职位详情
国籍要求:马来西亚
职位描述
🎯 Key Responsibilities
1. Infrastructure as Code (IaC) & Automation
Provision Everything as Code: Design and maintain all AWS resources (VPCs, IAM, RDS, EKS) using Terraform or AWS CDK.
Modular Architecture: Build reusable IaC modules to ensure consistency across Dev, Staging, and Production environments.
Eliminate Drift: Implement automated detection to ensure the live environment always matches the code repository.
2. Kubernetes (EKS) Orchestration
Cluster Management: Manage the full lifecycle of AWS EKS clusters (upgrades, scaling, and networking).
Scaling & Efficiency: Implement Karpenter for high-performance node auto-scaling and cost-efficient compute selection.
GitOps Delivery: Deploy and manage Kubernetes workloads using GitOps tools like ArgoCD or Flux.
3. DevSecOps & Compliance
Policy as Code: Implement guardrails using OPA (Open Policy Agent) or Kyverno to prevent insecure configurations.
Secret Management: Securely manage application secrets using AWS Secrets Manager or HashiCorp Vault integrated into EKS.
Compliance: Ensure the platform remains compliant with ISO27001 and SOC2 via automated auditing and patching.
4. FinOps & Observability
Cost Governance: Track and optimize EKS spend using Kubecost or AWS Cost Categories.
Monitoring: Build and maintain an observability stack using Prometheus, Grafana, and OpenTelemetry.
🛠️ Technical Requirements
Must-Haves (The Core)
Experience: 3+ years in Cloud Engineering/DevOps with a heavy focus on AWS.
Linux Administration: Strong foundational knowledge of Linux operating systems, covering core system administration, shell scripting (Bash/Zsh), system performance tuning, and low-level troubleshooting.
Networking Fundamentals: Solid grasp of core networking concepts essential for distributed cloud environments, including TCP/IP, DNS, HTTP/HTTPS, subnetting, routing, firewalls, and load balancing.
IaC Expert: Professional experience with Terraform (preferred) or Pulumi/CDK.
K8s Deep Dive: Hands-on experience managing production EKS clusters, including VPC CNI, Security Groups for Pods, and IRSA.
Scripting: Proficiency in Python or Go for building custom automation tools.
CI/CD: Experience building pipelines in GitLab CI, GitHub Actions, or Jenkins.
Nice-to-Haves
Service Mesh: Experience with Istio or Linkerd for mTLS and traffic management.
Certifications: CKA (Certified Kubernetes Administrator) or AWS DevOps Engineer Professional.
Security: Familiarity with Trivy or Snyk for container and IaC vulnerability scanning.