Description
Company Description
TAO Digital Solutions is a global technology company headquartered in Silicon Valley, with offices across the US, Canada, Taiwan, India, Australia, New Zealand, and Nigeria.
We specialize in product engineering, AI, data, cloud, managed services, and industry solutions across multiple sectors.
Our global team of 4,000+ professionals is passionate about building scalable, innovative, and data-driven solutions that help organizations accelerate digital transformation and unlock business value.
Role Description
We are looking for an SRE engineer to join our team in Taipei.
In this role, you will diagnose and resolve issues across the multicloud estate: AWS, GCP, AliCloud, and the internal cloud gateway and control planes.
You will take incidents from page or ticket intake through to resolution and written RCA, escalating to platform engineering only when a confirmed defect or capacity change is required.
Singapore is the anchor site for this role, covering the APAC estate at its point of origin.
Cloud platform core β must have
β’ Account lifecycle across providers: onboarding, org hierarchy placement, service enablement, decommission
β’ Provisioning failure diagnosis and stuck-state recovery, from request intake to delivered resource
β’ Quota management: request, validation, pre-requisite checks, and capacity escalation to the provider
β’ IAM and access: roles, trust policies, federated and short-lived credentials, SSO role mapping
β’ Cost visibility and remediation: identifying waste, right-sizing, and tracking realized savings
Multi-cloud β must have at least two
β’ AWS: EC2, VPC, NLB and ALB, Route 53, subnet and address-space reconciliation, IAM roles anywhere
β’ GCP: GCE, service accounts, vulnerability remediation workflows, project and folder structure
β’ AliCloud: region-specific service availability and version constraints, STS and RAM
β’ Cross-provider differences in quota, IAM, and network models.
Knowing where the three diverge is the point of the role
Platform tooling β must have
β’ Infrastructure as code: Terraform or Ansible, including drift detection and blast-radius management
β’ Deployment and release tooling such as Spinnaker
β’ Compass compliance onboarding, backup services, image and golden-AMI lifecycle
β’ Internal cloud inventory and query tooling for account, resource, and spend reporting
Observability β must have
β’ Prometheus and Grafana: dashboard authorship and alert definition that is actionable, not noise
β’ Splunk: forwarding, query authorship, and use in live incident diagnosis
β’ Defining SLIs for provisioning success, gateway availability, and request latency
Networking β must have
β’ Cross-environment DNS resolution and connectivity to managed database services
β’ Load balancer reconcile loops and subnet annotation behavior
β’ Gateway and proxy endpoint troubleshooting, including destination allow-listing and egress paths
β’ Outage triage and formal RCA authorship
Automation and code β must have
β’ Python or Go sufficient to ship tooling that goes through peer review, not throwaway scripts
β’ Converting repeat manual remediation into runbook automation or self-service paths
β’ Git-based operational workflow, GitHub Actions, PagerDuty
Incident discipline β must have
β’ Run an incident end to end: triage, mitigate, verify recovery against the customer-facing signal, resolve
β’ Journal every investigation in writing as you work, so the next shift continues instead of restarting
β’ Blameless RCA authorship and promotion of findings into the shared runbook library
β’ Clear written English.
Most hand-offs happen in writing across time zones
Required Qualifications
β’ 5+ years in cloud infrastructure support, site reliability, or cloud operations engineering.
The multi-provider scope sets this bar above a single-cloud equivalent role.
β’ Deep production expertise in at least one major cloud provider, with demonstrated working competence in a second.
Depth in AWS or GCP is the most common qualifying profile.
β’ Strong identity and access management fundamentals that transfer across providers: role assumption and delegation, service and machine identities, policy evaluation and troubleshooting, and federated or directory-sourced group mapping.
β’ Practical Kubernetes operations experience (EKS, GKE, or ACK) β inspecting pod and node state, diagnosing volume and networking failures, and interpreting cluster events.
β’ Working knowledge of enterprise network fundamentals: routing, DNS, TLS, proxies, CIDR planning, and firewall/ACL models.
β’ Scripting proficiency in Python or Bash, plus fluency with provider CLIs.
β’ Excellent written English β the majority of support happens asynchronously in text, and clarity directly determines resolution speed.
β’ Legally authorized to work in Singapore.
Preferred Qualifications
β’ Certification in one or more of: AWS Solutions Architect (Associate/Professional), Google Professional Cloud Architect, Alibaba Cloud ACP.
β’ Prior AliCloud experience, or demonstrated rapid ramp on an unfamiliar cloud provider.
AliCloud talent is scarce in the market; evidence of learning a new provider quickly is an acceptable and expected substitute.
β’ Experience supporting internal developer platforms in a large enterprise.
β’ Familiarity with hybrid connectivity between corporate networks and public cloud.
β’ Infrastructure-as-code exposure (Terraform, CloudFormation).
β’ Observability tooling experience (Splunk, Datadog, CloudWatch, Cloud Logging).
β’ Prior follow-the-sun or multi-region support rotation experience.
β’ Familiarity with China-region cloud operations and their regulatory constraints.