Description
About the Company
Join Us in Shaping the Future of Digital Assets in Thailand!
Be Part of a Licensed Startup Ready to Revolutionize the Industry
Tokenomics Co., Ltd.
is a fully licensed digital asset business operating under the regulatory supervision of the Securities and Exchange Commission (SEC) of Thailand.
The company is currently preparing for its official operational launch and is looking for passionate, driven individuals to join us on this journey.
As an early member of the team, you will have the unique opportunity to pioneer and build a forward-thinking organization from the ground up.
If you are ready to be part of the new wave in Thailand's digital asset industry, we invite you to build the future together.
Roles & Responsibilities
The Senior DevOps Engineer will be primarily responsible for designing, building, and maintaining Tokenomics' entire digital asset platform infrastructure on AWS using Terraform (IaC), GitHub Actions (CI), ArgoCD (CD), and HashiCorp Vault (Secret Management).
You will work closely with the Tech Lead, Engineering team, and IT Governance team to ensure the system is stable, secure, production-scalable, and fully compliant with SEC regulatory requirements for digital asset businesses.
Infrastructure as Code - Terraform
Design and develop Infrastructure as Code using Terraform covering all AWS resources, including VPC, ECS/EKS, RDS, SQS, SNS, CloudFront, and Route 53.Define Terraform Module standards, Project Structure, and State Management (Remote State, State Locking) to enable efficient infrastructure development and maintenance.Ensure infrastructure code has adequate test coverage and undergoes a code review process before applying.Manage multiple environments (Development, Staging, Production) to maintain consistency and safely promote changes.Monitor AWS costs and optimize resource utilization for cost-efficiency without compromising system stability.
CI Pipeline - GitHub Actions
Design and maintain CI pipelines using GitHub Actions, covering Build, Unit Test, Integration Test, SAST, Dependency Scanning, and Docker Image Build.Establish Reusable Workflow and Composite Action standards for engineers to reuse consistently across all repositories.Manage GitHub Actions Runners (Self-hosted or GitHub-hosted) to ensure optimal performance and adherence to company security standards.Define Branch Protection Rules, Required Status Checks, and Review Policies for safe and auditable merge processes.Manage Container Registry (ECR), including Image Tagging Strategy, Vulnerability Scanning, and Lifecycle Policies.
CD Pipeline - ArgoCD
Design and maintain GitOps workflows using ArgoCD covering deployment of all microservices to Kubernetes Clusters on AWS EKS.Define Application Structure in ArgoCD, including App of Apps Pattern, Sync Policies, and Health Checks for each service.Manage Helm Charts and Kustomize Overlays across environments to align with Terraform-managed infrastructure.Oversee Rollout Strategies (Blue/Green, Canary) and Rollback Procedures to prevent deployment disruptions to users and trading systems.Configure ArgoCD RBAC and SSO Integration to enforce access control based on the Principle of Least Privilege.
Secret Management - HashiCorp Vault
Design and maintain High Availability HashiCorp Vault Clusters on AWS, featuring Auto Unseal via AWS KMS and Audit Logging.Define Secret Engines, Policies, and Auth Methods (Kubernetes Auth, AWS IAM Auth) for each service and environment.Perform routine secret rotations and configure Dynamic Secrets for Database Credentials, AWS Credentials, and third-party API Keys.Collaborate with the IT Governance team to ensure secret management aligns with SEC requirements and international standards such as ISO 27001.Create documentation and runbooks for Break-Glass procedures and emergency Vault recovery.
MongoDB Atlas - Operations
Manage MongoDB Atlas Clusters, including Cluster Sizing, Replica Set Configuration, Auto Scaling, and AWS VPC Network Peering.Maintain backup strategies, Point-in-Time Recovery, and conduct quarterly data recovery drills.Configure MongoDB Atlas Alerts, Performance Advisor, and real-time monitoring connected to the team's observability system.Manage Atlas Network Access, IP Whitelisting, and Private Endpoints to ensure maximum database access security.Coordinate with developers to review Index Strategies and Query Performance to prevent production performance issues.
