Posted on: 19/08/2026
Role Overview :
Are you a DevOps Engineer who thrives under the hood of true on-premises architecture and bare-metal environments? Do you prefer building production-grade, 100% open-source platforms over managing managed public cloud services?
We are looking for a skilled DevOps Engineer (Cloud-Native | On-Premises) to own and scale our completely self-hosted infrastructure. In this role, you will build and maintain bare-metal Kubernetes clusters, implement GitOps pipelines, manage OpenStack environments, and drive production-grade reliability without relying on AWS or Azure managed services.
Key Responsibilities :
1. Infrastructure & Kubernetes (Bare-Metal / OpenStack) :
- Deploy, manage, and scale self-hosted Kubernetes clusters on bare metal and OpenStack.
- Build, maintain, and optimize custom Helm charts for platform services.
- Configure CNI plugins, network policies, and manage multi-cluster upgrades and lifecycle management.
2. CI/CD, Automation & GitOps :
- Design and maintain robust CI/CD pipelines using Jenkins and modern GitOps workflows.
- Manage self-hosted runners and internal artifact repositories (Nexus / Artifactory).
- Integrate automated testing, Trivy container security scans, and SonarQube quality gates into pipelines.
- Execute progressive deployment strategies including Canary and Blue-Green rollouts.
3. Observability & Operations :
- Deploy and tune Prometheus monitoring and custom Grafana dashboards.
- Maintain centralized logging using EFK (Elasticsearch, Fluentd, Kibana) or Loki stacks.
- Set up distributed tracing with Jaeger and configure production alert routing via AlertManager.
4. Networking & Platform Services :
- Configure Ingress controllers (NGINX / Traefik) and bare-metal load balancers (MetalLB).
- Manage DNS, service discovery, and automated TLS/SSL certificate lifecycles via cert-manager.
5. Security, Compliance & Governance :
- Implement strict Kubernetes RBAC rules and Pod Security Standards.
- Conduct automated security audits using tools like kube-bench and kube-hunter.
- Manage secrets securely using HashiCorp Vault or Sealed Secrets.
Core Requirements :
- Mandatory Technical Focus : Strong hands-on experience in Private Cloud / On-Premises infrastructure (OpenStack, bare-metal Kubernetes).
Note : Candidates exclusively experienced in public cloud managed services (AWS, Azure, GCP) will not be considered.
- Container Orchestration : Deep understanding of on-prem Kubernetes architecture, CNI, storage, and networking fundamentals.
- CI/CD & Code Control : Hands-on experience building Jenkins pipelines and developing Helm charts.
- Linux Systems : Advanced Linux administration skills and shell/automation scripting expertise.
- Work Logistics : Comfortable working a Hybrid schedule (4 days in-office, 1 day remote).
- Aligned with Kenya shift hours.
- Willingness to travel to Kenya periodically as required by projects.
Nice to Have :
- Hands-on experience with multi-cluster management tools (e.g., Rancher).
- Automated backup and disaster recovery mechanisms (e.g., Velero).
- Policy-as-code frameworks (e.g., OPA / Kyverno).
- Certified Kubernetes Administrator (CKA) or Application Developer (CKAD).
The job is for:
Did you find something suspicious?
Posted by
Posted in
DevOps / SRE
Functional Area
DevOps / Cloud
Job Code
1664421