Senior DevOps Engineer
Apply NowWe are looking for a Senior DevOps Engineer to join our team! You will own and evolve Mailtrap's production infrastructure — a multi-region AWS platform powering high-volume email sending and testing. You will keep it reliable, secure, and cost-efficient day to day.
You will also lead a key strategic initiative : planning and executing a partial migration of selected workloads from AWS to rented bare-metal / colocation infrastructure to cut costs — a hybrid-by-design effort, not a full cloud exit. You will decide what moves and what stays, design the target platform (likely Kubernetes or a similar orchestrator on bare metal), and own the migration end to end, from business case to cutover.
Our engineering team thrives in an agile, continuously improving, and automation-oriented environment. We value ongoing evolution, objective evaluation of our processes, and taking action to make things better.
What are we looking for?
Must have skills:- 5+ years DevOps/platform (senior), production ownership
- Deep AWS (VPC, ECS, IAM, RDS/ElastiCache or equivalents, networking)
- Terraform at scale (modules, remote state / Terraform Cloud)
- CI/CD with GitHub Actions, including automated deploys to production (e.g. blue/green deployments)
- (Docker); comfortable operating services on ECS or K8s
- Strong Linux networking (DNS, TLS, load balancing, firewalls, VPN/hybrid)
- Proven experience planning and executing migration to on-prem, colo, or private cloud (partial/hybrid OK — full exit not required)
- Comfortable owning a multi-quarter infra initiative: TCO, design, vendors, cutover, rollback
- Comfortable automating operational tasks with shell and/or Python
- Fluent English (both spoken and written)
- Colo/bare-metal ops: IPAM (NetBox), Ansible, image-based provisioning (Packer or equivalent), HAProxy/Nginx
- Replacing managed AWS services with self-hosted (Postgres HA, Redis/Valkey, Kafka, OpenSearch)
- Email infrastructure (MTA, SMTP, IP reputation, DKIM/SPF/DMARC) — Halon or similar
- Cloudflare (DNS/WAF/Access)
- Observability beyond CloudWatch (Prometheus/Grafana/Loki or equivalent)
- Prior work with multi-region SaaS or EU data residency
- Cost-driven architecture / FinOps mindset
- GCP (BigQuery/certificates)
- Comfortable reading Ruby or Go (used in our services and tooling)
- AWS Certificates
Responsibilities
Day-to-day:- Operate and evolve AWS multi-account / multi-region infra
- Terraform modules/workspaces
- Ensure safe infrastructure changes across network, storage, and services, with zero-downtime deployments.
- ECS services, blue/green deploys, Docker image pipelines
- Reliability: CloudWatch/PagerDuty/Sentry, capacity, cost tags
- Security baseline: IAM, secrets (SSM), Cloudflare edge rules
- Partner with engineers on release automation and production readiness
- Maintain the hybrid estate (AWS and rented bare metal) as one operable platform
- Build the business and technical case for what moves off AWS vs what stays
- Design the rented bare-metal / colo landing zone (compute, network, storage, observability, secrets)
- Produce migration waves, dependency maps, cutover/rollback plans
- Stand up hybrid connectivity and dual-run periods; shift traffic safely (e.g. via Cloudflare)
- Replace or re-home managed services where it pays off (compute, queues, search, cache, MTA nodes)
- Coordinate colo/vendors, timelines, and eng teams; report progress and risk
Benefits
and Perks
- Competitive compensationLet's face it: in a late capitalistic world, getting paid well certainly doesn't hurt.
- Growth opportunitiesOutline your growth and development plan, expand your skills, knowledge, and career horizons in a supportive and innovative environment.
- Remote and flexible scheduleRailswarians live in more than 25 countries with different time zones. All of them are free to choose their most productive work time and place.
- Smart Expense policyThere's an additional sum allocated to help you set up your workstation, improve your health, and learn whatever you want and how you want. No. Questions. Asked.
- Secure hardware and equipmentYour productivity is our priority. Once you join Railsware, you’ll get secure equipment of your choice.
- 34 Paid days offRailswarians rest 24 days per year + 10 days to cover your national holidays.
- Regular online and offline gatheringsWe frequently meet online and offline to get acquainted, collaborate, build a network, and have fun together.