts for internal and third-party workloads, including values management, chart dependencies, and templating standards across environments. * Build repeatable delivery into disconnected environments using Zarf (and equivalent packaging/mirroring tooling) - bundling images, charts, and manifests for air-gapped installs and reproducible deployments. * Codify infrastructure and platform configuration as code (Terraform, Helm, Kustomize) with a clear build-once / promote-per-environment strategy. * Build and harden CI/CD pipelines that move artifacts safely from dev through to restricted production and BCP targets. * Integrate platform services - certificate management (cert-manager), secrets management, container registries, storage, and observability - as shared, reusable building blocks. * Establish operational standards: monitoring, alerting, logging, runbooks, incident response, and capacity/cost management. * Other responsibilities as assigned. ## Related Videos - [How I saved 200K/yr in direct costs writing 0 code lines in K8s](https://www.wearedevelopers.com/videos/1055-how-i-saved-200k-yr-in-direct-costs-writing-0-code-lines-in-k8s) - [Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves](https://www.wearedevelopers.com/videos/100220-rate-limiting-using-ebpf-and-istio-how-to-protect-your-saas-customers-from-themselves) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [My journey into DevOps world - How it all started!](https://www.wearedevelopers.com/videos/545-my-journey-into-devops-world-how-it-all-started) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Learning Kubernetes made easy with KubeCampus](https://www.wearedevelopers.com/magazine/348-learning-kubernetes-made-easy-with-kubecampus) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [DevOps Engineer Salary [2023]](https://www.wearedevelopers.com/magazine/203-devops-engineer-salary-2023) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence)