- Location
- Slovenia / Remote · Viaduct SLO
- Workplace
- Remote
- Department
- Engineering
Description
About Us
Viaduct builds production-grade AI systems for the world's manufacturers: not pilots, not proofs of concept. The Internal Efficiencies team is deploying real AI use cases inside one of Japan's largest manufacturers - a modern cloud and AI stack, shipped all the way down to a plant floor running robots, lasers, and IoT gear most software teams never get near.
We're a new team building fast. Viaduct already has a sophisticated, battle-tested platform - AWS landing zone, Terraform, AKS, Postgres, ClickHouse, Argo, observability - with genuinely great bones. But that platform was built to host production SaaS applications, and our team's needs don't look like that. We need our own environment, built on the lessons of what already exists, but shaped around how we actually work: fast iteration, new tooling, production use cases shipping constantly.
Who You Are
You're an infrastructure engineer who treats AWS as something you architect and own, not something you're handed. You've built a cloud environment from scratch - landing zone, networking, IAM, the works - and you know the difference between copying a pattern and understanding why it exists. You're equally comfortable in the DevOps/DevEx world: CI/CD, GitOps, Kubernetes, making other engineers faster. And once things are live, you don't walk away - you watch them, you look for what's about to break, and you fix it before it does.
You like being a force multiplier. You'd rather build the paved road once than answer the same infra question five times.
About the Role
You'll work directly with the head of Internal Efficiencies and effectively own infrastructure for the team - currently 6+ people including 4 engineers, with plans to double engineering headcount or more over the next year as we take on more production use cases.
This is a build-from-scratch role with an unusually strong reference platform next door. You'll stand up an independent AWS environment purpose-built for how our team operates, informed by (but not constrained to) the existing hub-and-spoke Terraform setup. From there, you'll install and integrate the tools that let the team ship: a Dagster OSS agent running on Kubernetes workers, wired into CI/CD; a paved path for deploying "ordinary" Python/TypeScript prototype web apps with external access and Okta integration; and the observability and cost discipline to keep it all sane as it scales.
Once things are in production - and with this team, things go to production fast - you're the one proactively watching them: looking for robustness gaps, scalability limits, and cost inefficiencies before they become incidents, and building the automation that keeps the rest of the team out of the weeds.
This isn't a role where you disappear into infrastructure and hand down decrees. You'll work hand-in-hand with IE engineers, product managers, and leadership to understand what's actually being built and where it's headed, and with the wider Viaduct engineering org to stay aligned with (and pull forward, where it makes sense) the platform patterns they've already proven out. You own the infrastructure decisions - but you make them in the open, with the people who depend on them.
What You'll Do
- Architect and build an independent AWS environment for the team - landing zone, networking, IAM, security - informed by Viaduct's existing best-practices infrastructure but designed for our own needs
- Install, configure, and integrate new platform capabilities as the team needs them (e.g., Dagster OSS on Kubernetes workers, CI/CD integration)
- Build and maintain a paved path for deploying internal Python/TS web app prototypes, including external exposure and Okta-based access control
- Own observability, reliability, and cost-effectiveness for everything running in production
- Proactively identify and close robustness, scalability, and operational gaps before they become incidents
- Build automation that removes infrastructure toil from the rest of the team
- Ensure production systems are secure, backed up, and kept current with minimal downtime
- Partner closely with IE engineers, product managers, and leadership on infrastructure needs and tradeoffs, and with the wider Viaduct engineering org to stay aligned with broader platform direction
What We're Looking For
- Real AWS ops/admin depth - you've architected and run production AWS environments, not just consumed one someone else built
- Strong Infrastructure-as-Code chops (Terraform, Terragrunt, or similar)
- Proficiency with Kubernetes (Helm, Kustomize, kubectl) and GitOps patterns (Argo CD, Flux, or similar)
- Experience building CI/CD pipelines (GitHub Actions, Argo Workflows, or similar)
- Comfort owning infrastructure decisions independently, with imperfect information, on a small and fast-moving team
- Bonus: experience with Dagster, ClickHouse/Postgres administration, or Okta/SSO integration
Security and Privacy Responsibilities
- Member of the CSIRT Team
- Follow our policy and procedure documents related to security and privacy
- Follow the guidelines in the Employee Handbook
- Participate in new hire and annual training for security and privacy
- Treat data security and privacy as one of your primary job responsibilities
- Report Security Incidents you discover as bugs
- Get approval from the Security Team before adding new 3rd party software to our codebase
- Explicitly consider security implications when doing PR reviews