Staff Engineer, DevOps Engineering at Bain & Company | hitIT
Staff Engineer, DevOps Engineering
September 15, 2026
Office
Lead
Warsaw, Poland
Important before applying
This job has conditions that may affect your decision to apply
Office-only workEnglish is requiredGitHub profile required
Description
Bain & Company is hiring a Staff Engineer for the DevOps and Assurance team within Coro, the firm's internal product development and engineering organization (NGSS). The role owns the design, architecture, and long-term direction of cloud infrastructure and software delivery across Azure, Terraform, AKS, CI/CD, monitoring, and security. This is a foundational role in the early stages of a platform build, requiring strong technical fundamentals and the ability to set standards and roadmaps where none exist yet. The position is based in Warsaw, Poland.
Responsibilities
Own the design and evolution of cloud infrastructure built on Terraform and Terraform Cloud, defining module structure, state strategy, and remote backend conventions
Architect Azure networking end to end: VNet/subnet topology, private endpoints, DNS resolution, NSG design, and Front Door Premium configuration across dev, demo, and production
Set the standard for provisioning Azure platform services (App Services, Azure SQL, Azure OpenAI, Container Registry, Key Vault, Entra ID, Storage Accounts) and ensure environment parity by design
Own the automation roadmap for the team, identifying manual repetitive operational work and driving it toward self-service and infrastructure-as-code
Partner with Bain's central cloud and infrastructure teams to shape shared processes, tooling, and standards for operational work
Own Azure Kubernetes Service (AKS) architecture, including node pools, scaling strategy, spot instance usage, and workload connectivity to dependent services
Define identity and access architecture: Entra ID app registrations, managed identities, RBAC model, and integration with external IdPs (Okta)
Set infrastructure standards for database platforms (Azure SQL Serverless, PostgreSQL Flexible Server, Cosmos DB), including connectivity, Entra auth, firewall rules, and private endpoints
Ensure platform reliability and robust access controls across all environments, acting as senior escalation point for platform-level issues
Define and own the CI/CD strategy using GitHub Actions for container builds, infrastructure deployments, and application releases
Establish the container image lifecycle standard: build, scan, push to a container registry, and deploy to AKS or App Services
Design environment promotion workflows with appropriate gating, secrets management (Key Vault), and rollback strategies
Architect and operate GitHub-hosted private runners where required, including network integration with Azure VNets
Own the observability strategy using Datadog and Azure Application Insights, defining what the team monitors, alerts on, and how it optimizes cost and reliability
Lead the response to security findings: triage, containment, IAM scoping, container image CVE remediation, and endpoint hardening
Lead L2/L3 incident escalations, including root-cause analysis, user journey tracing, and log analysis, driving improvements to prevent recurrence
Define and enforce solution compliance across products: network isolation, least-privilege access, secrets hygiene, and deployment guardrails
Own the developer experience: set the standard for local development environments and deployment documentation for the distributed team
Lead and mentor DevOps engineers: set technical direction, review designs, grow the team's depth, and raise the bar on engineering practice
Anticipate stakeholder needs across NGSS and shape the platform roadmap proactively
Partner with architects, product engineers, and security teams to align on infrastructure standards across NGSS
Drive DevOps culture and automation-first thinking across the engineering organization and lead knowledge sharing
Contribute to and lead technical discovery, POCs, and innovation workstreams to validate new tools and architectural patterns
Requirements
Bachelor's or Master's degree in Computer Science, Engineering, or a related technical field
7–9 years of experience in DevOps, infrastructure engineering, or cloud platform engineering at senior or staff level
Proven track record of architecting and operating cloud infrastructure in production at scale
Demonstrated experience leading and mentoring DevOps or platform engineers in fast-paced product organizations
Deep hands-on expertise with Terraform and Terraform Cloud: module design, state strategy, and remote backends at scale
Strong mastery of Azure services including AKS, Networking (VNets, subnets, private endpoints, NSGs, DNS zones), App Services, Key Vault, Container Registry, and Storage Accounts
Deep experience with containerization technologies (Docker, Kubernetes) and container image lifecycle management
Expertise in roles, permissions, and IAM, particularly Microsoft Entra ID and Okta
Advanced CI/CD automation using GitHub Actions, Azure DevOps, and related DevOps toolchains
Proficient in Linux administration and automation scripting (Bash, PowerShell, Python) for reusable workflows
Strong command of monitoring and observability platforms (Datadog, Azure Application Insights)
Deep familiarity with Azure private networking: private endpoints, Private DNS Zones, and VNet integration for App Services and AKS
Command of database deployment and management from an infrastructure perspective: Azure SQL Serverless, PostgreSQL Flexible Server, and Cosmos DB
Strong foundation in security remediation: container CVE patching, IAM scoping, NSG/firewall tightening, and WAF/Front Door rule management
Excellent communication and collaboration skills with ability to translate complex technical topics for diverse stakeholders
Proactive, analytical, and systematic problem-solving skills across multiple layers (DNS, networking, identity, application)
Results-driven with strong bias for automation and continuous improvement
Comfortable owning ambiguity and working with limited direction, able to define standards where none exist
Familiarity with Agile methodologies
Preferred: Professional certifications such as Azure DevOps Engineer Expert, Azure Administrator, Terraform Associate, or CKA
Preferred: Experience owning multi-environment governance, cost optimization (FinOps), and compliance frameworks in cloud
Preferred: Familiarity with Azure OpenAI, Cognitive Search, Databricks, and integration of AI services into enterprise platforms
Preferred: Experience with workflow orchestration tools (Airflow or similar DAG/pipeline systems)
Preferred: Snowflake administration or connectivity from a DevOps lens
Preferred: Experience with AI/ML observability tools such as LangSmith or Arize
Preferred: Familiarity with AI coding assistants such as Cursor, Claude Code, or Codex
Conditions
Role within Bain's Coro product development and engineering organization (Next Generation Software Solutions department)
Supportive and inclusive work environment recognized as one of the world's best places to work
Opportunity to work alongside architects, backend engineers, product engineers, and security teams in a collaborative setting