Infrastructure Engineer

Gyde

$110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-10 years of infrastructure, platform, SRE, or DevOps experience with production ownership
  • Production experience with Kubernetes (EKS preferred) including upgrades and troubleshooting
  • Strong understanding of AWS fundamentals including IAM and VPC
  • Experience with infrastructure as code (Pulumi preferred, Terraform or CDK acceptable)
  • Fluent in production TypeScript or Node and comfortable shipping application code in a shared codebase
  • Experience with relational data modeling and SQL, preferably Postgres
  • Experience operating in a regulated environment (e.g., HIPAA, SOC 2)

Responsibilities

  • Own the complete process from identifying problems to implementing running controls
  • Build and maintain production TypeScript in shared packages and workflows
  • Manage the cloud platform using EKS, AWS, and related tools
  • Integrate and evaluate vendor systems, ensuring compliance with their permissions
  • Implement security and compliance measures that are automatic and enforceable
  • Monitor and manage the costs of infrastructure and LLM resources effectively

Benefits

  • Flexible (Unlimited) Paid Time Off
  • Hybrid Work options in Austin or NYC
  • Medical, Dental, and Vision coverage for employees and families
  • Retirement Plan (e.g., 401K)
  • Parental Leave
Full Job Description
Role Summary

You own the infrastructure that Gyde's AI-native brokerage platform runs on - but at our size, the title undersells the job. We acquire insurance agencies and fold them onto one platform, which means our environment grows in scale and in tenancy every quarter, and it has to stay secure, auditable, and predictable while it does. You sit on the Infrastructure team and report to our Head of Infrastructure.

The work deliberately blurs the usual line between infrastructure and application engineering. The cloud layer - EKS, AWS in Pulumi, CI/CD, the observability stack - is table stakes, but it is rarely the whole deliverable. A typical project runs the full chain: a business problem lands ("we can't tell which agency this contract belongs to", "we can't tell whether that email arrived", "we don't know what we're spending on LLMs"), and you own it from audit and data model through to the TypeScript that ships in a shared package, the Temporal workflow that runs it, the IAM role behind it, and the dashboard that proves it works.

So this is real application engineering as well as platform work - TypeScript in our monorepo, Temporal workers, Postgres and SQL migrations, packages other engineers depend on. A third part of the job is neither infrastructure nor application code: evaluating a vendor's permission model closely enough to know what it can actually enforce, designing an approval workflow with named humans and SLAs, and treating HIPAA and cost as design inputs rather than review gates. Because we're small, you are often the interface to security, data, finance, and legal at once. You will write the decision doc, then defend it in a comment thread with someone who cares about the price rather than the architecture.

