Cloud Infrastructure Engineer
Join a team that ships AI-first marketing systems for B2B—small teams, high ownership, and outcomes measured in pipeline and retention, not vanity metrics.
Location
Remote
Employment
Full-time
Team
Platform & Delivery
Company
DigiiMark
What you will do here
Everything below comes straight from our hiring team—no generic templates. Read it, then tell us what you have shipped that maps to it.
About this role
DigiiMark delivers always-on marketing systems for B2B clients—sites, automation, data pipelines, and integrations that have to stay fast, secure, and observable. We are hiring a Cloud Infrastructure Engineer to own how those systems run in production: from VPC layout and secrets to CI/CD, cost guardrails, and calm incident response.
You will work primarily on AWS, packaging workloads with Docker and orchestrating them with Kubernetes (EKS or equivalent patterns). You will partner closely with full-stack engineers and occasionally advise client teams on hardening and scale.
We optimize for boring operations: repeatable runbooks, small blast radius, and changes that are easy to roll back.
What you will own
- Platform foundations: accounts/organizations, networking (VPC, subnets, routing, endpoints), IAM baselines, and least-privilege access patterns for humans and workloads.
- Runtime & delivery: container images, cluster lifecycle, workload identities, autoscaling signals, and safe deployment strategies (blue/green, canary where appropriate).
- Infrastructure as code: Terraform, Pulumi, or equivalent—reviewable modules, environments that match prod, and drift detection you actually act on.
- CI/CD: pipelines for build, test, scan, sign, and promote; cache hygiene; artifact governance; secrets injection without sprawl.
- Observability & reliability: metrics, logs, tracing, SLOs/SLIs, alerting that pages humans for actionable events—not noise.
- Security & compliance hygiene: patching cadence, image scanning, dependency and SBOM practices, backup/restore drills, and sensible encryption in transit and at rest.
- Cost & performance: right-sizing, savings plans where justified, and profiling spend drivers with engineering.
Technical scope
You do not need every bullet on day one, but this is the terrain we expect you to grow mastery across:
- AWS: IAM, VPC, ALB/NLB, ECS and/or EKS, RDS or managed Postgres patterns, S3 lifecycle, CloudWatch, KMS, Route53, WAF concepts.
- Kubernetes: workloads, services, ingress, HPA, resource quotas, network policies, RBAC, and safe cluster upgrades.
- Linux: networking, systemd basics, disk and memory troubleshooting, performance triage.
- Automation: GitHub Actions or similar; scripting in bash/Python/Go for glue when it reduces toil.
What we look for
- Experience: 4+ years operating production systems with real traffic, incidents, and change management—not only lab clusters.
- Judgment: you can explain tradeoffs (cost vs. resilience vs. velocity) and document decisions stakeholders can trust later.
- Collaboration: async-friendly updates, pairing with app engineers, and crisp handoffs during incidents.
- Security instinct: least privilege, secret rotation, blast-radius reduction, and skepticism toward "just open the security group."
Bonus signals (not required)
- Experience with Supabase/Vercel-style edge and serverless adjacent workloads alongside long-lived services.
- FinOps habits: unit economics of infra, chargeback/showback reporting, and forecasting.
- Prior agency or consulting pace with multiple concurrent engagements.
How we work
This role is remote-first within regions where we can contract and maintain healthy overlap with teammates and clients. We bias toward written RFCs for risky changes, blameless postmortems, and automation that removes repetitive manual steps.
On-call may evolve as the practice grows—we aim for low toil, actionable alerts, and humane rotations.
Interview process (typical)
- Intro call — scope, mutual fit, and how you like to operate on-call and under pressure.
- Systems conversation — design and tradeoffs across AWS/Kubernetes/CI—not trivia.
- Practical exercise — bounded scenario (diagram + runbook outline, or hands-on in a sandbox).
- Team meet — values, incident culture, and expectations on both sides.
Compensation & growth
We offer competitive compensation aligned with ownership of production outcomes. We share ranges transparently once we align on scope and seniority.
Equal opportunity
DigiiMark is an equal opportunity employer. We welcome applicants of all backgrounds and do not discriminate on the basis of race, religion, gender identity, sexual orientation, age, disability, or any other protected characteristic.
Built for people who like shipping
Systems, not campaigns
We engineer durable pipelines—sites, automation, data—so clients compound results instead of restarting every quarter.
AI where it earns trust
We deploy models and agents with evaluation, guardrails, and human-in-the-loop review—not hype slides.
Craft + velocity
Premium UX and strict TypeScript can coexist. We optimize for clarity, observability, and calm deploys.