Role Description
We ship self-hosted software into regulated enterprises. That means every deployment involves someone else's Kubernetes cluster, someone else's identity provider, someone else's network policy, and a security team that has to sign off before any of it runs.
You will own how Preql gets installed, secured, upgraded, and kept healthy in customer environments.
-
Installation and configuration of Preql in customer environments: our Docker images and Helm charts, deployment into customer managed Kubernetes across AWS, Azure, GCP, and on-premise.
-
Networking, identity, and access setup: private connectivity, SSO and SAML, IAM and role design, warehouse permissions, secrets management.
-
The deployment architecture for each account, including choosing the right configuration and making sure what is scoped in the SOW is what actually gets built.
-
Navigating customer IT environments to proactively uncover and resolve potential blockers.
-
Enterprise security and compliance review: questionnaires, data handling and residency requirements, architecture walkthroughs with customer security teams, and the escalations that come with regulated buyers.
-
Production health in customer environments: monitoring, upgrades, and first response when something breaks, rather than escalating straight to product engineering.
-
Release and versioning discipline that keeps every customer on a known, supportable configuration.
-
Runbooks, install automation, and reference architecture documentation that make each deployment faster than the last.
Qualifications
-
5+ years in infrastructure, platform, or DevOps engineering, shipping into production environments you did not control.
-
Docker and Kubernetes in production.
-
Depth in at least one of AWS, Azure, or GCP, and a working understanding of the constraints in the others.
-
Networking and identity in enterprise settings: VPCs and private connectivity, SSO and SAML, IAM and role design, secrets management.
-
CI/CD, observability, and incident response.
-
High SQL and data infrastructure literacy.
-
Comfort working directly with customers, including scoping, pushing back, and delivering bad news early.
-
High tolerance for ambiguity. Early deployments will not have a runbook, and you will write the runbook.
Requirements
-
You have packaged and shipped self-hosted or customer managed software, not just SaaS.
-
You have carried a deployment through a bank or other regulated buyer's security review and kept the project moving while it was in flight.
-
Familiarity with enterprise data infrastructure and the finance systems around it.
What Success Looks Like
-
90 days:
You have run an install end to end without product engineering in the room, and you can walk a customer's security team through our architecture yourself.
-
6 months:
Install time for a comparable customer has dropped measurably, every account is on a known version, and there is a runbook that did not exist before.
-
12 months:
Deployment is a repeatable process rather than a project, and product engineers are not being pulled into customer environments.