Staff DevOps Engineer
Identity DigitalAbout the role
Summary / Objective
Identity Digital is building DNS-native identity infrastructure for AI agents and other non-human identities: a durable, governance-backed domain name that serves as an agent’s foundational identity. Our managed service is evaluation-ready today, and we are taking it to enterprise general availability. The platform underneath it needs an owner.
You will join a small team early, own the infrastructure architecture, build the platform, and then build the operational practice around it. Success in the first six months is a production platform ready for enterprise customers, with clear reliability targets, tested recovery, and a delivery pipeline the whole team trusts. Success in the first year is an operational practice for on-call, incidents, capacity, and cost that holds up while the engineering team doubles.
What You'll Do
- Own the technical direction for our cloud infrastructure: the architecture across services, build-versus-buy decisions, and the standards other engineers build against
- Design, build, and operate the cloud-native platform behind our multi-tenant managed service, including tenant isolation, capacity planning, and disaster recovery
- Own production readiness for enterprise launch: SLOs and error budgets, runbooks, failover testing, and business continuity
- Run DNS as production infrastructure: zone operations, DNSSEC, registrar and provider integrations, and failover across providers. DNS is the product here, not plumbing
- Operate the signing and certificate infrastructure behind agent identity in partnership with security engineering: key custody, rotation, signing-path availability, and certificate lifecycle at scale
- Build the delivery pipeline for an AI-assisted engineering team, where CI is the enforcement boundary: policy-as-code, required checks, and the guardrails that make machine-authored contributions safe to merge
- Ship releases with integrity for everything we publish: signed artifacts, provenance, and supply-chain controls for our open-source SDKs and tools
- Instrument the platform with logging, metrics, and tracing so problems are found before customers notice them
- Automate the infrastructure side of audit readiness: audit logging and retention, access reviews, and evidence collection that runs itself
- Keep cloud spend visible and healthy as usage grows, including unit economics per tenant and per workload
- Multiply the team: review designs across engineering, mentor engineers on operational practice, and help set the hiring bar as we grow
- Stand up the on-call practice, act as incident commander when production breaks, and drive a blameless postmortem culture
- Actively model and promote Identity Digital’s core values through day-to-day interactions, behaviors, and decision-making
- Other duties as assigned
Who You Are / What You Bring
- 10+ years in DevOps, site reliability, or platform engineering, including work at principal or staff scope: setting direction across teams rather than executing inside one
- Bachelor’s degree in a relevant field or equivalent experience
- Deep experience with cloud-native architectures and services (AWS/GCP preferred).
- Strong proficiency with Kubernetes, Terraform, and modern infrastructure-as-code practice
- Hands-on experience with CI/CD systems (GitHub Actions, GitLab CI, ArgoCD, or similar)
- Strong scripting or programming skills in Python, Go, or TypeScript/JavaScript.
- Experience building observability stacks (Prometheus, Grafana, ELK/EFK, OpenTelemetry)
- Working depth in DNS operations: zone management, DNSSEC, and how registrars, resolvers, and authoritative providers behave in production
- Solid understanding of PKI, secrets management, and certificate workflows, including how these systems fail under attack
- Experience running multi-tenant SaaS and distributed systems in production, including incident command
- A track record of raising the operational bar of the teams around you through standards, design review, and mentoring
- Ability to travel as needed
- Ability to work effectively across time zones on a distributed team
Preferred Qualifications
- Experience operating signing infrastructure or a certificate authority at scale: HSM or KMS key custody, key ceremonies, rotation without downtime
- Supply-chain security in practice: SLSA, sigstore/cosign, reproducible builds, and provenance for published artifacts
- Familiarity with agentic AI systems and their operational surface: machine-scale request patterns, short-lived credentials, egress control, and the OWASP Agentic and NHI Top 10
- Infrastructure-side experience with SOC 2 or a comparable aud
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s