Role Summary The Company operates cloud applications, data systems, and connected infrastructure that support the organization and, in some cases, sensitive healthcare data. We are seeking a experienced hands-on infrastructure owner to make our systems secure, observable, recoverable, and dependable in production. This is broader than a traditional CI/CD role. You will own infrastructure end to end and isolate failures across the full path from network and connectivity, through servers, containers, and cloud services, into applications, storage, and databases. You will also help support the company's broader technology environment, working closely with organizational leaders to understand priorities, scope deliverables, and deliver dependable technical solutions so our platforms and the wider organization operate cleanly together, not in isolation. Core Responsibilities
- Stakeholder communication and technical translation: Support external vendor and partner communications.
- Cloud and deployment: Own production and development infrastructure on GCP; deploy and troubleshoot Cloud Run; manage Docker images, Artifact Registry, IAM, service accounts, secrets, access controls, scaling, memory, timeouts, startup failures, and crash loops.
- Azure and multi-cloud: Support and integrate Microsoft Azure workloads alongside GCP — Azure resource groups, App Service / Container Apps / AKS, Azure Storage, Azure Key Vault, Azure Monitor, and networking (VNets, peering, private endpoints).
Establish and troubleshoot secure GCP↔Azure connectivity, consistent
IAM/RBAC
across clouds, and a coherent multi-cloud secrets, logging, and cost posture.
- Corporate integrations and identity: support integrations between the platform and corporate systems — Microsoft Entra ID (Azure AD) for SSO (SAML/OIDC), SCIM user provisioning/deprovisioning, and role/group mapping.
Integrate with corporate directory, Microsoft 365 / Google Workspace, and business systems via APIs, webhooks, and service accounts. Ensure identity, access, and offboarding flow consistently across cloud and corporate boundaries.
- Release and recovery: support head of DevOps in Improve build, deployment, rollback, backup, restoration, and disaster-recovery practices while maintaining clear development, test, and production separation.
Networking and VPN:
Design and troubleshoot private connectivity using WireGuard, Tailscale, or similar tools, including subnet routing, ACLs, tagged devices, NAT, DNS, firewalls, certificates, and intermittent site connectivity. Extend this to hybrid corporate connectivity (site-to-site VPN, cloud VPN gateways, private link/peering) between on-prem, GCP, and Azure.
- Application and data operations: maintain and build Node.js, TypeScript, and Python services; operate PostgreSQL connections, pooling, migrations, backups, restores, and production access; support webhooks and notification providers.
- Security and automation: Apply least privilege, encryption, credential rotation, auditability, secure retention/deletion, vulnerability management, and practical controls aligned with HIPAA and SOC 2. Move repeatable infrastructure toward Terraform or equivalent (across both GCP and Azure). Required Qualifications
- 5+ years in DevOps, cloud infrastructure, systems engineering, or a related role.
- Working experience with Microsoft Azure (compute, storage, networking, Key Vault, and RBAC) in a production or hybrid context.
- Solid networking knowledge across VPNs, routing, NAT, DNS, firewalls, TLS certificates, private networks, and access policies.
- Experience operating and troubleshooting databases like PostgreSQL and MongoDB, backups, restores, and production access.
- Experience with Git and GitHub branches, pull requests, releases, and access controls. Strong general CLI skills.
- Ability to read and troubleshoot Node.js/TypeScript and Python applications when infrastructure or deployment work requires it.
- Experience managing secrets, service accounts, credentials, production permissions, logs, monitoring, backups, and disaster recovery.
- Strong production troubleshooting, written documentation, communication, and independent ownership skills. Strongly Preferred
- Experience with corporate identity and SSO — Microsoft Entra ID (Azure AD) and/or Okta, SAML/OIDC, and SCIM provisioning.
- Strong Linux knowledge
- Strong hands-on GCP experience, including production Cloud Run troubleshooting.
- Experience integrating cloud platforms with corporate systems such as Microsoft 365, Google Workspace, or business/line-of-business applications via APIs and webhooks.
- Experience with IP cameras, NVRs, UniFi Protect, and relevant protocols.
- Experience with FFmpeg, OpenCV, H.264/H.265, and secure video storage.
- Practical HIPAA knowledge and experience with sensitive healthcare or video systems. Helpful, but Not Required
- Experience with Azure DevOps, Azure Container Apps/AKS, or Azure Monitor/Log Analytics.
- Experience with Replit workflows, secrets, databases, and development environments.
- Familiarity with
SOC 2, ISO
27001, or early-stage technical teams.
Salary:
100k - 110k
Pay:
$100,000.00 - $110,000.00 per year
Benefits:
401(k) Dental insurance Health insurance Paid time off Vision insurance
Work Location:
Hybrid remote in Attleboro, MA 02703