Senior Software Engineer, Platform
DittoAbout the role
About Ditto:
Ditto is redefining how data moves at the edge. Our mission is to make it seamless for developers to build resilient, real-time applications, regardless of network conditions. Whether you're in a stadium, airplane, or remote military base, Ditto's peer-to-peer sync engine ensures devices stay connected and data stays consistent, even without internet. With more than $145 million in funding and trusted by organizations like Chick-fil-A, Delta Airlines, and the U.S. military, Ditto powers mission-critical experiences across aviation, retail, travel, hospitality, defense, and more. As a globally distributed, fast-growing startup, we’re committed to building a diverse and inclusive team that reflects the wide range of perspectives needed to solve the world’s hardest connectivity problems.
We're looking for a Platform Engineer that can work REMOTE, to own and architect Ditto's multi-cloud Kubernetes infrastructure. In this role, you'll build the platform that enables enterprise customer deployments across Azure, AWS, and GCP—from cluster provisioning to cross-cloud identity federation to secure access management. This is greenfield infrastructure work with direct business impact: enterprise customers are waiting for these capabilities, and the company's product roadmap depends on what you build. You'll define how we deploy and operate across cloud providers, solving genuinely hard distributed systems problems while creating infrastructure that feels consistent and reliable regardless of where it runs.
What You'll Be Up To…
Own the architecture and evolution of Ditto's managed Kubernetes platform across AKS, EKS, and GKE, ensuring consistent operational excellence across cloud provider boundaries
Design and implement cross-cloud identity and authentication systems, including OIDC delegation and identity federation patterns that enable secure service communication across AWS, Azure, and GCP
Build secure access infrastructure that provides auditable cluster access for operations teams, including automated emergency access procedures and compliance controls
Architect cloud account governance systems covering provisioning, resource management, policy enforcement, and multi-tenant isolation across providers
Design ingress and traffic management patterns that replace legacy components with cloud-native solutions integrated into each provider's ecosystem
Create infrastructure lifecycle tooling that provisions, configures, and migrates Kubernetes environments—including migration paths from legacy self-managed clusters to managed Kubernetes
Partner with the Cloud Organization and customer-facing teams to ensure infrastructure capabilities align with product roadmap requirements and enterprise customer needs
What Helps You Thrive…
Deep experience with managed Kubernetes platforms (AKS, EKS, or GKE) in production environments, including cluster lifecycle management and operational tooling
Strong multi-cloud fluency—you understand the differences between cloud providers and can design abstractions that respect each platform's constraints while delivering consistent experiences
Track record of solving complex authentication and identity challenges, particularly across trust boundaries or federated environments
Systems thinking orientation—you see infrastructure as interconnected platforms, not isolated components, and architect for long-term evolution
Comfort with enterprise customer requirements—you've built infrastructure subject to security reviews, compliance standards, and sophisticated operational expectations
Ability to operate under timeline pressure with real consequences—you're energized by work that's on the critical path, not paralyzed by it
A proactive and curious attitude about how AI can support your role through automation, ideation, or more thoughtful decision-making
Great-to-Haves…
Experience with infrastructure-as-code at scale (Terraform, Pulumi, Crossplane) across multiple cloud providers
Background in BYOC, self-hosted, or customer-managed deployment models where infrastructure runs in environments you don't fully control
Familiarity with secure access tooling (Teleport, Boundary, or similar) and zero-trust access patterns
Prior work migrating production workloads between Kubernetes environments or from self-managed to managed Kubernetes
Experience with cloud account vending, organizational policies, or multi-tenant cloud architectures
Understanding of Kubernetes networking, ingress controllers, and service mesh patterns
Open source contributions or community
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s