Senior Software Engineer, Platform

Starcom Mediavest Group Germany Gmbh

$112K — $172K *
Enterprise Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 6+ years in software/infrastructure engineering
  • Bachelor's degree or equivalent experience
  • Deep hands-on experience with Kubernetes and AWS at scale
  • Operational depth in observability, AWS networking, Vault, or CI infrastructure
  • Strong AWS networking design and judgment
  • Proven ability to critically review infrastructure changes
  • Skills in mentoring engineers and managing technical uncertainty

Responsibilities

  • Own reliability and operability of critical systems
  • Establish and enforce platform standards and best practices
  • Manage infrastructure as code using Terraform across AWS accounts
  • Review Terraform, Kubernetes configurations, and CI/CD pipelines for quality
  • Transform recurring requests into self-service workflows
  • Lead resolution of platform incidents with a focus on learning
  • Evaluate new patterns against operational trade-offs

Benefits

  • Medical, dental, and vision coverage
  • Disability insurance
  • 401(k) plan
  • Paid time off
  • Opportunity for hybrid work model
Full Job Description
Job Description

You must be work authorized in the United States without the need for employer sponsorship.

This is a hybrid role requiring 3 days a week in a CJ office location (www.cj.com)

Must have AdTech / MarTech industry experience, specifically in e-commerce, travel, and finance.

As a Senior Software Engineer on the Engineering Experience (EngExp) platform team, you help run and evolve the platform that powers CJ's production systems across multiple AWS regions. "Platform" here is broad - it is the Kubernetes clusters, but also the observability stack every squad depends on, the CI/CD and artifact infrastructure their builds run through, the AWS networking that connects them, the secrets and access systems that gate them, and the cost visibility that keeps them accountable. EngExp owns all of it, and this role touches most of it. This is not just an infrastructure role - your value is in engineering judgment. You are a leader on the team: you own the reliability and operability of the platform, act as a critical reviewer of systems and changes, set standards, and mentor other engineers. We especially want someone with real depth in the systems below - we have made platform decisions we later had to reverse because the team lacked deep expertise in a component we owned, and that depth is exactly what this role brings.

Responsibilities

The Systems You Work On:

EngExp owns the systems below. You'll own their reliability, be the critical reviewer of changes to them, and raise the team's depth in them:
  • Observability & monitoring - Prometheus, Alertmanager, Grafana, and OpenTelemetry across every production region. This is not dashboard-building: you own cardinality budgets and recording-rule design, keep a production Prometheus healthy as it outgrows a single shard (federation / sharding / long-term store strategy), and own Alertmanager HA and the blast radius of alert-routing config. Deep Prometheus and Alertmanager expertise is a core requirement.
  • Kubernetes & cloud infrastructure - multi-region EKS clusters: upgrades, node group and Karpenter management, controller lifecycle, and add-on / configuration management. Identify failure modes before they happen (subnet IP exhaustion, API server latency, ArgoCD reconciliation lag, Prometheus cardinality, Karpenter consolidation disruption).
  • AWS networking - VPC design, subnet allocation and CIDR management, VPC peering, Transit Gateway, security groups, Route53, and NAT gateway topology across multiple accounts and regions, plus 24/7 networking alarms for all prod networking between clusters and squad resources.
  • CI/CD & artifact management - GitLab administration (runner fleet, AMI updates, cache, access - not just pipeline authoring), GitOps delivery through ArgoCD, and the Nexus artifact repository including its storage lifecycle as it grows.
  • Access & identity - Vault secrets management, IAM roles and service accounts for apps in clusters, cluster permission management for audit compliance, and AI model access management (including cost alerts and reporting).
  • Cost observability - OpenCost, EBS orphan cleanup, cost anomaly investigation, and rightsizing attribution across teams, so waste is attributable rather than shared overhead.
  • Internal tools & delivery - the container image build pipeline and base image standards, code audit tooling, HedgeDoc, and the UI CDN (S3 + CloudFront), plus adopted applications with no other owner.

