Mid DevOps Engineer (Security and Reliability)

Posted 4 Days Ago
Be an Early Applicant
Hiring Remotely in Poland
Remote
96K-96K Annually
Senior level
Healthtech • Information Technology • Software • Telehealth
The Role
Own the security and reliability of a multi-region AWS infrastructure, including Envoy-based edge protection, WAF, rate limiting, cloud security posture, secrets, certificates, PostgreSQL and search platforms, and observability. Build reliable monitoring, alerting, detection, and runbooks while supporting ISO 27001 audits and enterprise security reviews. Participate in compensated on-call rotation and document threat models, decisions, and operational procedures.
Summary Generated by Built In
Mid DevOps Engineer (Security and Reliability)

Physitrack PLC · Fully remote, based in Poland Contract: B2B contractor, EUR 6,000-8,000 per month

About us

Physitrack PLC builds digital health software used by clinicians, physiotherapists and employers in over 100 countries. Our two product lines, Physitrack (exercise prescription, telehealth and patient engagement) and Champion Health (workplace wellbeing), run on a multi-region AWS platform serving Europe, the UK, North America, Australia and the Middle East.

We are ISO 27001:2022 certified. We hold clinical data and a large proprietary content library, and both need defending properly.

The role

You will own the security and reliability surface of our infrastructure: the edge, the data layer, and the observability stack that tells us when either is misbehaving. It sits where security engineering meets SRE. You will design controls at the edge, harden our cloud posture, make sure we can see what is happening across a multi-region estate, then evidence all of it to auditors and enterprise customers. This is hands-on engineering, not a governance role.


We are recruiting two senior infrastructure roles. This one covers the edge, observability and cloud security posture. The other, Senior DevOps Engineer (Platform), covers the Kubernetes estate, delivery pipelines and migrations. Apply for whichever fits, and tell us if both do.

What you will do

Edge and network security

  • Own our Envoy based edge, along with WAF rules, rate limiting and bot management across our cloud and CDN layers

  • Design and tune protections against abuse, including content scraping, credential attacks and traffic anomalies

  • Build detection for the traffic patterns that matter, and keep improving its signal to noise ratio


Cloud security posture

  • Harden our AWS estate: IAM boundaries, least privilege access, threat detection and runtime monitoring on EKS

  • Manage secrets, certificates and token lifecycle across the platform

  • Produce the infrastructure evidence behind ISO 27001 audits, penetration tests and enterprise security reviews


Data platform

  • Run PostgreSQL and RDS in production across regions, covering upgrades, performance, encryption and access control

  • Own our search infrastructure, Typesense and vector search, end to end

  • Work with MongoDB and Elasticache alongside the primary data stores


Observability

  • Own the monitoring platform: Grafana, Loki and Prometheus, plus Sentry and PagerDuty

  • Build alerting people actually trust, with meaningful thresholds, low noise and clear runbooks

  • Improve how logs and metrics flow from the edge and the application into the stack

What we are looking for

Essential

  • 5+ years in infrastructure, SRE or security engineering, with strong AWS depth

  • Real experience with edge, WAF or reverse proxy technology: Envoy, nginx, Cloudflare, ModSecurity, Coraza or equivalent

  • Production Kubernetes, ideally EKS, and strong Terraform

  • Operating PostgreSQL at scale. You have done upgrades and performance work, not just connected to one

  • Practical observability experience. You have built alerting that worked, and killed alerting that did not

  • A security engineer's instincts. You think about what an attacker does with the thing you just shipped

  • English at a working professional level. Our engineering team is international

Nice to have

  • Search infrastructure: Typesense, Elasticsearch, OpenSearch or vector search

  • Content protection and anti-scraping work

  • Having supported ISO 27001, SOC 2 or similar audits from the technical side

  • Healthcare, fintech or another regulated domain

  • Polish. Much of the engineering team is in Poland, though the company works in English

How we work
  • On-call. We run a 24/7 rotation through PagerDuty, with documented playbooks and readiness checklists. Participation is agreed with you rather than assumed, and separately compensated.

  • Cadence. Written async updates, a fortnightly planning touchpoint and a regular infrastructure and security sync. You set your own hours and choose your own tools.

  • Documentation. Threat models, decision records and runbooks are part of the work. We expect the reasoning to be written down, not just the config.

  • Autonomy. Small team, wide scope, very little process between you and a decision.

Skills Required

  • 5+ years of experience in infrastructure, SRE, or security engineering
  • Strong AWS experience
  • Production experience with edge, WAF, or reverse proxy technologies such as Envoy, NGINX, Cloudflare, ModSecurity, or Coraza
  • Production Kubernetes experience, ideally Amazon EKS
  • Strong Terraform experience
  • Experience operating PostgreSQL at scale, including upgrades and performance work
  • Practical observability experience building effective alerting
  • Security engineering mindset and ability to assess attacker behavior
  • Working professional level English
  • Experience with Typesense, Elasticsearch, OpenSearch, or vector search
  • Experience with content protection and anti-scraping
  • Technical support for ISO 27001, SOC 2, or similar audits
  • Experience in healthcare, fintech, or another regulated domain
  • Polish language proficiency
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
Year Founded: 2012

What We Do

Physitrack PLC is a global digital healthcare provider specializing in physiotherapy and musculoskeletal care. The company offers a SaaS-based platform that enables healthcare practitioners to create customized home exercise programs, prescribe education, and track patient outcomes. Through its Lifecare and Wellness divisions, Physitrack aims to elevate global wellbeing by providing remote patient engagement and virtual-first care solutions.

Similar Jobs

Mondelēz International Logo Mondelēz International

Senior Director, Global Supply Chain Excellence Program & Focused Improvement Lead

Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
Remote or Hybrid
29 Locations
90000 Employees
174K-287K Annually

Atlassian Logo Atlassian

Principal Forward Deployed Engineer, AI (Remote Poland)

Cloud • Information Technology • Productivity • Security • Software • App development • Automation
In-Office or Remote
Gdańsk, Pomorskie, POL
11000 Employees
350K-457K Annually

Capco Logo Capco

Senior Delivery Lead Manager – Modern Core Banking (She/ He/ They)

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
Poland
6000 Employees

Capco Logo Capco

Senior Manager – Risk & Regulatory (She/ He/ They)

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
Poland
6000 Employees

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software • Productivity
US
15 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account