Senior Platform Operations Engineer, Infrastucture

Viome Life Sciences

Bellevue (WA)

On-site

USD 130,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Viome Life Sciences in Bellevue, WA, seeks a Senior Platform Operations Engineer, Infrastructure to own Viome’s Azure-based service platform and simplify it through robust Unix-based systems engineering.

You will migrate services from AKS to VM-based hosting, author systemd units, and build deployment scripts with a focus on immutable artifacts, rollback, and secure, scalable hosting. The role emphasizes governance, observability, and cross-cloud coordination.

Qualifications

  • 7+ years operating production Unix/Linux systems, with deep knowledge of systemd, process supervision; Apache, HAProxy
  • Strong shell plus one scripting language (bash/Python/PHP) with a track record of building deploy and rollback tooling, not just using it.
  • Demonstrated reverse-engineering ability: taking ownership of an undocumented production service and recovering its real dependencies and failure modes.
  • Message-queue literacy: Azure Service Bus, SQS, RabbitMQ, or equivalent — ordering, lock/ack semantics, dead-letter handling.
  • PostgreSQL operations: replicas/clones, connection proxying, network-restricted access, production diagnostics.
  • Working proficiency with Kubernetes and cloud networking — enough to operate private AKS clusters, an Istio-style ingress layer, and Azure firewall/DNS during the transition.
  • Migration experience: consolidating or re-platforming production services with zero-downtime cutover and tested rollback.
  • A demonstrable record of reducing system surface area — services consolidated, infrastructure retired.
  • Clear written communication for runbooks, migration plans, and cross-functional coordination.

Responsibilities

  • Plan and execute zero-downtime migrations of services from AKS/containers to VM-based hosting: systemd unit authoring and service supervision (restart policy, resource limits, sandboxing), Apache, HAProxy and/or nginx as reverse proxy and TLS terminator, certificate automation.
  • Build and own the deployment scripts for the target platform: build → test → archive → ship → symlink-flip → health-check → rollback, scripted in bash.
  • Preserve two non-negotiable invariants while simplifying everything else: immutable, commit-traceable artifacts and scripted rollback.
  • Inventory and retire stale infrastructure: dormant deployments, unused DNS records, orphaned firewall rules, unpinned image tags.
  • Maintain host hygiene for consolidated services: OS patching discipline, runtime vendoring, log rotation, centralized log aggregation.
  • Familiarity with UptimeKuma, Nagios or similar.
  • Operate and migrate data stores: PostgreSQL and/or MySQL.

Skills

Unix/Linux
systemd
Apache
HAProxy
Nginx
bash scripting
Python
PHP
Kubernetes
Azure
Networking
OpenTelemetry
ELK
Terraform

Tools

AKS
Docker
Istio
Terraform (IaC)
OpenTelemetry tooling

Job description

At Viome, we are driven by a singular mission: to help people live a healthy, disease-free life. This mission guides our actions, fuels our passion, and shapes the impact we aim to have in the world. Our core values - Be Bold, Be Collaborative, Be Frugal, and Grow Continuously - underpin our approach to achieving this goal. If you are motivated by the idea of working in an environment that prioritizes bold innovation, teamwork, efficient resource use, and continuous learning, all towards promoting health and preventing disease, we warmly invite you to apply. Join us in our journey to transform lives and create a healthier future for all.

We are looking for a Senior Platform Operations Engineer, Infrastructure to take ownership of Viome’s Azure-based service platform with a clear mandate: make it dramatically simpler through robust Unix-based systems engineering.

This is a consolidation role for a seasoned systems administrator. The work involves migrating a suite of abstracted services onto a deliberately stable target platform: Linux VMs, systemd-supervised services, Apache, HAProxy, and Nginx routing. You must possess strong Unix knowledge to operate and eventually transform the current stack safely. We are looking for a traditional operations background where success is measured by the removal of unnecessary layers and a genuine bias toward simplicity and host-level stability.

