Senior DevOps Engineer

Tetra Digital Group — Canada · Posted ~1 hour ago

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Description

Who We Are 🇨🇦Tetra Digital Group is Canada's leading institutional digital asset infrastructure provider, and right now, we're at an inflection point five years in the making. As Canada's first and only regulated digital asset custodian, we've built the institutional foundation the market now demands. We're backed by Urbana Corporation, National Bank, ATB Financial, Wealthsimple, Purpose Unlimited, Shakepay, Shopify, and Coinbase Ventures — some of the most consequential names in Canadian finance and fintech. We operate three interconnected businesses: Tetra Trust, our regulated custody arm and CADD, a compliant on-chain payment rail backed 1:1 by Canadian dollars. In May 2026, we launched CADD — Canada's first CAD-backed stablecoin issued by a regulated financial institution — following approval from Alberta Treasury Board and Finance. It's live on Base, Ethereum, and Tempo today, with Solana next. CoinDesk and BNN Bloomberg covered it as the arrival of Canada's first regulated digital dollar. 🚀 Here's the problem we're actually solving: Canada clears roughly $424 billion every business day, and much of the retail payment infrastructure underneath it was designed in the 1980s. Batch windows. Cut-off times. Weekends off. We're the team replacing that with rails that settle continuously, programmatically, and under real regulatory oversight. We're a team of under 30. The infrastructure we've built punches well above that number, and so does the opportunity ahead. The Role ⚙️You own the ground everything else stands on. Custody doesn't get a maintenance window. Neither does a payment rail. When a Canadian bank settles CADD at 2am or an asset manager needs proof of holdings before a board meeting, our platform is either up and provably correct or we have a very different kind of morning. 🌙 This is a genuine platform ownership role, not a ticket queue. You'll define how we build, deploy, observe, secure, and recover — and you'll do it inside a licensed trust company, which means your infrastructure decisions become audit artifacts and client diligence answers. Terraform that gets read by an auditor hits differently than Terraform that gets read by nobody. Here's the edge, stated plainly: in this industry, an infrastructure failure isn't downtime, it's a headline. 🔥 The graveyard of crypto companies that got custody, key handling, or access control wrong is public, permanent, and instructive. We intend to stay out of it, and we're hiring the person who helps guarantee that. You'll report to [Head of Engineering / CTO] and partner closely with our security, compliance, and operations leads. What You'll Own 🎯Infrastructure as code, end to end. [AWS] estates, [Terraform], environment parity, and the unglamorous discipline of making sure nothing important exists only because someone once clicked it. 🖱️❌CI/CD and deployment safety. Pipelines that make shipping routine and make a bad ship hard. Progressive rollout, fast rollback, meaningful gates.Observability and incident response. Metrics, logs, traces, alerts that mean something at 3am, runbooks a tired human can follow, and blameless postmortems we actually act on.Secrets, access, and key material boundaries. Working alongside security on [KMS/HSM/Vault], least-privilege IAM, credential rotation, and the operational envelope around signing infrastructure.Controls that constrain you, too. 🔐 We're a custodian, so segregation of duties is real. You'll help design peer approval, break-glass procedures, and immutable audit logging — including for your own access. If that sounds like a loss of power rather than a mark of a serious platform, this isn't your role.Resilience and DR. Backup, restore, failover, and the tested confidence that we can bring it all back. Untested DR is a rumour.Compliance evidence, automated. SOC 2-style control evidence generated by the system instead of assembled by a human in a spreadsheet the week before an audit. 📋 What We're Looking For 🔍6+ years in DevOps, SRE, platform, or cloud infrastructure engineering, including production ownership of systems where failure had real consequencesDeep [AWS] (or equivalent cloud) — networking, IAM, multi-account architecture, and the cost side of the houseFluent in infrastructure as code. [Terraform] as a first language, not a copy-paste ritualContainer orchestration — [Kubernetes/ECS] in anger, not in a tutorialReal secrets and identity management experience. You know why "it's in an environment variable" isn't an answerIncident maturity. You've been the one on the bridge, you've written the postmortem, and you've shipped the fix that made that class of failure impossibleYou write code. Not necessarily application features, but scripting and tooling that other engineers rely onCommunication under pressure. You can explain an outage to a compliance officer and a client without either of them feeling managed Crypto experience is a plus, not a requirement. If you've run regulated financial infrastructure at a bank, a payments processor, or a fintech that survived a real audit, you already have the harder half of this job. We'll teach you the chains. Extra points for: 🏆 You've been through SOC 2 Type II, PCI, OSFI-adjacent, or provincial regulatory examination and livedExperience with node infrastructure, MPC, or hardware security modulesYou've built a platform that a small team could operate — force multiplication over clevernessYou have a strong, specific opinion about alert fatigue and you're right What You Get 💼💰 $200,000–$300,000 base salary, commensurate with experience🦷 Comprehensive health, dental, and paramedical coverage🌱 $1,000 annual learning budget for cloud and security certifications, courses, and conferences🏢 Hybrid Toronto — With real flexibility around it🏝️ Generous vacation, and the cultural expectation that you actually take it🇨🇦 A front-row seat to Canada's digital asset transformation — this is a rare opportunity to be part of something that doesn't exist yet👀 A small, high-calibre team where your work is visible, your contributions are felt, and your growth is real A Note on Fit 🧭Tetra moves fast and the expectations are high. We're not a place that slows down to accommodate bureaucracy or process for its own sake. But we're also a licensed trust company, and some things genuinely cannot break. Holding both of those at once is the actual skill. Some honest specifics, because you'll ask in the interview anyway and we'd rather answer now: On-call is real and it's shared. 24/7 market, 24/7 platform, we protect recovery time, and we are explicitly hiring toward a bigger rotation rather than one hero with a phone. 📱You'll inherit some things you didn't build. We're five years in and pragmatic. There is work to clean up, and we'd rather you see it in week one than week ten.You will not be a solo function forever. Platform is on the hiring roadmap beyond this role. If you want to eventually lead it, say so in your application — that's a conversation we're happy to have.You'll be building controls, not just capability. Roughly some of this job is enabling engineers to ship, and some of it is making sure nobody, including you, can do something irreversible alone. Both matter. If you've spent your career waiting for a fully defined job description before getting started, this isn't the right fit. But if you see a gap and fill it, thrive in ambiguity, and take real ownership of outcomes, this role was built for you. If that sounds energizing rather than exhausting, we'd love to hear from you. 🤝 How to Apply ✍️Submit your resume along. Don't meet every bullet? Give us your pitch anyway, we hire for trajectory and judgment, not checklists. Tetra is committed to building a diverse and inclusive team. We encourage candidates from all backgrounds to apply and will provide accommodation throughout the hiring process upon request.