With 1,000+ intelligence professionals serving over 1,900 clients worldwide, Recorded Future is the world's most advanced, and largest, intelligence company! Recorded Future equips our teams and customers with secure, isolated environments for high-risk research, threat analysis, and sensitive investigative work. To scale this capability, we rely on a container streaming platform that delivers browser-accessible desktops, applications, and isolated browsers on demand. As our operational footprint grows, we need an Application Support DevOps Engineer to own the deployment, tuning, and day-to-day health of this platform across our Kubernetes environments. Your work will directly enable analysts and internal teams to spin up disposable, policy-controlled workspaces, ensuring they have fast, reliable, and secure access to the tools they need without compromising our security posture.
What You'll Do
- Lead the deployment, upgrade, and lifecycle management of a containerized workspace streaming platform running on Kubernetes, including Helm chart customization, namespace and zone design, and configuration of core services such as the API, manager, and connection proxy components.
- Design, build, and maintain custom Docker images (desktops, browsers, and single-application workspaces) based on upstream core images, including adding software, startup scripts, branding, and launch forms to meet internal team requirements.
- Build and maintain custom VM images and auto-scaling agent pools (on KubeVirt, Harvester, or cloud hypervisors) to support containerized sessions, RDP-based sessions, and GPU-accelerated workloads.
- Operate and scale the underlying infrastructure, including Kubernetes clusters, Linux servers, and cloud resources (AWS, Azure, GCP), covering capacity planning, node management, storage, and patching of agent hosts.
- Own networking and ingress for the platform: TLS certificate management (including cert-manager integration), ingress controllers, load balancers, DNS, firewall rules, and secure routing between control plane, agents, and end users.
- Build CI/CD pipelines that automate image builds, vulnerability scanning, registry publishing, Helm chart deployments, and configuration rollouts across environments.
- Monitor platform health, investigate incidents, tune performance (session density, resource limits, autoscaling thresholds), and drive root-cause analysis on deployment, session, and connectivity issues.
- Partner with Security, IT, and engineering teams to integrate the platform with SAML and OIDC identity providers, session recording, logging, and SIEM pipelines, and compliance controls.
- Document runbooks, deployment standards, and image-build procedures, and mentor other engineers and support staff on operating the platform.
What You'll Bring
- 5+ years of experience in a DevOps, SRE, platform engineering, or application support role supporting production workloads.
- Strong hands-on experience with Kubernetes (deployments, services, ingress, Helm, RBAC, troubleshooting pods and networking) in real production environments. Experience with Rancher, RKE2, EKS, AKS, or GKE is a plus.
- Deep Docker expertise, including authoring multi-stage Dockerfiles, building and optimizing images, managing private registries, and debugging container runtime issues.
- Solid Linux systems administration skills (Ubuntu or Debian preferred), including scripting in Bash and at least one of Python or Go for automation and tooling.
- Working knowledge of at least one major cloud provider (AWS, Azure, or GCP), including compute, networking (VPC, subnets, security groups), storage, IAM, and managed Kubernetes offerings.
- Strong networking fundamentals, including TLS and PKI, DNS, HTTP and HTTPS proxies, reverse proxies, load balancers, and common troubleshooting tools (tcpdump, curl, dig, kubectl exec).
- Experience building CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins, or similar) for image builds and Kubernetes deployments.
- Comfort operating and patching Linux VMs and servers in a production setting, including creating reproducible VM images (Packer, cloud-init, or equivalent).
- Bonus: Experience with Infrastructure-as-Code (Terraform, Ansible), KubeVirt or Harvester, GPU-enabled container workloads, session streaming or VDI platforms, SAML or OIDC integration, or running regulated environments (FedRAMP, HIPAA, PCI).
The base salary range for this full-time position is $129,000-$193,500. Our salary ranges are determined by role, level, and location. The salary displayed reflects the range for new hire salaries for the position across all US locations. Within the range, individual pay is determined by state, work location and additional factors, including job-related skills, experience, and relevant education or training. This position may be eligible for incentive compensation, equity, and medical, dental, vision, life insurance and 401K. Your recruiter can share more about the specific details of the compensation and benefit package during the hiring process. #LI-Hybrid
Why should you join Recorded Future? Recorded Future employees (or "Futurists"), represent over 40 nationalities and embody our core values of having high standards, practicing inclusion, and acting ethically. Our dedication to empowering clients with intelligence to disrupt adversaries has earned us a 4.6-star user rating on G2 and more than 50% of Fortune 100 companies as customers. Want more info? Blog & Podcast: Learn everything you want to know (and maybe some things you'd rather not know) about the world of cyber threat intelligence Linkedin, Instagram&Twitter: What's happening at Recorded Future The Record: The Record is a cybersecurity news publication that explores the untold stories in this rapidly changing field Timeline: History of Recorded Future Recognition: Check out our awards and announcements We are committed to maintaining an environment that attracts and retains talent from a diverse range of experiences, backgrounds and lifestyles. By ensuring all feel included and respected for being unique and bringing their whole selves to work, Recorded Future is made a better place every day.
If you need any accommodation or special assistance to navigate our website or to complete your application, please send an e-mail with your request to our recruiting team at careers@recordedfuture.com
Recorded Future is an equal opportunity and affirmative action employer and we encourage candidates from all backgrounds to apply. Recorded Future does not discriminate based on race, religion, color, national origin, gender including pregnancy, sexual orientation, gender identity, age, marital status, veteran status, disability or any other characteristic protected by law.
Recorded Future will not discharge, discipline or in any other manner discriminate against any employee or applicant for employment because such employee or applicant has inquired about, discussed, or disclosed the compensation of the employee or applicant or another employee or applicant.
Recorded Future does not administer a lie detector test as a condition of employment or continued employment. This is in compliance with the law of the Commonwealth of Massachusetts, and in alignment with our hiring practices across all jurisdictions. Recorded Future maintains a drug-free workplace. Note: Our interview process for all final-round candidates requires a mandatoryin-person interviewor a live, scheduledvideo conference with the hiring manager. We do not conduct interviews via instant messaging or text. All communications during the application process will come from individuals within our HR department via their Recorded Future email address. Notice to Agency and Search Firm Representatives: Recorded Future will not accept unsolicited resumes from any source other than directly from a candidate. Any unsolicited resumes sent to Recorded Future, including those sent to our employees or through our website, will become the property of Recorded Future. Recorded Future will not be liable for any fees related to unsolicited resumes. Agencies must have a valid written agreement in place with Recorded Future's recruitment team and must receive written authorization before submitting resumes. Submissions made without such agreements and authorization will not be accepted and no fees will be paid.
|