Your role with us
As Senior Platform Engineer, you own the platform that Workist's AI agents run on: two clouds, the Kubernetes clusters for production, staging and ML workloads, and the path from merge request to production for every service we ship. You decide how this platform evolves, you keep it secure, observable and cost-efficient, and you extend it as the product grows. Most recently that meant an LLM gateway with region failover in front of our Azure OpenAI deployments, and performing GPU capacity planning for our own models.
You set your own roadmap. Infrastructure at Workist is run as quarterly themes that you propose, make the case for and deliver, and roughly a third of your time goes to whatever the week brings: an incident, a pentest finding, a developer whose deployment is stuck and needs a second pair of eyes. You report to our CTO and are the voice of the platform in engineering decisions.
How we build and run things
Everything runs on Kubernetes (Azure AKS), deployed with Helm and GitOps/Flux. All infrastructure is Terraform, applied through CI.
CI/CD for every service on GitLab
Managed services wherever they keep life simple: Postgres, OpenSearch, Redis, blob storage. We self-host only where it clearly pays off.
Two clouds: Azure as our primary cloud, AWS for search and mail ingestion.
Python everywhere: read and fix application code when that is where the fix belongs.
Security is routine: automated scanning in every pipeline, regular external pentests, quarterly backup and disaster-recovery tests.
Your responsibilities
Own the platform
Own the architecture of our cloud environments across Azure and AWS: how subscriptions, networks, identities and environments are structured and stay isolated
Design and deliver the platform capabilities the product needs next, from GPU capacity and an LLM gateway to new environments
Set the standard for how we run Kubernetes and our managed data services: capacity planned ahead of growth, changes and upgrades rolled out safely and routinely, costs kept in check
Keep it quiet
Own the security posture end to end: least-privilege access, network isolation, findings from scanners and pentests, and a patch cadence that runs itself. Be a technical counterpart for audits and security questionnaires
Own observability and alerting so that every alert is worth acting on, and lead the response to platform incidents including the follow-up fixes
Run quarterly backup/restore and disaster-recovery tests, and close what they reveal
Make the team faster
Own the path from merge request to production: fast builds, reliable deployments, environments and access on demand
Build the infrastructure behind our AI models: the LLM gateway, model deployments with region failover, GPU capacity, and whatever the next model needs
Your profile
We're looking for a professional team player who thrives in an environment where we share knowledge openly and push each other to deliver the best possible outcome. What you bring:
You have run production infrastructure for years, ideally as the person who owned it end to end rather than one of many in a large ops team
Kubernetes and Terraform in production: cluster upgrades, Helm, GitOps, and infrastructure as code for a whole cloud estate
Production experience on Azure or AWS. Most of our estate is Azure, so an AWS background works if you are willing to go deep on Azure.
Active Python skills: you read and debug a Python codebase and fix the application when the application is what is broken
Security as a habit: you have run patch management, handled pentest findings and designed least-privilege access, and you prioritise findings pragmatically
You write clearly: runbooks, incident write-ups and architecture decisions that others can follow
Fluent English (engineering runs in English, so German is not required, though it can help in some customer and vendor conversations)
Our benefits & culture
- Worki Tower: Our office in the heart of the city over 8 floors invites you to work professionally at an ergonomic workplace and gives you space for your creativity. Our own Workist Lounge awaits you with a cozy atmosphere including coffee, drinks and a vitamin basket for short or longer creative breaks. Play table tennis, darts or Nintendo to clear your head and exchange ideas with other teams.
- Flexible working hours: Shape your working day with our flexible working hours. Have important appointments in the morning or evening? No problem, take advantage of work schedule flexibility.
- Office, Remote & Workation: You decide yourself and have the flexible choice between an office or remote from your favorite location! We give you the freedom to work 4 weeks a year from abroad. Your state-of-the-art hardware will accompany you on your way!
- Come-Together: Let's play together - let's celebrate together! End the working day with a cool drink in our lounge or enjoy the time with your colleagues at the summer party, Christmas party or our quarterly team events.
- Stay fit & healthy: Your fitness is important to us, so join our weekly RunningLunch and connect with your colleagues. Work-life balance and reduction of your stress level included.
- Stay mobile: Choose between Deutschlandticket Job and a JobRad allowance and be mobile throughout Berlin and/or Germany.
- Be social: For your heart's project or to get involved in social and volunteer work, we support you with 3 additional "Social Days".
- Further your education - with a personal development budget of EUR 1,000.00 per year.