Descrição da vaga
<p>N-iX is looking for <strong>Senior Platform Engineer/EKS </strong>to join the team</p>
<p> </p>
<p><strong>Client Overview:</strong><br>Our client is an Azerbaijani telecommunications company, the largest mobile network operator in Azerbaijan. The main products are: Fixed telephony, Mobile telephony, Internet services, Wireless broadband, and Value-added services.</p>
<p><strong>Project Objectives:</strong><br>The primary goal is to accelerate the client’s Data & AI initiatives via a secure, hybrid cloud foundation on AWS while systematically modernizing the IT estate as part of the cloud migration.</p>
<p> </p>
<p><strong>Key Project Objectives include:</strong></p>
<ul>
<li>Cloud Foundation & Landing Zone: Deploy target hybrid network architectures, establishing a secure Landing Zone and hybrid Data/AI platforms on AWS.</li>
<li>Security, Compliance & Governance: Operationalize on-prem tokenization (achieving zero raw PII in the cloud), resolve policy blockers to include AWS in the ISMS, and establish a Cloud Center of Excellence (CCoE) to govern Cloud adoption.</li>
<li>AI Chatbot & Voicebot Design & Implementation: Develop and operationalize a flagship Customer Care Chatbot and Voicebot as the first hybrid-setup consumer.</li>
</ul>
<p> </p>
<p><strong>Key Responsibilities:</strong></p>
<ul>
<li>Design, provision, and maintain production-grade Amazon EKS clusters across AWS cloud and on-premises environments using EKS Hybrid Nodes with Cilium VXLAN CNI overlay networking.</li>
<li>Implement dynamic node autoscaling and OS lifecycle management using Karpenter and immutable Bottlerocket node images across cloud and hybrid compute nodes.</li>
<li>Configure and manage EMR-on-EKS platform runtimes to execute distributed Big Data and PySpark batch/streaming analytics workloads.</li>
<li>Provision, optimize, and manage specialized GPU node pools (NVIDIA A100/L40S / EC2 GPU instances) for Azerbaijani SLM/LLM model training, fine-tuning, and low-latency speech inference (ASR / TTS voicebot pipelines).</li>
<li>Implement automated GitOps continuous deployment workflows using Argo CD and Helm charts for all Kubernetes platform components and application workloads.</li>
<li>Enforce cluster security, governance, and compliance using Kubernetes admission controllers and policy engines (e.g., OPA / Kyverno) alongside fine-grained Workload Identity (IRSA / Pod Identities).</li>
<li>Build and maintain Infrastructure-as-Code (IaC) templates using Terraform and AWS CDK integrated into GitLab CI/CD pipelines for repeatable cluster lifecycle management.</li>
<li>Implement container microsegmentation, network security policies, and split-horizon DNS resolution across hybrid VPCs and on-premises substrates.</li>
<li>Integrate platform logging, metrics, and trace telemetry with Amazon CloudWatch and central on-premises Splunk / SOC SIEM ingestion pipelines.</li>
<li>Author technical documentation, cluster operational runbooks, disaster recovery (DR) procedures, and platform upgrade playbooks.</li>
</ul>
<p> </p>
<p><strong>Requirements:</strong></p>
<p><strong>Mandatory Technical Skills:</strong></p>
<ul>
<li>4+ years of hands-on experience in Platform Engineering, DevOps, or Site Reliability Engineering with a primary focus on enterprise Kubernetes / Amazon EKS.</li>
<li>Deep expertise with Amazon EKS, including EKS Hybrid Nodes architecture, Cilium CNI (VXLAN), and hybrid networking topologies.</li>
<li>Strong experience in cloud-native autoscaling using Karpenter and container-optimized operating systems (Bottlerocket).</li>
<li>Practical experience setting up and operating EMR-on-EKS for distributed data processing and Spark runtimes.</li>
<li>Hands-on experience with GPU node pool orchestration for AI/ML workloads, LLM/SLM serving, and real-time speech/voicebot inference.</li>
<li>Proficient with GitOps release methodologies using Argo CD, Helm, and automated CI/CD pipelines (GitLab CI).</li>
<li>Solid knowledge of Kubernetes security, admission control (OPA / Kyverno), RBAC, secrets management (HashiCorp Vault / CyberArk), and pod security standards.</li>
<li>Strong proficiency in Infrastructure-as-Code using Terraform or AWS CDK.</li>
</ul>
<p> </p>
<p><strong>Strong Plus (Nice-to-Have Skills):</strong></p>
<ul>
<li>Certified Kubernetes Administrator (CKA) and/or Certified Kubernetes Security Specialist (CKS)</li>
<li>AWS Certified Solutions Architect – Professional or AWS Certified DevOps Engineer – Professional.</li>
<li>Experience in telecom domain infrastructure, low-latency real-time voice/chat processing, or hybrid cloud data sovereignty architectures.</li>
<li>Familiarity with AWS Landing Zone Accelerator (LZA), AWS Transit Gateway, and AWS Lake Formation.</li>
</ul>
<p> </p>
<p><strong>Soft Skills & Team Fit:</strong></p>
<ul>
<li>Strong critical thinking, problem-solving, and analytical skills.</li>
<li>Excellent communication and collaboration skills to work closely with cross-functional teams (Data Engineering, MLOps, Cloud/Network, Security).</li>
<li>Results-oriented, proactive mindset with strong ownership of deliverables within an Agile / Scrum framework.</li>
<li>Upper-Intermediate+ English level (written and spoken).</li>
</ul>
<p> </p><div class="content-conclusion"><p><strong>We offer*:</strong></p>
<ul>
<li>Flexible working format - remote, office-based or flexible</li>
<li>A competitive salary and good compensation package</li>
<li>Personalized career growth</li>
<li>Professional development tools (mentorship program, tech talks and trainings, centers of excellence, and more)</li>
<li>Active tech communities with regular knowledge sharing</li>
<li>Education reimbursement</li>
<li>Memorable anniversary presents</li>
<li>Corporate events and team buildings</li>
<li>Other location-specific benefits</li>
</ul>
<p>*not applicable for freelancers</p></div>