What You'll Do:
  • Own the reliability and operability of the systems above - focused on what is happening and why
  • Establish and enforce platform standards: RBAC, admission webhooks, resource limits, LimitRanges, policy-as-code
  • Manage infrastructure-as-code with Terraform across AWS accounts
  • Act as a high-quality reviewer of infrastructure changes - Terraform, Kubernetes configs, CI/CD pipelines, observability config - catching subtle issues and long-term risks before they ship
  • Turn recurring requests (ingress, DNS, service accounts) into self-service workflows that are hard to misuse
  • Drive resolution of platform incidents with a focus on learning and lasting system improvement
  • Evaluate new patterns (Gateway API / Kgateway, claim-based self-service) on tradeoffs, not hype
  • Mentor less-senior engineers and raise the team's depth in the components we own

Technologies We Use:
  • Kubernetes / EKS (multi-cluster, multi-region), Karpenter, cert-manager, external-dns
  • Prometheus, Alertmanager, Grafana, OpenTelemetry (and long-term storage / sharding for Prometheus)
  • AWS networking (VPC, VPC peering, Transit Gateway, Route53, NAT Gateway, security groups, subnet/CIDR design across accounts and regions)
  • Terraform, AWS (IAM, EKS, S3, EBS)
  • ArgoCD, GitLab CI/CD, Nexus (artifact registry), Docker, container image build pipelines
  • Vault, OpenCost
  • Gateway API / Kgateway
  • Kubernetes controllers/operators (reconciliation patterns, restart safety) - Go experience is a plus, not required


Qualifications

What We Look For:
  • 6+ years of experience in software and/or infrastructure engineering
  • Bachelor's degree or equivalent experience
  • Deep, hands-on production experience operating Kubernetes and AWS at scale, across multiple accounts and regions
  • Real operational depth in at least one system we own beyond the cluster - most importantly the observability stack (Prometheus/Alertmanager at scale), but AWS networking, Vault, or artifact/CI infrastructure also count. We are filtering for people who have run these systems, not just used them.
  • Strong AWS networking judgment (VPC, peering, Transit Gateway, subnet/CIDR design)
  • A track record as a critical reviewer - spotting subtle infrastructure issues and long-term risks before they ship
  • Experience leading technical work and mentoring engineers; can manage, clarify, and plan around uncertainty
  • Effective communication and the ability to influence design in a product-focused way

Nice to Have:

Prometheus long-term storage / sharding (Thanos, Cortex, Mimir, or equivalent) run in production
  • Experience owning a container image / base image pipeline
  • Policy-as-code (Kyverno / OPA) and admission webhook design
  • Building claim-based self-service platform capabilities

What Success Looks Like:
  • Engineers can deploy and debug services without needing platform intervention
  • The systems we own are understood deeply enough that we stop making decisions we have to reverse
  • Production issues are understood quickly, not just reacted to
  • Platform changes are intentional and low-risk, and standards are clear and enforced


Additional Information

This is a hybrid role requiring 3 days a week in office.

Compensation Range: USD $112,290.00 - USD $172,032.00/Annually. This is the pay range the Company believes it will pay for this position at the time of this posting. Consistent with applicable law, compensation will be determined based on the skills, qualifications, and experience of the applicant along with the requirements of the position, and the Company reserves the right to modify this pay range at any time. Temporary roles may be eligible to participate in our freelancer/temporary employee medical plan through a third-party benefits administration system once certain criteria have been met. Temporary roles may also qualify for participation in our 401(k) plan after eligibility criteria have been met. For regular roles, the Company will offer medical coverage, dental, vision, disability, 401k, and paid time off. The Company anticipates the application deadline for this job posting will be 9/27/2026.

Similar Jobs

More Jobs at Starcom Mediavest Group Germany Gmbh

More Enterprise Technology Jobs

Find similar Senior Software Engineer, Platform jobs: