Lead Infrastructure Engineer - India

Rojo Integrations

Pune District

On-site

INR 4,000,000 - 7,000,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Rojo Integrations seeks a hands-on Infrastructure Lead to own the Kubernetes-native foundation for its New Integration Products. You will define the cluster, IaC, secrets, identity, messaging, and observability from day one.

You will implement tenant isolation, hybrid/on-prem deployment, and a resilient Kafka backbone, while shaping the architecture and later building a team. Strong English and leadership are required.

Qualifications

  • 5+ years of experience owning production infrastructure end-to-end at a startup or scale-up.
  • Kubernetes expertise across cloud-managed and on-prem environments with advanced security and autoscaling.
  • Hybrid networking experience with secure cross-environment connectivity.
  • Terrafrom / IaC design with remote state and blast-radius control.
  • Apache Kafka production experience, preferably KRaft mode, with broker sizing and DLQ/DLT handling.
  • Identity & Secrets infrastructure using OIDC/RBAC providers and Vault-based secret management.

Responsibilities

  • Own the Kubernetes-native foundation for Rojo's integration products, including cluster, IaC, secrets, and observability.
  • Write Terraform configurations, manage cluster setup, and debug Kafka broker issues.
  • Set direction for infra architecture, ensure tenancy and data governance.
  • As the team grows, build and lead the infra team while maintaining architectural focus.

Skills

Kubernetes expertise
Hybrid networking
Terraform / IaC
Apache Kafka (KRaft)
Identity & secrets
CI/CD
Observability stack
Leadership
English proficiency

Tools

Terraform
ArgoCD/Flux
Vault
Keycloak
OpenTelemetry
Prometheus
Loki
Tempo

Job description

Role in one sentence

A hands-on infrastructure lead who owns the Kubernetes-native foundation for Rojo's New Integration Products. This covers the cluster, IaC, secrets, identity, messaging, and observability.

This is a greenfield build. There's no legacy infra and no existing conventions to inherit. Every foundational decision gets made once, by this person, and lived with for years. That takes someone senior enough to set direction and own it. As we scale, this person will build and lead a team. Right now, the focus is architecture. The person writes the Terraform, configures the cluster, debugs the Kafka broker.

The infra has to cover several key pillars from day one:

  • Tenant Isolation: Namespace-per-tenant, default-deny network policy, per-tenant secrets, and identity realms.

  • Hybrid & On-Prem Deployment: Hosting central control planes in the cloud while supporting deployment across on-premises or private cloud customer environments.

  • Durability & Messaging: Kafka as the backbone for event-driven components.

  • EU Data Sovereignty: Region, encryption, audit trails, and self-hosted vs. managed choices that hold up under GDPR and EU AI Act rules.

  • Observability: Every span, log, and metric traceable per tenant across all deployed environments.

Must-haves
  • 5+ years of experience owning production infrastructure end-to-end at a startup or scale-up. Ideally as an early or first infra hire with full accountability.

  • Kubernetes Expertise (Managed & On-Prem): Strong experience with cloud-managed K8s (EKS/GKE) as well as self-hosted, bare-metal, or lightweight distributions (e.g., K3s, Rancher, OpenShift) for on-premise setups. Deep grasp of namespace-per-tenant patterns, ResourceQuota/LimitRange, NetworkPolicy (default-deny), Pod Security Admission, and autoscaling.

  • Hybrid Networking & Connectivity: Experience with secure cross-environment networking (VPNs, mTLS, reverse proxies, WireGuard) to establish reliable communication between cloud control planes and on-premise execution nodes.

  • Terraform / IaC: Modular design (network / cluster / IAM / tenant-namespace / addons), remote state with locking, and state-splitting for blast-radius control. Treats IaC as a long-lived codebase.

  • Apache Kafka: Production experience (ideally KRaft mode). Broker sizing, replication/AZ placement, Schema Registry, DLQ/DLT, and retry topology.

  • Identity & Secrets Infrastructure: An OIDC/RBAC identity provider (e.g., Keycloak) with per-tenant realm patterns. A secrets manager (e.g., Vault) with Kubernetes-native auth and zero-hardcoded-secrets enforcement.

  • CI/CD: Practical experience with pipelines (e.g., GitHub Actions), lint/test/build/push/deploy flows, OIDC-based cloud auth, and secret-scanning pre-commit hooks.

  • Observability Infrastructure: OpenTelemetry Collector deployment patterns and a metrics/logs/traces stack (e.g., Prometheus, Loki, Tempo) built to be tenant-aware across hybrid environments.

  • Leadership & Independence: Sets technical direction, defends architecture choices (e.g., node pool strategy, partitioning, IAM boundaries), and prioritizes ruthlessly without needing a pre-built roadmap.

  • Language: Fluent English. Works well directly within a small, fast-moving technical team.

Nice-to-haves
  • GitOps Patterns: Experience with multi-cluster management and GitOps workflows (e.g., ArgoCD, Flux) for deploying and maintaining workloads across multi-region or on-prem environments.

  • Multi-tenant Regulated SaaS: Experience with compliance (finserv, healthcare, public sector), data residency, audit logging, and encryption-at-rest requirements.

  • Integration/ESB Runtimes: Familiarity with engines like Apache Camel or durable-execution/workflow orchestration engines (e.g., Temporal.io).

  • API Gateways: Rate limiting, mTLS termination, per-tenant quotas.

  • AI/LLM Infrastructure: Basic familiarity with vector databases, self-hosted inference, or GPU node pools.

Tech stack
  • Orchestration: Managed Kubernetes (EKS/GKE) + On-Prem/Lightweight K8s (K3s/Rancher)

  • IaC & GitOps: Terraform, ArgoCD/Flux

  • Messaging & Data: Apache Kafka (KRaft mode)

  • Identity & Secrets: Keycloak (OIDC/RBAC), HashiCorp Vault

  • Observability: OpenTelemetry, Prometheus, Loki, Tempo

Great people rarely fit completely into job descriptions.

Different perspectives make better ideas, stronger teams, and better outcomes for our customers.

Come build with us.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior DevOps Engineer
Senior DevOps Engineer

Refold AI • Bengaluru

On-site
INR 4,000,000 - 6,500,000
Senior Devops Engineer
Senior Devops Engineer

Randstad • Hyderabad

Hybrid
INR 4,200,000 - 6,500,000
DevOps Engineer
DevOps Engineer

NAVVYASA CONSULTING PRIVATE LIMITED • Gurugram District

On-site
INR 800,000 - 1,200,000
Lead / Senior Engineer – Build, Release & Deploy (K8s Operations & Observability)
Lead / Senior Engineer – Build, Release & Deploy (K8s Operations & Observability)

RackBank Datacenters Private Ltd. • Bengaluru

On-site
INR 4,000,000 - 6,500,000
Competitive compensation
Growth opportunities
Tooling & automation culture
Infra Team Manager
Infra Team Manager

Krafton • Bengaluru

On-site
INR 1,500,000 - 2,000,000
Platform Engineer (Performance & Reliability)
Platform Engineer (Performance & Reliability)

QUIPU • Hyderabad

On-site
INR 1,800,000 - 3,200,000
DevOps Engineer
DevOps Engineer

zenda • Bengaluru Urban

On-site
INR 3,500,000 - 5,500,000
Senior Site Reliability Engineer
Senior Site Reliability Engineer

Headout • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Senior Devops Engineer
Senior Devops Engineer

Artech L.L.C. • India

On-site
INR 4,000,000 - 7,000,000
DevOps Lead - hiver
DevOps Lead - hiver

OpenTalent • Karnataka

On-site
INR 2,000,000 - 4,200,000