Responsibilities
Simplification & Migration (core mandate)
  • Plan and execute zero-downtime migrations of services from AKS/containers to VM-based hosting: systemd unit authoring and service supervision (restart policy, resource limits, sandboxing), Apache, HAProxy and/or nginx as reverse proxy and TLS terminator, certificate automation.
  • Build and own the deployment scripts for the target platform: build → test → archive → ship → symlink-flip → health-check → rollback, scripted in bash.
  • Preserve two non-negotiable invariants while simplifying everything else: immutable, commit-traceable artifacts and scripted rollback.
  • Inventory and retire stale infrastructure: dormant deployments, unused DNS records, orphaned firewall rules, unpinned image tags.
  • Maintain host hygiene for consolidated services: OS patching discipline, runtime vendoring, log rotation, centralized log aggregation.
  • Familiarity with UptimeKuma, Nagios or similar.
  • Operate and migrate data stores: PostgreSQL and/or MySQL.
Network and Infrastructure Operations
  • Operate and troubleshoot workloads during the transition, focusing on the networking layer, load balancing, and core platform services.
  • Administer the hub network: Azure Firewall rules, VPN gateways, VNet peering, public and private DNS zones and reason about a packet’s full path from public IP to service.
  • Support the existing release process and network and infrastructure operations until each service is migrated to the new VM-based standard.
  • Keep the observability stack healthy (OpenTelemetry, ELK, Grafana, uptime and cost monitoring) and carry its essentials forward to the simplified platform.
  • Coordinate cross-cloud dependencies with AWS: DNS/edge routing, queue consumers, and egress IP allowlists.
  • L2+ operations support; manage runbooks for external L0, L1 support.
External Integrations & Security
  • Own the external integrations most at risk during migration: e-commerce and subscription platforms, messaging/notification providers, and clinical/health-data partners — webhook delivery, signature verification, idempotency, and retry semantics.
  • Raise the security baseline as you consolidate: secrets management, webhook authentication, least-privilege network access, and data-retention hygiene. Findings from an internal review are ready for you to remediate; the instinct to spot and close this class of issue — and not create more — is part of the job.
Qualifications
Required
  • 7+ years operating production Unix/Linux systems, with deep knowledge of systemd, process supervision; Apache, HAProxy
  • Strong shell plus one scripting language (bash/Python/PHP) with a track record of building deploy and rollback tooling, not just using it.
  • Demonstrated reverse-engineering ability: taking ownership of an undocumented production service and recovering its real dependencies and failure modes.
  • Message-queue literacy: Azure Service Bus, SQS, RabbitMQ, or equivalent — ordering, lock/ack semantics, dead-letter handling.
  • PostgreSQL operations: replicas/clones, connection proxying, network-restricted access, production diagnostics.
  • Working proficiency with Kubernetes and cloud networking — enough to operate private AKS clusters, an Istio-style ingress layer, and Azure firewall/DNS during the transition. We will onboard you on our specifics; deep specialization is not required.
  • Migration experience: consolidating or re-platforming production services with zero-downtime cutover and tested rollback.
  • A demonstrable record of reducing system surface area — services consolidated, infrastructure retired.
  • Clear written communication for runbooks, migration plans, and cross-functional coordination.
Strongly Preferred
  • Azure networking at landing-zone depth: hub-spoke VNets, Azure Firewall, Private Link/Private DNS, VPN gateways.
  • Administration of external-dns, cert-manager, and policy engines such as Kyverno.
  • ELK and OpenTelemetry pipeline operations.
  • Webhook-heavy integration experience (e-commerce platforms such as Shopify, subscription billing, marketing/notification platforms, or healthcare data exchanges).
  • Experience in a regulated or health-data environment: PHI handling, audit trails, least-privilege network design.
  • Terraform or equivalent IaC for cloud network and compute resources.
  • Enough AWS to manage cross-cloud seams (Route53, SQS, egress allowlists).
  • AI minded; proficient with Claude or similar.
What Success Looks Like
  • First 30 days: Trace and fix a production issue end-to-end (DNS → firewall → ingress → service → database) with guidance; produce a true-dependency inventory for one candidate service.
  • First 90 days: First service migrated off AKS to the VM/systemd platform with a passing rollback drill; firewall rules, DNS zones, and cluster add-ons documented and reproducible; stale-resource inventory complete and retirement underway.
  • First 6 months: Migration cadence established with multiple services consolidated; release and rollback drills routine on both platforms; measurable reduction in infrastructure footprint and spend; security-baseline remediations closed.

$130,000 - $150,000 a year

Become part of a team that values your health, growth, and contributions to the health industry.

We believe that transparency in pay is essential to promoting fairness and accountability in our workplace. Therefore, we will provide candidates with the salary range for this position during the interview process. We also welcome and encourage candidates to discuss their compensation expectations with us during this process.

We are an equal opportunity employer and do not discriminate based on race, color, religion, sex, national origin, age, disability, or any other legally protected status. We value diversity, equity, and inclusion, and are committed to creating a workplace that reflects these values.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Platform Operations Engineer, Infrastucture
Senior Platform Operations Engineer, Infrastucture

Viome • Bellevue (WA)

On-site
USD 150,000 - 210,000
Senior Platform Engineer - Zero-Downtime Infra Migrations
Senior Platform Engineer - Zero-Downtime Infra Migrations

Viome Life Sciences • Bellevue (WA)

On-site
USD 130,000 - 150,000
Full-Stack Software Engineer Innovation
Full-Stack Software Engineer Innovation

Viome • Bellevue (WA)

On-site
USD 120,000 - 180,000
Competitive salary
Health insurance
Equity participation
+1
Senior Product Manager, Consumer
Senior Product Manager, Consumer

Viome • Bellevue (WA)

On-site
USD 110,000 - 140,000
Insurance premium coverage
Flexible Time Off
401(k) Plan
+1
Senior Technical Support Engineer – Software & IT Connectivity
Senior Technical Support Engineer – Software & IT Connectivity

Vitrafy Life Sciences • Denver (CO)

On-site
USD 130,000 - 155,000
Medical, dental, and vision plans
401(k) plan
Unlimited vacation & sick time
Senior Azure Cloud Engineer
Senior Azure Cloud Engineer

Vaxcyte • San Carlos (CA)

On-site
USD 163,000 - 191,000
Comprehensive benefits
Equity component
Competitive compensation
Senior DevOps Specialist
Senior DevOps Specialist

VIA • Washington

Hybrid
USD 165,000 - 195,000
401K plan with up to 5% employer contribution
Fully funded health benefits plan
Flexible vacation policy
+2
Senior DevOps Engineer
Senior DevOps Engineer

Qualified Health PBC • Palo Alto (CA)

Hybrid
USD 170,000 - 220,000
Equity
Medical/Dental/Vision insurance
Hybrid work options
+1
DevSecOps
DevSecOps

Veeam Software • San Jose (CA)

On-site
USD 111,000 - 184,000
Unlimited PTO
12 holidays incl. VeeaMe Days
Volunteer hours
+1
Senior DevOps Engineer
Senior DevOps Engineer

Transformcap • Palo Alto (CA)

Hybrid
USD 170,000 - 220,000
Equity
Medical insurance
Flexible hours
+1