Lead Infrastructure Engineer
Rojo Integrations · Breukelen, Netherlands
You apply on the site where the job is posted. I never handle applications.
Role in one sentence
A hands-on infrastructure lead who owns the Kubernetes-native foundation for Rojo's New Integration Products. This covers the cluster, IaC, secrets, identity, messaging, and observability.
This is a greenfield build. There's no legacy infra and no existing conventions to inherit. Every foundational decision gets made once, by this person, and lived with for years. That takes someone senior enough to set direction and own it. As we scale, this person will build and lead a team. Right now, the focus is architecture. The person writes the Terraform, configures the cluster, debugs the Kafka broker.
The infra has to cover several key pillars from day one:
- Tenant Isolation: Namespace-per-tenant, default-deny network policy, per-tenant secrets, and identity realms.
- Hybrid & On-Prem Deployment: Hosting central control planes in the cloud while supporting deployment across on-premises or private cloud customer environments.
- Durability & Messaging: Kafka as the backbone for event-driven components.
- EU Data Sovereignty: Region, encryption, audit trails, and self-hosted vs. managed choices that hold up under GDPR and EU AI Act rules.
- Observability: Every span, log, and metric traceable per tenant across all deployed environments.
Must-haves
- 5+ years of experience owning production infrastructure end-to-end at a startup or scale-up. Ideally as an early or first infra hire with full accountability.
- Kubernetes Expertise (Managed & On-Prem): Strong experience with cloud-managed K8s (EKS/GKE) as well as self-hosted, bare-metal, or lightweight distributions (e.g., K3s, Rancher, OpenShift) for on-premise setups. Deep grasp of namespace-per-tenant patterns, ResourceQuota/LimitRange, NetworkPolicy (default-deny), Pod Security Admission, and autoscaling.
- Hybrid Networking & Connectivity: Experience with secure cross-environment networking (VPNs, mTLS, reverse proxies, WireGuard) to establish reliable communication between cloud control planes and on-premise execution nodes.
- Terraform / IaC: Modular design (network / cluster / IAM / tenant-namespace / addons), remote state with locking, and state-splitting for blast-radius control. Treats IaC as a long-lived codebase.
- Apache Kafka: Production experience (ideally KRaft mode). Broker sizing, replication/AZ placement, Schema Registry, DLQ/DLT, and retry topology.
- Identity & Secrets Infrastructure: An OIDC/RBAC identity provider (e.g., Keycloak) with per-tenant realm patterns. A secrets manager (e.g., Vault) with Kubernetes-native auth and zero-hardcoded-secrets enforcement.
- CI/CD: Practical experience with pipelines (e.g., GitHub Actions), lint/test/build/push/deploy flows, OIDC-based cloud auth, and secret-scanning pre-commit hooks.
- Observability Infrastructure: OpenTelemetry Collector deployment patterns and a metrics/logs/traces stack (e.g., Prometheus, Loki, Tempo) built to be tenant-aware across hybrid environments.
- Leadership & Independence: Sets technical direction, defends architecture choices (e.g., node pool strategy, partitioning, IAM boundaries), and prioritizes ruthlessly without needing a pre-built roadmap.
- Language: Fluent English. Works well directly within a small, fast-moving technical team.
Nice-to-haves
- GitOps Patterns: Experience with multi-cluster management and GitOps workflows (e.g., ArgoCD, Flux) for deploying and maintaining workloads across multi-region or on-prem environments.
- Multi-tenant Regulated SaaS: Experience with compliance (finserv, healthcare, public sector), data residency, audit logging, and encryption-at-rest requirements.
- Integration/ESB Runtimes: Familiarity with engines like Apache Camel or durable-execution/workflow orchestration engines (e.g., Temporal.io).
- API Gateways: Rate limiting, mTLS termination, per-tenant quotas.
- AI/LLM Infrastructure: Basic familiarity with vector databases, self-hosted inference, or GPU node pools.
Tech stack
- Orchestration: Managed Kubernetes (EKS/GKE) + On-Prem/Lightweight K8s (K3s/Rancher)
- IaC & GitOps: Terraform, ArgoCD/Flux
- Messaging & Data: Apache Kafka (KRaft mode)
- Identity & Secrets: Keycloak (OIDC/RBAC), HashiCorp Vault
- Observability: OpenTelemetry, Prometheus, Loki, Tempo
Great people rarely fit completely into job descriptions.
If you’re curious, driven, and excited by what we’re building, apply - even if your experience doesn’t match every bullet point.
Different perspectives make better ideas, stronger teams, and better outcomes for our customers.
Come build with us.