Senior DevOps Engineer

ARCHICOO SOLUTION INCORPORATED
United States
2 months ago

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
$113,152.0 - $200,000.0
Working hours
Regular working hours
Job source

Tech stack

User Authentication Backup Devices Software as a Service Continuous Integration DevOps Lightweight Directory Access Protocols (LDAP) Performance Tuning Security Assertion Markup Language (SAML) Software Engineering Data Logging System Availability Delivery Pipeline
+6 more
Gitlab Kubernetes Terraform Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

We are looking for a senior engineer who owns our GitLab self-managed platform end to end, not someone who has merely used GitLab, but someone who has run it. You will be the technical authority on our self-hosted GitLab environment, responsible for its availability, performance, security posture, and the CI/CD experience of every engineering team that depends on it.

This is a hands-on, deep-specialist role. We are deliberately not hiring a broad DevOps generalist who lists GitLab among ten other tools. We want someone who knows the product intimately, stays current with its fast-moving release cycle, and treats the platform as a product in its own right. You will work in a security-conscious, regulated environment, so we need someone who is comfortable making security a first-class concern in everything they build and who is willing to speak up when something isn’t right.

What You’ll Own

  • The full lifecycle of our self-managed GitLab deployment: upgrades, backups, high availability, capacity planning, and performance tuning.
  • CI/CD pipeline architecture across the organization, including reusable pipeline templates, parent/child pipelines, and integrations with our security scanners and artifact repositories.
  • GitLab Runner fleet management at scale, including shared, group, and project-scoped runners running on a Kubernetes executor on EKS.
  • Authentication and access control across the platform - SSO/SAML/LDAP integration and enterprise-scale group and project permission models.
  • Managing platform configuration as code rather than through the UI, with Terraform as the source of truth., Security is not a separate workstream in this role - it’s built into the platform you operate. You will:

  • Integrate and maintain security and vulnerability scanning (e.g., Wiz, SAST/DAST, dependency and container scanning) directly within CI/CD pipelines, and ensure findings are visible and actionable for engineering teams.
  • Harden the GitLab platform itself: enforce least-privilege access models, manage secrets and CI/CD variables securely, and keep the environment patched and current with security releases.
  • Implement and maintain supply-chain security controls, such as signed artifacts, trusted artifact repositories (JFrog), and policies that prevent untrusted dependencies from entering builds.
  • Support audit, logging, and compliance requirements, and help maintain the platform’s posture against frameworks such as NIST 800-53 in support of FedRAMP/IL5 and ATO obligations.
  • Partner with security and compliance teams to translate control requirements into enforceable, automated platform configuration.

Who You Are Vocal and comfortable speaking up. This is a genuine requirement, not a throwaway line. We need someone who will raise concerns early, flag risks before they become incidents, push back on shortcuts that compromise security or stability, and advocate for the right technical approach, even when it’s not the easiest conversation in the room. Quiet competence isn’t enough here; we need your voice.

  • A specialist at heart. You’d rather know one critical platform deeply than know ten tools superficially.
  • Current. You’ve worked on self-managed GitLab within the last couple of years and keep pace with how quickly the product evolves.
  • Pragmatic and security-minded, with a bias toward automation and codified, repeatable configuration over manual changes., To be clear about the bar for this role: we’re looking for an administrator and platform owner, not an end user. Candidates whose GitLab experience amounts to having used it at a previous company are not a fit. Likewise, generalists who can name many tools but can’t go deep on the operation of any of them won’t be the right match. Because self-managed GitLab changes quickly, we’re specifically looking for people who have administered it hands-on recently.

Requirements

Do you have experience in Terraform?, GitLab self-managed administration. Direct, recent experience administering self-managed GitLab (not GitLab.com SaaS). You have personally handled upgrades, backups, high-availability configurations, runner management, and performance tuning.

  • CI/CD pipeline architecture. You design and maintain reusable pipeline templates and parent/child pipeline structures, and you’ve integrated pipelines with security scanners and artifact repositories. We use JFrog and Wiz; experience with these specifically is a plus.
  • GitLab Runner management at scale. You understand the trade-offs between shared, group, and project-scoped runners, and you’ve operated runners using the Kubernetes executor on EKS.
  • Authentication and access control. You’ve implemented and maintained SAML/SSO/LDAP integration and designed group and project permission models at enterprise scale.
  • Infrastructure-as-code fluency. You’re fluent in Terraform, ideally including the GitLab provider, and you instinctively manage configuration as code rather than clicking through the UI.

Strong Nice-to-Haves

  • GitLab Geo experience, including replication and disaster-recovery scenarios.
  • Container Registry and Package Registry administration.
  • Migration experience such as onboarding organizations into GitLab, or executing major version upgrades on self-managed instances.
  • Hands-on experience integrating GitLab with Kubernetes/EKS for runner workloads and deployment pipelines.
  • Federal or regulated-industry exposure: FedRAMP, IL5, NIST 800-53, and familiarity with the ATO process.

Benefits & conditions

$113,152.21 - $200,000.00 a year - Full-time, Contract, Pulled from the full job description

  • Dental insurance
  • Flexible schedule, If you’ve run GitLab self-managed in earnest, kept it up, kept it fast, kept it secure, and kept its users productive, we want to talk to you.

Pay: $113,152.21 - $200,000.00 per year

Benefits:

  • Dental insurance
  • Flexible schedule

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:14 min

Structuring CI/CD pipelines with integrated security and quality checks

Christoph Ruggenthaler · LIVE

1:33 min

Recapping vital capability shifts across security and enterprise infrastructure

Sergej Reznik Sergej Reznik · Europe 2026 Virtual

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · WWC Europe 2026

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

4:54 min

Implementing geographic salary tiers for compensation equity and fairness

Rudi Bauer Rudi Bauer +1 · Cappuccino with HR

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

Videos

See all

Related articles

See all