Senior DevOps Engineer - Security and Reliability

Physitrack — Poland · Posted ~2 hours ago

Senior Contract Remote EUR 8000/month

Skills

DevOps Site Reliability Engineering Cloud security AWS Infrastructure security Observability Multi-region cloud infrastructure Security controls Cloud posture management Audit compliance SRE ISO 27001

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A fully remote senior DevOps and reliability role focused on securing and operating a multi-region AWS environment. You will design edge controls, strengthen cloud security posture, improve observability, protect sensitive data infrastructure, and provide evidence of controls for audits and enterprise requirements.

Highlights

Fully remote senior role based in Poland with a B2B contract and EUR 8,000 monthly compensation. The position offers ownership of security and reliability across a multi-region cloud environment, including infrastructure hardening, observability, and audit readiness.

Description

Physitrack PLC Fully remote, based in Poland Contract: B2B contractor, EUR 8,000 per month About Us Physitrack PLC builds digital health software used by clinicians, physiotherapists and employers in over 100 countries. Our two product lines, Physitrack (exercise prescription, telehealth and patient engagement) and Champion Health (workplace wellbeing), run on a multi-region AWS platform serving Europe, the UK, North America, Australia and the Middle East. We are ISO 27001:2022 certified. We hold clinical data and a large proprietary content library, and both need defending properly. The role You will own the security and reliability surface of our infrastructure: the edge, the data layer, and the observability stack that tells us when either is misbehaving. It sits where security engineering meets SRE. You will design controls at the edge, harden our cloud posture, make sure we can see what is happening across a multi-region estate, then evidence all of it to auditors and enterprise customers. This is hands-on engineering, not a governance role. We are recruiting two senior infrastructure roles. This one covers the edge, observability and cloud security posture. The other, Senior DevOps Engineer (Platform), covers the Kubernetes estate, delivery pipelines and migrations. Apply for whichever fits, and tell us if both do. What you will do Edge and network security Own our Envoy based edge, along with WAF rules, rate limiting and bot management across our cloud and CDN layersDesign and tune protections against abuse, including content scraping, credential attacks and traffic anomaliesBuild detection for the traffic patterns that matter, and keep improving its signal to noise ratio Cloud security posture Harden our AWS estate: IAM boundaries, least privilege access, threat detection and runtime monitoring on EKSManage secrets, certificates and token lifecycle across the platformProduce the infrastructure evidence behind ISO 27001 audits, penetration tests and enterprise security reviews Data platform Run PostgreSQL and RDS in production across regions, covering upgrades, performance, encryption and access controlOwn our search infrastructure, Typesense and vector search, end to endWork with MongoDB and Elasticache alongside the primary data stores Observability Own the monitoring platform: Grafana, Loki and Prometheus, plus Sentry and PagerDutyBuild alerting people actually trust, with meaningful thresholds, low noise and clear runbooksImprove how logs and metrics flow from the edge and the application into the stack What we are looking for Essential 5+ years in infrastructure, SRE or security engineering, with strong AWS depthReal experience with edge, WAF or reverse proxy technology: Envoy, nginx, Cloudflare, ModSecurity, Coraza or equivalentProduction Kubernetes, ideally EKS, and strong TerraformOperating PostgreSQL at scale. You have done upgrades and performance work, not just connected to onePractical observability experience. You have built alerting that worked, and killed alerting that did notA security engineer's instincts. You think about what an attacker does with the thing you just shippedEnglish at a working professional level. Our engineering team is international Nice to have Search infrastructure: Typesense, Elasticsearch, OpenSearch or vector searchContent protection and anti-scraping workHaving supported ISO 27001, SOC 2 or similar audits from the technical sideHealthcare, fintech or another regulated domainPolish. Much of the engineering team is in Poland, though the company works in English How we work On-call. We run a 24/7 rotation through PagerDuty, with documented playbooks and readiness checklists. Participation is agreed with you rather than assumed, and separately compensated.Cadence. Written async updates, a fortnightly planning touchpoint and a regular infrastructure and security sync. You set your own hours and choose your own tools.Documentation. Threat models, decision records and runbooks are part of the work. We expect the reasoning to be written down, not just the config.Autonomy. Small team, wide scope, very little process between you and a decision.