Mach aus dieser Rolle ein Vorstellungsgespräch — ein Lebenslauf und ein Anschreiben, die darauf ausgerichtet sind, was dieser Arbeitgeber sucht.
Constellr GmbH is seeking a mid-to-senior Cloud Infrastructure Engineer to design, build and operate cloud and on-prem infrastructure that underpins our space‑based data platform. You’ll own end-to-end topics, contribute to golden paths, and help maintain security and compliance standards across multiple providers and AIT facilities.
You will collaborate with Security/Compliance and IT teams, grow observability and automation, and drive platform reliability while reducing vendor lock‑in.
Team & Reporting Line: Cloud Infrastructure
Our Mission
At constellr, we’re harnessing the power of space to solve one of Earth’s greatest challenges: climate resilience & security in a changing world. Our thermal satellite constellation delivers the most accurate land surface temperature data on the market, equipping commercial players, governments, defence agencies, and global institutions with the thermal intelligence they need to make strategic decisions– from national security and infrastructure to agriculture and climate resilience.
As a fast-scaling company with offices in Brussels, Freiburg, Munich, Washington and Toulouse, our multidisciplinary team of engineers, scientists, and strategists is building the future of space-based Earth observation
Your Role
You’ll join our central Infrastructure team to helpconstellrbuild and operate the cloud and on-prem infrastructure behind our software systems — the Ground Segment for satellite operations, Data and User Segments, and Space Engineering-related systems, plus (together with IT) our AIT facilities.
We currentlyoperateplatform-style and arelargely self-organised, but with a realopscomponent: we support other teams via tickets, incident response, and bug fixes, and own infrastructure reliability end-to-end. Beyond day-to-day operations, we proactively shape “golden paths” for engineeringteamscompany-wide rather than only reacting to requests. Securityand cloudagnosticityarefirst-class concernsfor us — we work towardhighstandards(e.g.,ISO/IEC 27001) and collaborate closely with our Security/Compliance and IT departments, who own dedicated responsibilities in this area.
We’rehiring at a mid-to-senior level where tenureisn’tthe leading indicator, more importantly you are expected to be able to see the bigger picture and weigh trade-offs across systems and teams, proactively surface issues and are comfortable owning topics end-to-end.
Key responsibilities
Design andoperateinfrastructure across multiple cloud providers (currently AWS, expanding to an EU-sovereign provider) plus on-prem/AIT environments, usingIaC(Terraform/Terramate) with an eye towardsecurity andportabilitywhileavoiding unnecessary vendor lock-in.
Take ownership of key systems and topics alongside theteamwhilecontributingactivelyto shared team responsibilities and outcomes, not just your own backlog.
Improve the reliability, performance, and scalability of systems deployed in the cloud and on-prem.
Manage secrets, encryption, and certificates (SOPS, KMS/HSM equivalents) consistently across cloud and on-prem.
Partner withtheSecurity/Compliancedepartmenton ISO/EIC27001 controls, risk assessments, and audits; implement infrastructure controls satisfying security requirements (access control, segregation of duties, auditability, data residency).
Contribute to improvingthe observability stack to better monitor systems in the cloud and on-prem.
Help spreaddomain and techknowledgeacross the team to prevent siloing.
Support other engineering teams via tickets and incident response whileidentifyingrecurring pain points to turn into paved-road solutions (golden paths, self-service tooling, standardized platform patterns).
Manage OS-level configuration via Ansible for on-prem/VM fleets (including AIT facility systems, in coordination with IT).
Provide architectural supportand guidanceto other engineering teams on selectedcloud, platform, and security topics.
Contribute to andmaintaininfrastructure documentation and onboarding materials.
About you
Required:
Significant hands-on experience designing, securing,administeringandoperatingsoftware systems in the cloud.
Hands-on experience with AWS or a comparablehyperscalerin a production setting.
Experience with containerization, Kubernetes,and cloud-agnostic deployment technologies.
Experience administering andmaintainingdatabases and cloud-hosted services — both self-hosted and managed/cloud-native.
Experiencemaintainingand administering on-prem/VM-based Linux systems alongside cloud resourcesand management of configurations via Ansible.
Experience withvirtualization platforms, configuration of routers, switches, VLANs, network segmentation, etc.
Experience with VPCs, cloud networking, and modern zero-trust/mesh networking tools (e.g.,Tailscale).
Solid working knowledge of Terraform; comfortable adoptingTerramate(or similarIaCorchestration tooling) if youhaven’tused it yet.
Experience with observability stacks (Prometheus, Grafana, time-series stores).
Solid working knowledge in practical security fundamentals: secrets/encryption management, IAM least-privilege, network segmentation, audit logging.
A track recordof owning systems end-to-end while being a reliable, collaborative team member.
Nice to Have_:_
Experience with an EU-sovereign cloud provider (e.g.,Scaleway, T Public Cloud, STACKIT).
Experience with incident response /operationalpractices.
Exposure to ISO/IEC 27001 (or comparable public-sector/security-relevant certifications), or interest in contributing to certification efforts.
Experience withGitOps/CD tooling (e.g., Argo CD, Argo Workflows).
Experience administering Git hosting platforms for engineering teams (e.g., GitHub/GitLab administration).
Experience administering Windows VMs.
Experience in aerospace, satellite ground segment, or other regulated/mission-critical environments.
Experience with cloud-agnostic secrets management (e.g.,OpenBao).
Openness tobeingon-call.
Why join constellr?