Description
CBS group is one of the largest Technology, Information Technology and Telecommunications groups, Key Systems Integrators of the Greek and Cypriot Market, with a powerful presence of 35 years and consists of Cosmos Business Systems SA, Cosmos Consulting, CBS LAN and CBS IT Systems (Cyprus) LTD.
Our company's mission is to provide high quality integrated solutions in technology products and services to meet the needs of Private Business Sector and Public Sector Organizations, investing in people and knowledge, a combination that makes it competitive and efficient.
DevOps / Platform Engineer
📍Location: Hybrid (Athens)
💼Experience:3+ years in a similar role
⏰ Type: Full-time
About the role
We are looking for a DevOps / Platform Engineer to maintain and secure our infrastructure, automate processes, and support our development teams with their deployments.
We run our applications on Kubernetes, both on premises and in the public cloud, using a GitOps approach.
Our wider ecosystem includes Linux servers, CI/CD pipelines, infrastructure as code, monitoring, and a range of self-hosted platform services (databases, messaging, search, identity, and object storage).
Key responsibilities
Kubernetes & GitOps
· Operate and maintain Kubernetes clusters (k3s, kubeadm, AKS, OKE): upgrades, node maintenance, certificates, etcd backups, and capacity management.
· Maintain and extend Helm charts and per-environment values in the GitOps repository.
· Manage Argo CD: app-of-apps, sync policies, drift/OutOfSync troubleshooting, and custom health checks.
· Provision new environments/tenants from scratch (VM → k3s → Argo CD → applications) based on existing runbooks—and improve those runbooks.
Linux & VM operations
· Manage Ubuntu LTS servers: patching/updates, kernel and security upgrades, disk/LVM, systemd, journald, cron, firewalls (ufw/nftables), SSH hardening, and jump hosts.
· Monitor and schedule maintenance (patch windows) with no downtime in production environments.
· Use Bash scripting for operational tasks (secrets bootstrapping, image mirroring, health checks).
CI/CD
· GitHub Actions: build/push images, promotion flows from dev → uat → prd, and update-gitops jobs that update image tags in the GitOps repository.
· Manage container registries (Docker Hub, OCIR, ACR) and image mirroring in closed/air-gapped environments.
· Build linting/validation pipelines for charts and tenant configurations.
Platform services
· Operate self-hosted components: PostgreSQL (Zalando operator), Kafka (Strimzi), Elasticsearch/OpenSearch (ECK), Keycloak, Redis, MinIO/Garage (S3), Milvus, ClamAV, and oauth2-proxy.
· Ingress and networking: Traefik, ingress controllers, TLS certificates, Azure Application Gateway, Cloudflare Tunnel, and DNS.
· Secrets management: External Secrets Operator with Azure Key Vault, sealed/generated secrets, and rotation.
Observability & reliability
· Manage kube-prometheus-stack, Grafana dashboards, alert rules, ServiceMonitors, and log aggregation.
· Handle incident response, root cause analysis, and post-mortems.
· Manage backups and disaster recovery (DR environments, restore drills).
· Infrastructure as Code
· Use Terraform / OpenTofu for cloud infrastructure (currently OCI OKE, with Azure to follow).
· Maintain documentation: initial setup guides, go-live checklists, and break-glass procedures.
Required qualifications
· 3+ years of experience in a DevOps / SRE / Platform Engineering role.
· In-depth knowledge of Linux (Ubuntu/RHEL): troubleshooting from networking to systemd, package management, security updates, and performance analysis (top/iostat/ss/journalctl).
· Production Kubernetes experience: deployments, services, ingress, RBAC, storage classes/PVs, resource limits, probes, HPA, and cluster upgrades.
Confident with kubectl debugging.
· Helm: ability to write and maintain charts (templating, values, helpers), beyond simply running helm install.
· Git and GitOps mindset: all changes go through pull requests; no changes are made manually in the cluster.
· CI/CD: GitHub Actions or an equivalent platform (GitLab CI, Azure DevOps).
· Containers: Docker/OCI images, multi-stage builds, image security, and image size optimization.
· Bash scripting and confidence working on the command line.
· Networking fundamentals: DNS, TLS/PKI, HTTP proxying, firewalls, VPNs, and routing.
· Good command of English (documentation and vendor communication).
Preferred qualifications
· Production experience with Argo CD or Flux.
· Terraform / OpenTofu.
· Experience with Azure (AKS, Key Vault, Application Gateway, NSG) and/or Oracle Cloud (OKE, Object Storage, OCIR).
· Keycloak / OIDC / SAML and integrations with government identity providers.
· Kafka (Strimzi), PostgreSQL or Oracle DB administration, and Elasticsearch/OpenSearch.
· Prometheus/Grafana and alerting design.
· Security hardening, penetration-test remediation, and CIS benchmarks.
· Experience with on-premises deployments in the public sector and/or environments with restricted network access.
· Python or Go for tooling.
We are committed to an inclusive culture that encourages and supports the diverse voices of our employees.
We welcome applications from individuals of all genders, ages, sexual orientations, nationalities, ethnicities, religions, beliefs, and ability status and all other diversity characteristics.
🔒 All submissions will be treated as confidential.
Dear Applicants,
After you submit your application, it will be evaluated by Cosmos Business Systems’ Human Resources Department and, if your academic and professional profile meets the requirements of the position in question, we will contact you to schedule a personal interview.
Cosmos Business Systems, will process your Personal Data in its capacity as Data Controller, according to the information you will find available in the following link:
Privacy Notice for processing personal Data
For any clarification or objection related to the processing of your Personal Data by Cosmos Business Systems, you may contact the Data Controller to the following email address: dpo@cbs.gr