Observability and Incident Response
Implement an end-to-end Observability system covering Metrics (CloudWatch, Prometheus), Logging (CloudWatch Logs, ELK Stack or equivalent), and Tracing (AWS X-Ray or OpenTelemetry).Design Alert Rules and On-call Runbooks for critical events such as system outages, service degradation, or high database latency.Act as Incident Commander during critical production incidents, collaborating with the Tech Lead and team to resolve issues and report outcomes.Prepare Post-mortem Reports following major incidents and systematically follow up on Root Cause Analysis (RCA), while supporting regulatory incident reporting to the SEC when required.
Security and Compliance
Maintain AWS Security Baseline, covering IAM Policies (Least Privilege), Security Groups, VPC Flow Logs, AWS Config, CloudTrail, and GuardDuty.Collaborate with the IT Governance team to ensure infrastructure complies with SEC IT regulations for digital asset operators.Support annual Vulnerability Assessments and Penetration Testing per regulatory cycles, as well as re-assessments during major system modifications.Support audit readiness by keeping access logs, technical documentation, and change logs accurate and up to date.
Team Development and Standards
Establish DevOps Best Practices, Runbooks, and Standard Operating Procedures (SOPs) for the team.Mentor Junior and Mid-level DevOps Engineers on AWS, Kubernetes, Terraform, and Security.Work with the Tech Lead to align the Infrastructure Roadmap with the Engineering Roadmap and regulatory deadlines.Evaluate and propose new tools or services to enhance platform stability or efficiency.
Qualifications
Education and Experience
Bachelor’s degree or higher in Computer Science, Software Engineering, Computer Engineering, or a related field.Minimum 5 years of experience in DevOps, Platform Engineering, or Site Reliability Engineering.Prior experience in high-stability production environments such as FinTech, Digital Assets, Cryptocurrency Exchanges, or regulated financial industries is preferred.
Technical Expertise
Deep proficiency in AWS, covering Networking (VPC, Transit Gateway, PrivateLink), Compute (ECS, EKS, Lambda), Storage (S3, EFS), Messaging (SQS, SNS, EventBridge), and Security (IAM, KMS, Secrets Manager).Production-level experience with Terraform or other IaC tools (Pulumi, CDK), with the ability to code in TypeScript, Python, or Go.Advanced Kubernetes skills covering Cluster Management, Networking (Service Mesh, Ingress), Resource Management, RBAC, and Helm.Hands-on experience with GitHub Actions for complex CI pipelines, including Reusable Workflows and Self-hosted Runners.Hands-on experience with ArgoCD or other GitOps tools for microservice CD pipeline management.Practical experience with HashiCorp Vault, including setup, policy management, secret engines, and integration with Kubernetes/AWS.Production experience with MongoDB Atlas operations.Scripting proficiency in Bash, Python, or Go for operational automation.Basic understanding of Blockchain technology and digital asset trading platforms is an advantage.
Leadership & Collaboration
Ability to collaborate effectively with Tech Leads, Engineering teams, and IT Governance teams by balancing developer infrastructure needs with regulatory requirements.Strong communication skills, with the ability to convey infrastructure challenges and solutions clearly to non-DevOps team members.Experience producing thorough, actionable documentation and runbooks.Prior experience collaborating with Compliance, Legal, or Regulatory stakeholders is an advantage.
Personal Attributes
Strong security mindset—prioritizing security in every infrastructure decision.High accountability for system reliability, willing to be on-call for emergency situations when needed.Passionate about automating repetitive tasks and continuously seeking process improvements.Keen interest in the digital asset and blockchain industry, actively keeping up with trends.Proficient Thai language skills (spoken and written), as internal communication and documentation are primarily in Thai.Intermediate English language proficiency—able to read technical documentation and communicate with international vendors.
Working Conditions
Probation and Benefits
90-day probation period.Flexible Hybrid Work Arrangement (On-site 60% : Remote 40%).Health Insurance.Performance-based Bonus & Equity Options (Details provided during the offer stage).
Office Location
The RICE Building: 1467/8 (14th Floor), Saphan Khwai Intersection, Phahonyothin Road, Bangkok.Close to BTS Green Line (Saphan Khwai Station)