OPSWAT
OPSWAT14d ago

Infrastructure & CloudOps Engineer

OtherDevOps & InfrastructureInfrastructure EngineerInfrastructureInfrastructure & Cloud
0 views0 saves0 applied

Quick Summary

Key Responsibilities

EC2 instances (eu-north-1), S3 buckets, IAM roles, SSM -based remote access (no SSH),

Requirements Summary

we do not accept unsolicited resumes from third party agencies for any of our open positions. To submit resumes for our jobs, there must be a recruiting contract approved by our legal te

Technical Tools
OtherDevOps & InfrastructureInfrastructure EngineerInfrastructureInfrastructure & Cloud

OPSWAT, a global leader in IT, OT, and ICS critical infrastructure cybersecurity, delivers an end-to-end platform that gives public and private sector organizations and enterprises the critical advantage needed to protect their complex networks, secure their devices, and ensure compliance. Over the last 20 years our commitment to innovative technology has earned the trust of more than 1,700 organizations, governments, and institutions globally, solidifying our role in protecting the world’s critical infrastructure and securing our way of life.

About the Role

~1 min read

The CTO Intelligence Hub is OPSWAT’s internal data platform; a fleet of 20+ containerised applications running on AWS EC2 that deliver AI adoption analytics, financial intelligence, customer health scoring, sales leaderboards, and content generation to OPSWAT leadership and 590+ engineers worldwide. You will own the infrastructure layer that keeps this platform reliable, secure, and scalable.

This is a hands-on individual-contributor role. You will be the sole infrastructure owner on day one, working closely with the CTO and one AI Platform Architect to operationalise and evolve the system.

Responsibilities

~1 min read
  • AWS infrastructure: EC2 instances (eu-north-1), S3 buckets, IAM roles, SSM-based remote access (no SSH), security group allowlists across 8 global offices
  • Container orchestration: Docker Compose fleet of 20+ services with sequential startup chains, health monitoring, auto-rollback, and OOM prevention on memory-constrained instances
  • CI/CD pipeline: GitHub Actions workflows (centralized deploy-app.yml), S3 artifact rotation, per-service smart change detection, post-deploy health checks
  • Reverse proxy & SSO: nginx routing, Cloudflare SSL termination, OAuth2 Proxy backed by Azure AD for single sign-on across all internal apps
  • Credential & secrets management: OAuth token lifecycle (token-proxy auto-refresh), GitHub org secrets, PAT rotation, SSM Parameter Store, per-app .env files
  • Data pipeline operations: EC2 #3 (Fabric → Parquet → S3), daily cron jobs, MSAL token refresh, lockfile and resume logic
  • Observability & incident response: health monitor (15-min cron), watchdog deep-checks, Telegram alerting, EC2 reboot recovery, Docker mount-corruption recovery
  • Security posture: network-level access controls, credential hygiene, OPSEC between corporate and personal identities
  • 3–6 years hands-on AWS experience (EC2, S3, IAM, SSM — not just console clicks)
  • Solid Docker and Docker Compose skills; you debug failed container starts at 2 am without fear
  • GitHub Actions: writing and maintaining multi-job workflows with secrets, artifacts, and matrix builds
  • Linux system administration (Ubuntu): cron, systemd, disk management, process investigation
  • Python scripting for ops tasks (deployment scripts, health checks, API automation)
  • nginx configuration: upstream proxying, path-based routing, SSL
  • A security-first mindset: you default to least-privilege and always ask “what happens if this leaks?”

Nice to Have

~1 min read
  • Experience with Cloudflare (proxying, SSL, DNS management)
  • Azure AD or OAuth2 Proxy familiarity
  • PostgreSQL administration
  • Experience operating ML/AI inference workloads
  • GitHub App development (JWT-based installation tokens)
  • Familiarity with Microsoft Fabric or Azure data services

OPSWAT is an equal opportunity employer. We celebrate diversity and are committed to providing an environment where equal employment opportunities are extended to all employees and applicants, free of discrimination and harassment of any type. All employment decisions are based on individual qualifications, job requirements, and business needs without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other category protected by federal, state, or local laws.

Recruiting Agencies: we do not accept unsolicited resumes from third party agencies for any of our open positions. To submit resumes for our jobs, there must be a recruiting contract approved by our legal team and endorsed by both parties. We are currently not accepting additional 3rd party agencies at this time.

 

Location & Eligibility

Where is the job
Vietnam
On-site within the country
Who can apply
Open to applicants worldwide
Listed under
Vietnam

Listing Details

Posted
April 15, 2026
First seen
April 15, 2026
Last seen
April 29, 2026

Posting Health

Days active
14
Repost count
0
Trust Level
36%
Scored at
April 29, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
OPSWAT
OPSWAT
greenhouse

OPSWAT is a leading cybersecurity firm that protects critical infrastructure by eliminating malware and zero-day attacks.

Employees
350
Founded
2002
View company profile
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

OPSWATInfrastructure & CloudOps Engineer