A Senior DevOps / Infrastructure Engineer in this role is responsible for building, optimizing, and maintaining a highperformance, secure, and globally distributed infrastructure. The position requires deep expertise in Linux systems, networking, monitoring, VPN technologies, and trafficevasion techniques used in modern privacyfocused environments.
**About the Role**
------------------
You will design and operate missioncritical infrastructure that supports largescale, highload systems. The work goes far beyond container management: it involves kernellevel tuning, advanced networking, VPN stack engineering, and building monitoring systems from the ground up. This is a role for someone who understands how systems behave under pressure and knows how to automate everything that repeats.
**Key Responsibilities**
------------------------
* Develop and evolve infrastructure architecture to ensure stability, scalability, and high availability.
* Build and automate CI/CD pipelines using GitLab, Ansible, and Terraform.
* Maintain and optimize Linux systems for highload environments, including kernel tuning and network performance adjustments.
* Configure and improve monitoring systems (Zabbix, Grafana), including custom templates, autodiscovery, and alerting logic.
* Manage and optimize VPN technologies such as StrongSwan, OpenVPN, and Xray.
* Analyze complex incidents, identify root causes, and implement longterm fixes.
* Ensure infrastructure security through access control, firewall management, updates, and 2FA.
* Collaborate with development and QA teams in a distributed environment.
* Participate in architectural decisions and guide the team through best practices.
#### **Core Skills and Expertise**
##### **Monitoring Engineering**
* Advanced proficiency with **Zabbix and Grafana**, including:
* custom templates,
* autodiscovery rules,
* external scripts,
* alerting pipelines,
* performance dashboards.
##### **Linux & Kernel Optimization**
* Deep understanding of **kernel and OS tuning** for highload systems:
* network I/O optimization,
* socket buffer tuning,
* IRQ affinity and CPU interrupt balancing,
* NIC queue configuration,
* sysctl tuning for throughput and latency.
##### **VPN Technologies**
* Handson experience configuring and optimizing:
* **StrongSwan (IPsec)**,
* **OpenVPN**,
* **Xray-core** (VLESS/REALITY, VMess, Shadowsocks).
* Understanding how VPN protocols behave under different network conditions and censorship environments.
##### **DPI Evasion & Traffic Obfuscation**
* Knowledge of **DPI/TSPU architecture** and modern circumvention techniques:
* domain fronting,
* SNI masking,
* ECH (Encrypted Client Hello),
* REALITY,
* uTLS fingerprinting.
* Familiarity with obfuscation protocols such as Shadowsocks2022, TrojanGFW, and Cloak.
##### **Additional Technical Areas**
* Scripting: Bash, sed, awk; Go or Python for tooling and automation.
* Virtualization: Proxmox, Docker, Portainer.
* Networking: firewalls (nftables/iptables), routing, PBR, VLANs, GRE/IPIP tunnels, tun/tap, veth, bridges.
* Databases: PostgreSQL or MySQL (schema design, optimization, replication basics).
* Automation: Ansible, Terraform.
* Cloud: AWS, Cloudflare, Hetzner.
* Logging: Elastic Stack, OpenSearch, Vector, Promtail, Loki.
* Kubernetes on bare metal: deployment, CNI, storage, operations.
* Secrets management: Infisical.
##### **Who Thrives in This Role**
* Engineers who understand systems deeply and enjoy solving complex infrastructure problems.
* People who automate everything and dislike repetitive manual work.
* Those who can take ownership of critical systems and support the team with expertise.
* Individuals comfortable working in distributed teams and communicating clearly in English.
##### **What the Company Offers**
* Fully remote, fulltime position with weekends off.
* Work with international, highimpact projects.
* Opportunities for professional growth and specialization.
* Competitive salary based on experience.
* A young, friendly, and technically strong team.