waypointjobs

Novacard

DevOps

Remote — Worldwide (see timezone requirements)

Check who can apply and the requirements below before continuing.

Job description

At NOVACARD, we’re redefining how people use credit. We are the first interest-free and no-annual-fee credit card in Mexico, designed to simplify personal finances and give users complete control - all from a mobile app. With NOVACARD, users can access up to $200,000 MXN in credit, only pay when they use it, and manage everything digitally in under 5 minutes. Our mission is to empower people to make smarter financial decisions by offering flexibility, transparency, and the freedom they need to reach their goals. Simple finances, big goals.

About the Role:

We’re looking for a DevOps Engineer to design, deploy, and operate AWS infrastructure for a large-scale migration of a digital financial product. You’ll build and maintain a production-ready platform covering AWS networking, Kubernetes/EKS, CI/CD, observability, backup/restore, and secure access management. You’ll collaborate closely with development, system analysis, QA, and engineering teams to ensure fast delivery, stable services, and a controlled migration.

Key Responsibilities:

AWS Infrastructure Design & Operations

Design, deploy, and maintain AWS infrastructure: VPC, Subnets, Route Tables, Security Groups, IAM, EC2, EBS, S3, ELB/ALB/NLB, Route53.

Configure AWS networking: public/private subnets, NAT Gateway, Internet Gateway, VPC Peering / Transit Gateway, VPN, routing.

Ensure HA, backup/restore, disaster recovery, and production infrastructure principles.

Create and maintain AWS infrastructure as code using Terraform.

Kubernetes & Containerization

Build and operate Kubernetes on AWS (EKS).

Work with core Kubernetes objects: Deployment, StatefulSet, DaemonSet, Service, Ingress, ConfigMap, Secret, Job/CronJob, PVC/PV, Namespace, ServiceAccount.

Use Helm for application management.

Configure Ingress Controller, Load Balancer, and TLS/certificates.

Understand Kubernetes storage and ensure stateful applications run reliably.

Work with Docker: image builds, registry, container troubleshooting.

CI/CD & Automation

Build CI/CD processes, preferably with GitLab CI.

Automate deployment of applications and dependent services.

Integrate infrastructure changes into pipelines and maintain reproducible environments.

Observability, Reliability & Operations

Set up monitoring with Prometheus + Grafana: metrics and alerts.

Organize centralized log collection and analysis: Loki/ELK/OpenSearch.

Diagnose network and system issues in Linux.

Ensure production stability, respond to incidents, and eliminate root causes.

Security & Access Management

Manage secrets: AWS Secrets Manager / Vault/OpenBao / External Secrets.

Configure RBAC/IAM and follow the principle of least privilege.

Ensure secure service-to-service communication and infrastructure access.

Data & Services

Support PostgreSQL, Redis, RabbitMQ/Kafka at the infrastructure and application integration level.

Ensure backup/restore and fault tolerance for stateful services.

Help teams deploy and maintain dependent services in Kubernetes.

Requirements

Key Requirements:

AWS & Networking

Strong AWS experience: VPC, Subnets, Route Tables, Security Groups, IAM, EC2, EBS, S3, ELB/ALB/NLB, Route53.

Good understanding of AWS networking: public/private subnets, NAT Gateway, Internet Gateway, VPC Peering / Transit Gateway, VPN, routing.

Kubernetes & Containers

Hands-on experience building and operating Kubernetes on AWS (EKS).

Understanding of core Kubernetes objects: Deployment, StatefulSet, DaemonSet, Service, Ingress, ConfigMap, Secret, Job/CronJob, PVC/PV, Namespace, ServiceAccount.

Experience with Helm.

Experience configuring Ingress Controller, Load Balancer, and TLS/certificates.

Experience with Docker: image builds, registry, container troubleshooting.

Understanding of Kubernetes storage and stateful application operation.

IaC & CI/CD

Terraform — creating and maintaining AWS infrastructure as code.

Experience building CI/CD, preferably GitLab CI.

Data, Queues & Storage

Experience with PostgreSQL, Redis, RabbitMQ/Kafka at the infrastructure and application integration level.

Understanding of HA, backup/restore, disaster recovery, and production infrastructure principles.

Monitoring, Logging & Secrets

Monitoring: Prometheus + Grafana, configuring metrics and alerts.

Centralized log collection and analysis: Loki/ELK/OpenSearch.

Secrets management: AWS Secrets Manager / Vault/OpenBao / External Secrets.

Linux & Security

Linux administration and confident diagnosis of network and system issues.

Experience configuring RBAC/IAM and following the principle of least privilege.

Especially Important Practical Experience:

The engineer must be able to design an AWS network from scratch → set up EKS → deploy an application and dependent services → configure ingress/DNS/TLS → CI/CD → monitoring/logging → backup → hand over a production-ready infrastructure for operation.

Nice to Have:

Experience migrating lending systems or fintech products.

Experience building CI/CD with GitLab CI.

Hands-on experience with Vault/OpenBao, External Secrets.

Experience with Kafka and stateful services in Kubernetes.

What We Offer:

Participation in a large-scale migration of a digital financial product.

Work with a modern stack: AWS, Kubernetes/EKS, Terraform, CI/CD, Prometheus/Grafana.

Close collaboration with development, system analysts, QA, and engineers.

Opportunity to build a production-ready platform from scratch and hand it over to operations.

Terms and work format — discussed individually

Originally posted on Himalayas

Who can apply

The source lists worldwide eligibility. Accepted UTC offsets: UTC-11, UTC-10, UTC-9.5, UTC-9, UTC-8, UTC-7, UTC-6, UTC-5, UTC-4, UTC-3.5, UTC-3, UTC-2, UTC-1, UTC+0, UTC+1, UTC+2, UTC+3, UTC+3.5, UTC+4, UTC+4.5, UTC+5, UTC+5.5, UTC+5.75, UTC+6, UTC+6.5, UTC+7, UTC+8, UTC+8.75, UTC+9, UTC+9.5, UTC+10, UTC+10.5, UTC+11, UTC+12, UTC+12.75, UTC+13, UTC+14. Review the full description for employer-specific work authorization, residency and schedule requirements.

Ready for your next step?Apply on the official website
Apply on Himalayas ↗

Explore related searches

Current related jobs

infisical

Jobicy

Senior Full Stack Engineer

Remote — Brazil, Canada, Europe, USA

Salary not specifiedRemote

Infisical is the open source security infrastructure platform that engineers use for secrets management, certificates, and privileged access mana…

Listing review due 2026-10-07View job

Spotify

Jobicy

Data Scientist - Music Mission

Remote — USA

Salary not specifiedRemote

The Music Mission enables music creators to grow, engage, and monetize their fan bases on Spotify. Central to the Music Mission's vision is the d…

Listing review due 2026-10-07View job

Spotify

Jobicy

Data Scientist - Music Promotion

Remote — USA

Salary not specifiedRemote

The Music Mission enables Music creators to grow, engage & monetize their fan bases on Spotify. Central to the Music Mission's vision is the deve…

Listing review due 2026-10-07View job

infisical

Jobicy

Strategic Finance

Remote — Canada, USA

Salary not specifiedRemote

Infisical is the open source security infrastructure platform that engineers use for secrets management, certificates, and privileged access mana…

Listing review due 2026-10-07View job