Senior Devops Engineer

Physitrack PLC

United States

Remote

USD 77,000 - 103,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Physitrack PLC is seeking a Mid DevOps Engineer focused on security and reliability. This fully remote, Poland-based role centers on securing edge, data, and observability across a multi-region AWS platform.

You will implement edge controls, strengthen cloud posture, and evidence security for audits and customers. Beyond hands-on engineering, you’ll design detections for abuse and traffic anomalies, run PostgreSQL at scale, and own the observability stack.

Qualifications

  • 5+ years in infrastructure, SRE or security engineering with AWS depth.
  • Hands-on with edge, WAF or reverse proxy tech: Envoy, Nginx, Cloudflare, ModSecurity or equivalent.
  • Production Kubernetes (ideally EKS) and Terraform experience.
  • PostgreSQL at scale with upgrades and performance work.
  • Proven observability skills and meaningful alerting.
  • Security mindset: think like an attacker; strong English in a multinational team.

Responsibilities

  • Own the edge and network security with Envoy-based edge, WAF rules, rate limiting and bot management.
  • Harden AWS estate with IAM boundaries, least privilege, threat detection and runtime monitoring on EKS.
  • Manage secrets and certificates across the platform and prepare ISO 27001 audit evidence.
  • Run PostgreSQL and RDS across regions; manage search infrastructure (Typesense) and data stores.
  • Own monitoring stack: Grafana, Loki, Prometheus, Sentry and PagerDuty; build trusted alerts.

Skills

AWS depth
Envoy edge
Kubernetes (EKS)
Terraform
PostgreSQL at scale
Observability
English proficiency

Tools

Nginx
Cloudflare
ModSecurity
Coraza
Typesense
OpenSearch
Grafana
Prometheus
PagerDuty
Sentry

Job description

Mid DevOps Engineer (Security and Reliability)

Physitrack PLC · Fully remote, based in Poland Contract: B2B contractor, EUR 6,000-8,000 per month

About us

Physitrack PLC builds digital health software used by clinicians, physiotherapists and employers in over 100 countries. Our two product lines, Physitrack (exercise prescription, telehealth and patient engagement) and Champion Health (workplace wellbeing), run on a multi-region AWS platform serving Europe, the UK, North America, Australia and the Middle East.

We are ISO 27001:2022 certified. We hold clinical data and a large proprietary content library, and both need defending properly.

The role

You will own the security and reliability surface of our infrastructure: the edge, the data layer, and the observability stack that tells us when either is misbehaving. It sits where security engineering meets SRE. You will design controls at the edge, harden our cloud posture, make sure we can see what is happening across a multi-region estate, then evidence all of it to auditors and enterprise customers. This is hands-on engineering, not a governance role.

What you will do

Edge and network security

  • Own our Envoy based edge, along with WAF rules, rate limiting and bot management across our cloud and CDN layers

  • Design and tune protections against abuse, including content scraping, credential attacks and traffic anomalies

  • Build detection for the traffic patterns that matter, and keep improving its signal to noise ratio

Cloud security posture

  • Harden our AWS estate: IAM boundaries, least privilege access, threat detection and runtime monitoring on EKS

  • Manage secrets, certificates and token lifecycle across the platform

  • Produce the infrastructure evidence behind ISO 27001 audits, penetration tests and enterprise security reviews

Data platform

  • Run PostgreSQL and RDS in production across regions, covering upgrades, performance, encryption and access control

  • Own our search infrastructure, Typesense and vector search, end to end

  • Work with MongoDB and Elasticache alongside the primary data stores

Observability

  • Own the monitoring platform: Grafana, Loki and Prometheus, plus Sentry and PagerDuty

  • Build alerting people actually trust, with meaningful thresholds, low noise and clear runbooks

  • Improve how logs and metrics flow from the edge and the application into the stack

What we are looking for

Essential

  • 5+ years in infrastructure, SRE or security engineering, with strong AWS depth

  • Real experience with edge, WAF or reverse proxy technology: Envoy, nginx, Cloudflare, ModSecurity, Coraza or equivalent

  • Production Kubernetes, ideally EKS, and strong Terraform

  • Operating PostgreSQL at scale. You have done upgrades and performance work, not just connected to one

  • Practical observability experience. You have built alerting that worked, and killed alerting that did not

  • A security engineer's instincts. You think about what an attacker does with the thing you just shipped

  • English at a working professional level. Our engineering team is international

Nice to have

  • Search infrastructure: Typesense, Elasticsearch, OpenSearch or vector search

  • Content protection and anti-scraping work

  • Having supported ISO 27001, SOC 2 or similar audits from the technical side

  • Healthcare, fintech or another regulated domain

  • Polish. Much of the engineering team is in Poland, though the company works in English

How we work
  • On-call. We run a 24/7 rotation through PagerDuty, with documented playbooks and readiness checklists. Participation is agreed with you rather than assumed, and separately compensated.

  • Cadence. Written async updates, a fortnightly planning touchpoint and a regular infrastructure and security sync. You set your own hours and choose your own tools.

  • Documentation. Threat models, decision records and runbooks are part of the work. We expect the reasoning to be written down, not just the config.

  • Autonomy. Small team, wide scope, very little process between you and a decision.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Site Reliability Engineer
Site Reliability Engineer

sportygroup • United States

Remote
USD 150,000 - 210,000
Remote-first company
Competitive salary
Sr DevOps Engineer
Sr DevOps Engineer

Decca Consulting LLC • United States

Remote
USD 140,000 - 190,000
Senior DevOps Engineer
Senior DevOps Engineer

Decca Consulting LLC • United States

Remote
USD 140,000 - 210,000
Remote Senior DevOps Engineer - Edge Security & Reliability
Remote Senior DevOps Engineer - Edge Security & Reliability

Physitrack PLC • United States

Remote
USD 77,000 - 103,000
Weekend Site Reliability Engineer
Weekend Site Reliability Engineer

sportygroup • United States

Remote
USD 140,000 - 170,000
Remote-first company
Competitive salary with quarterlyBonu
28 days paid annual leave
+4
DevOps Engineer
DevOps Engineer

Decca Consulting • Norwalk (CT)

On-site
USD 120,000 - 180,000
Health insurance
Paid time off
Competitive salary
Weekend Site Reliability Engineer
Weekend Site Reliability Engineer

Sporty Group • United States

On-site
USD 120,000 - 180,000
Remote first
Bonuses (quarterly)
28 days leave
+4
SRE/DevOps
SRE/DevOps

NDEAVOUR CONSULTING • United States

Hybrid
USD 120,000 - 150,000
Remote Office
Parking Space
Fun Office Space
+7
Senior Devops Engineer (AWS)
Senior Devops Engineer (AWS)

Read-A-Thon • United States

On-site
USD 120,000 - 170,000
Systems & Security Engineer
Systems & Security Engineer

Fairly Inc. • Portland (OR)

Hybrid
USD 120,000 - 180,000
Collaborative environment
Impactful role in growth