Staff Engineer I, DevOps Engineering at Bain
Zapisz tę ofertę pracy i uporządkuj wyszukiwanie
Utwórz bezpłatne konto, aby zapisywać oferty pracy, tworzyć alerty i wracać do tego ogłoszenia ze swojego pulpitu nawigacyjnego.
Staff Engineer I, DevOps Engineering at Bain & Company in Warszawa, MZ, PL.
This Full time on site position offers great opportunities for career growth.
WHAT MAKES US A GREAT PLACE TO WORK
We are proud to be consistently recognized as one of the world’s best places to work.
We are currently the top ranked consulting firm on [1] Eurostaffs’s Best Places to Work list and have earned the #1 overall spot a record seven times.
Extraordinary teams are at the heart of our business strategy, but these don’t happen by chance.
They require intentional focus on bringing together a broad set of backgrounds, cultures, experiences, perspectives, and skills in a supportive and inclusive work environment.
We hire people with exceptional talent and create an environment in which every individual can thrive professionally and personally.
WHO YOU’LL WORK WITH
Coro is Bain's persistent product development and engineering organization, building and operating the firm's proprietary digital solutions.
Coro brings together technology, data, and services to create differentiated value for Bain's clients and case teams.
This role sits within Coro's DevOps and Assurance team, part of the Next Generation Software Solutions (NGSS) department.
The team enables secure, efficient, and reliable delivery of technology across Bain's global ecosystem, focusing on both technical operations and platform assurance so that every deployment meets the firm's standards for quality, security, and compliance.
WHERE YOU’LL FIT WITHIN THE TEAM
The Staff Engineer owns the design, architecture, and long-term direction of cloud infrastructure and software delivery across Coro's DevOps and Assurance team.
Working alongside architects and backend engineers, this engineer sets the technical standard for how the team provisions infrastructure, ships software, and secures its platforms, and ensures those platforms scale as the build plan expands.
This is a critical foundational role in the early stages of the platform build, requiring both strong technical fundamentals and the pragmatism to make infrastructure decisions that support a fast-moving product team.
Infrastructure Architecture & Automation
30% Own the design and evolution of cloud infrastructure built on Terraform and Terraform Cloud.
Define the module structure, state strategy, and remote backend conventions the rest of the team builds against.
Architect Azure networking end to end: VNet/subnet topology, private endpoints, DNS resolution, NSG design, and Front Door Premium configuration across dev, demo, and production.
Set the standard for provisioning Azure platform services (App Services, Azure SQL, Azure OpenAI, Container Registry (e.g. Azure Container Registry, Cloudsmith), Key Vault, Entra ID, Storage Accounts / ADLS Gen2) and ensure environment parity by design.
Own the automation roadmap for the team: identify manual, repetitive operational work, own the backlog of it, and drive it toward self-service and infrastructure-as-code so operational load trends down over time.
Partner with Bain's central cloud and infrastructure teams to shape shared processes, tooling, and standards for operational work.
Cloud & Platform Management (Azure)
20% Own Azure Kubernetes Service (AKS) architecture, including node pools, scaling strategy, spot instance usage, and workload connectivity to dependent services (databases, storage, AI services).
Define identity and access architecture: Entra ID app registrations, managed identities, RBAC model, and integration with external IdPs (Okta).
Set infrastructure standards for database platforms (Azure SQL Serverless, PostgreSQL Flexible Server, Cosmos DB), including connectivity, Entra auth, firewall rules, and private endpoints.
Ensure platform reliability and robust access controls across all environments, and act as the senior escalation point for platform-level issues.
CI/CD & Software Delivery
15% Define and own the CI/CD strategy using GitHub Actions for container builds, infrastructure deployments, and application releases, setting the patterns other engineers extend.
Establish the container image lifecycle standard: build, scan, push to a container registry (e.g. Azure Container Registry, Cloudsmith), and deploy to AKS or App Services.
Design environment promotion workflows with appropriate gating, secrets management (Key Vault), and rollback strategies.
Architect and operate GitHub-hosted private runners where required, including network integration with Azure VNets.
Monitoring, Security & Assurance
15% Own the observability strategy using the team's monitoring stack (e.g. Datadog, Azure Application Insights).
Define what the team monitors, alerts on, and how it optimizes cost and reliability.
Lead the response to s