The throughline is simplification. Anyone can add another tool. We want someone who takes a complex, regulated, multi-tenant environment and makes it feel simple to the people using it - and who knows that the mechanism is usually the short part, while the carve-outs, the sequencing, and the question of whether a control is truly enforced are the job.
Key Responsibilities
  • Own the chain from problem to running control - take an ambiguous business or platform problem, establish what is actually true today rather than what the docs claim, design the fix, build it, and instrument it so you can prove it works. Most projects here cross the infra/app line and you own both sides.
  • Build in the monorepo - production TypeScript in shared packages other engineers import, Temporal workers and scheduled workflows, data models and SQL migrations, internal services and tooling. Not just YAML wrapped around someone else's code.
  • Run the cloud platform - EKS, AWS defined in Pulumi, CI/CD, secrets and workload identity, and the metrics, logging, and alerting that tell us something is wrong before a broker does.
  • Evaluate and integrate the systems we buy - identity, orchestration, model gateways, warehouse and vendor APIs. Read a permission model and plan tier closely enough to know what a tool enforces versus what a person is merely promising to do, then build the glue that makes them agree.
  • Make security and compliance enforceable - least-privilege IAM and workload identity, BAA before PHI access, data classification, PHI-aware logs and metric labels, and audit trails that hold up in a carrier audit because the system produces them, not because someone remembered.
  • Own cost as an engineering surface - per-key LLM and infrastructure spend, estimated-versus-billed reconciliation, and alerting that fires before a runaway job becomes an invoice.
What you bring and who you are
  • Cloud & Kubernetes Foundations - Production EKS and AWS expressed in code, CI/CD you would stake a release on, and observability people actually act on. You have operated clusters through upgrades and incidents, not just deployed to them. Here this is table stakes rather than the whole job.
  • Application Engineering in a Shared Codebase - You write real TypeScript, not only glue. Durable workflows, relational data modeling, migrations, and packages other engineers import. You are comfortable opening a pull request in application code you do not own, and you know when a shared abstraction earns its keep.
  • Integration & Vendor Systems - You reverse-engineer an admin console rather than trusting its marketing page. You check plan tiers and API surfaces before committing to a design, and you can tell the difference between a control a system enforces and a process a human promises to follow.
  • Security, Compliance & Cost as Design Inputs - Least privilege is a default, not a cleanup task. You know where PHI leaks in a stack - logs, traces, metric labels, backups, third-party payloads - and you treat spend as something you instrument, not something finance discovers on an invoice.
  • Judgment, Sequencing & Written Decisions - You verify the premise before you build. You think in blast radius, carve-outs, and reversible-first rollout, because the first casualty of enforcing something early is usually a business process. You write the one-page decision doc with ranked options and open questions, and you can defend it to a non-engineer.
Technical Requirements
  • 5-10 years in infrastructure, platform, SRE, or DevOps engineering, with meaningful production ownership.
  • Production Kubernetes experience - EKS preferred: cluster upgrades, autoscaling, networking, and hands-on troubleshooting.
  • Strong AWS fundamentals: IAM, VPC and networking, compute, storage, KMS, and a working grasp of the cost model.
  • Infrastructure as code in a real codebase - Pulumi preferred; Terraform or CDK acceptable with a willingness to work in Pulumi.
  • Production TypeScript or Node - you will ship application code in a shared monorepo, not only infrastructure definitions. We care that you have shipped real application code and will work primarily in TypeScript; which language you did it in matters less.
  • Relational data modeling and SQL, Postgres preferred; comfortable writing and reviewing migrations.
  • Built and owned CI/CD pipelines (GitHub Actions or comparable), including deployment strategy and rollback.
  • Observability in practice - metrics, logs, and distributed tracing, plus alerting that engineers trust.
  • Experience operating in a HIPAA, SOC 2, or otherwise regulated and audited environment.
  • A writing habit - design docs, RFCs, or postmortems you can point to.
  • Fluency with AI coding tools in day-to-day work - we are an AI-native company and expect engineers to use agents well.
Nice to have
  • Durable workflow engines - Temporal especially - or comparable orchestration and job systems.
  • Hands-on administration of an IdP or SaaS admin surface (Okta, Entra) including SCIM, RBAC, and API integration.
  • Multi-tenant SaaS, or M&A integration work folding acquired companies onto a single platform.
  • Data warehouse pipelines (Redshift, BigQuery, Snowflake) and event-ingestion plumbing.
  • LLM infrastructure: gateways and virtual keys, provider rate limits, token and spend telemetry.
  • Secrets management at scale, policy-as-code, and supply chain hygiene (image signing, SBOMs).
What we offer

Gyde offers a competitive benefits package to all employees.
  • Flexible (Unlimited) Paid Time Off
  • Hybrid Work in Austin or NYC
  • Medical, Dental, and Vision benefits for you and your family
  • Retirement Plan (e.g., 401K)
  • Parental Leave

Similar Jobs

More Jobs at Gyde

  • Partner Growth Director
    $125K — $150K *
    Austin, TX 78745 (Travis County)
    Healthcare
    In-Person
  • FP&A Manager
    $110K — $130K *
    Austin, TX 78745 (Travis County)
    Finance & Insurance
    In-Person

More Information Technology Jobs

Find similar Infrastructure Engineer jobs: