Staff Engineer I, DevOps Engineering​

bain

New Delhi 7 Years Exp Posted 10d ago

Job Description

  • Own the design and evolution of cloud infrastructure built on Terraform and Terraform Cloud. Define the module structure, state strategy, and remote backend conventions the rest of the team builds against.
  • Architect Azure networking end to end: VNet/subnet topology, private endpoints, DNS resolution, NSG design, and Front Door Premium configuration across dev, demo, and production.
  • Set the standard for provisioning Azure platform services (App Services, Azure SQL, Azure OpenAI, Container Registry (e.g. Azure Container Registry, Cloudsmith), Key Vault, Entra ID, Storage Accounts / ADLS Gen2) and ensure environment parity by design.
  • Own the automation roadmap for the team: identify manual, repetitive operational work, own the backlog of it, and drive it toward self-service and infrastructure-as-code so operational load trends down over time.
  • Partner with Bain's central cloud and infrastructure teams to shape shared processes, tooling, and standards for operational work.

Cloud & Platform Management (Azure) – 20%

  • Own Azure Kubernetes Service (AKS) architecture, including node pools, scaling strategy, spot instance usage, and workload connectivity to dependent services (databases, storage, AI services).
  • Define identity and access architecture: Entra ID app registrations, managed identities, RBAC model, and integration with external IdPs (Okta).
  • Set infrastructure standards for database platforms (Azure SQL Serverless, PostgreSQL Flexible Server, Cosmos DB), including connectivity, Entra auth, firewall rules, and private endpoints.
  • Ensure platform reliability and robust access controls across all environments, and act as the senior escalation point for platform-level issues.

CI/CD & Software Delivery – 15%

  • Define and own the CI/CD strategy using GitHub Actions for container builds, infrastructure deployments, and application releases, setting the patterns other engineers extend.
  • Establish the container image lifecycle standard: build, scan, push to a container registry (e.g. Azure Container Registry, Cloudsmith), and deploy to AKS or App Services.
  • Design environment promotion workflows with appropriate gating, secrets management (Key Vault), and rollback strategies.
  • Architect and operate GitHub-hosted private runners where required, including network integration with Azure VNets.

Monitoring, Security & Assurance – 15%

  • Own the observability strategy using the team's monitoring stack (e.g. Datadog, Azure Application Insights). Define what the team monitors, alerts on, and how it optimizes cost and reliability.
  • Lead the response to security findings: triage, containment, IAM scoping, container image CVE remediation, and endpoint hardening, and set the remediation standards others follow.
  • Lead L2/L3 incident escalations, including root-cause analysis, user journey tracing, and log analysis, and drive the improvements that prevent recurrence.
  • Define and enforce solution compliance across products: network isolation, least-privilege access, secrets hygiene, and deployment guardrails.
  • Own the developer experience: set the standard for local development environments and deployment documentation so engineers across the distributed team can onboard quickly and operate with minimal infrastructure friction.

Technical Leadership & Team Development – 20%

  • Own the design and evolution of cloud infrastructure built on Terraform and Terraform Cloud. Define the module structure, state strategy, and remote backend conventions the rest of the team builds against.
  • Architect Azure networking end to end: VNet/subnet topology, private endpoints, DNS resolution, NSG design, and Front Door Premium configuration across dev, demo, and production.
  • Set the standard for provisioning Azure platform services (App Services, Azure SQL, Azure OpenAI, Container Registry (e.g. Azure Container Registry, Cloudsmith), Key Vault, Entra ID, Storage Accounts / ADLS Gen2) and ensure environment parity by design.
  • Own the automation roadmap for the team: identify manual, repetitive operational work, own the backlog of it, and drive it toward self-service and infrastructure-as-code so operational load trends down over time.
  • Partner with Bain's central cloud and infrastructure teams to shape shared processes, tooling, and standards for operational work.
  • Cloud & Platform Management (Azure) – 20%

  • Own Azure Kubernetes Service (AKS) architecture, including node pools, scaling strategy, spot instance usage, and workload connectivity to depend

Similar Openings for You