DevOps Engineer, Terraform, Kubernetes, Cloud, Azure, AWS, GCP.
Our client is a Global organisation providing services to the aviation industry and has a requirement for a DevOps Engineer. The DevOps Engineer owns the pipeline layer that turns code in a repository into provisioned, governed, observable infrastructure and applications. The role builds and maintains the continuous integration and continuous delivery platform, defines the standard pipeline patterns that every workload follows, and engineers the policy and security gates that prevent unsafe change from reaching production.
This role is critical to closing a current operational gap. Manual portal driven deployment has accumulated drift, weakened auditability, and exposed the estate to risks that disciplined pipeline engineering eliminates by default. The DevOps Engineer makes the repository, the pipeline, and the policy engine the only path to production, and engineers that path so it is fast, predictable, and safer than the manual alternative.
The role is a key partner to the Cloud Platform Engineer for Infrastructure as Code pipelines, to the Cybersecurity team for security gates, to the FinOps Engineer for cost gates, and to application engineering for application delivery pipelines. The pipeline platform is provider agnostic and must support workloads on the primary Azure estate, the AWS secondary estate, and a future Google Cloud Platform footprint if and when workloads require it. The DevOps Engineer also owns the developer experience of the pipeline platform, ensuring that workload teams find the standard path to be the easiest path.
Experience Required:
The main skills required for this role are strong DevOps experience with Terraform, Kubernetes and Cloud experience (ideally Azure and AWS with GCP as desirable) together with a combination of some of the following:
GitHub Enterprise and GitHub Actions:
Production experience operating GitHub Enterprise and authoring GitHub Actions workflows and composite actions.
Pipeline tooling:
Working knowledge of policy as code (Open Policy Agent, Conftest, Gatekeeper), IaC validation (tflint, Checkov, tfsec), Snyk across IaC, SAST, SCA, and container scanning, secrets scanning, and web application Firewall (WAF) concepts.
Containers:
Solid Docker and OCI image practice including multi stage builds, image signing, and registry operations.
AKS and Kubernetes:
Production experience operating private Azure Kubernetes Service clusters, including Azure CNI Overlay with Cilium, node pool design, workload identity, and the Container Storage Interface (CSI), with deployment through Helm, cert-manager, and ArgoCD GitOps, or Flux.
Scripting and automation:
Proficiency in Bash or PowerShell, with day to day command line fluency in Azure CLI, kubectl, and git for pipeline and platform operations.
Azure platform experience (primary):
Strong production experience engineering infrastructure and pipelines against Azure, including Terraform and Terragrunt against the azurerm, azuread, and azapi providers with Azure Verified Module (AVM) wrappers; Azure governance through management groups, Azure Policy, RBAC, and Privileged Identity Management (PIM); Entra ID groups, app registrations, OpenID Connect federation, and workload identity federation; and core networking including hub and spoke topology, Azure Firewall, Private DNS, Private Link, the ExpressRoute gateway, and Application Gateway WAF_v2.
Data and PaaS services:
Working experience operating Azure Container Registry (ACR), Key Vault, PostgreSQL Flexible Server, Cosmos DB for MongoDB vCore, and Azure Data Lake Storage Gen2 (ADLS Gen2), including data migration tooling for moving workloads onto these services.
Observability:
Working experience instrumenting services with OpenTelemetry and operating Grafana Cloud, Log Analytics, and Kusto Query Language (KQL) for logs, metrics, and alerting.
Backup and disaster recovery:
Working experience with Velero for Kubernetes backup and restore, and with point in time recovery (PITR) and restore procedures for databases and stateful workloads.
DNS and edge security:
Working experience managing Cloudflare DNS, Tunnel, Access, WAF, and Load Balancing as code through Terraform.
AWS pipeline experience (secondary):
Working production experience engineering pipelines against AWS including OpenID Connect federation, Identity and Access Management role assumption, and the AWS specific GitHub Actions patterns. Required at working level.
Google Cloud Platform awareness (emerging):
Working familiarity with GCP pipeline patterns is desirable. The organisation is not currently operating GCP at scale, so this is treated as upside rather than a hard requirement.
Certifications:
GitHub Actions certification desirable. Azure DevOps Engineer Expert (AZ-400) desirable for Senior. AWS Certified DevOps Engineer Professional desirable for Senior. Certified Kubernetes Administrator desirable.
Pipeline metrics:
Familiarity with DORA metrics and engineering them into the pipeline platform itself.
Security awareness:
Understanding of supply chain security including SBOMs, image signing, and provenance attestation.