Sphera

Sr. DevOps Engineer

Sphera Püttlingen, Saarland, Germany

IT Services and IT Consulting · 1,001-5,000 employees

12 h ago
Remote devops Senior (5-10 yrs) Full-time Germany
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

Design, build, and maintain shared Azure platform services while acting as an internal consultant for product and engineering teams. Manage infrastructure as code, CI/CD pipelines, and platform identity to ensure reliable and scalable SaaS operations.

What they look for

Azure Terraform Azure DevOps Infrastructure as Code PaaS CI/CD PowerShell Bash Azure CLI Git Application Gateway Azure Service Bus Entra ID Databricks MLOps API Management

Requirements

Requires deep hands-on experience with Azure PaaS, infrastructure-as-code using Terraform, and Azure DevOps CI/CD pipelines. Candidates must possess strong scripting skills and a proven track record of managing infrastructure for large-scale SaaS products.

Full description

Sphera is a leading global provider of enterprise software and services that enables companies to manage and optimize their environmental, health, safety and sustainability. Our mission is to create a safer, more sustainable and productive world.

Sphera is a portfolio company of Blackstone, a U.S.-based alternative asset investment company that focuses on private equity, technology and innovation, and more. Blackstone businesses succeed through strong partnerships, a personalized approach and a commitment to exceptional performance with uncompromising integrity. Sphera and Blackstone are leaders in the Environmental, Social and Governance (ESG) space.

We are guided by our core values of Customer Centricity, Accountability, Bias to Action, Innovation, and Collaboration. These values help us recruit the right talent to join our rapidly expanding team of around the globe. It is important to us that each and every Spherion is not only eager to challenge themselves and knows how to get work done but is an awesome addition to our company culture.

You'll be part of a global team supporting multiple SaaS environments that help make the world a safer place. This role sits on the Platform Engineering team, where you will build the shared Azure services that every product family and engineering team across the business depends on. That means two jobs at once: delivering new platform capabilities and features, and acting as the trusted expert other teams come to when they consume those services.

We are Azure-first and PaaS-first, with everything defined in Terraform. The environment moves quickly — from IaaS to PaaS to serverless — so you'll apply the skills you have while learning new ones constantly. We do not run Kubernetes; our compute is Azure App Service, Function Apps, and Container Apps. If you have deep, hands-on Azure PaaS and infrastructure-as-code experience and enjoy being the person who unblocks other engineers, you'll do well here.

Key Responsibilities

  • Design, build, and maintain the shared Azure platform services used across all product families — new projects and features as well as enhancements to existing services.
  • Own platform infrastructure as code in Terraform: author reusable modules, manage state, review plans, and drive changes safely through environments.
  • Act as the platform's internal consultant — onboard product and engineering teams onto platform services, review their designs, troubleshoot integration issues, and document self-service patterns.
  • Build and maintain CI/CD pipelines in Azure DevOps for infrastructure, application deployments, and Databricks assets.
  • Manage the edge: Application Gateway and WAF configuration (rewrite rules, path-based routing, listeners, backend pools, custom rules, TLS) and Traffic Manager profiles for multi-region routing and failover.
  • Manage identity and access for the platform — Entra ID app registrations, OAuth 2.0 / OIDC flows, service principals and managed identities, and RBAC role design and assignment.
  • Configure and maintain Azure AD B2C, including custom SSO XML policies (Identity Experience Framework), and support product teams integrating with them.
  • Operate API Management — API and product configuration, policy authoring, versioning, and deployment of APIM changes through Terraform and pipelines.
  • Operate Azure Service Bus — namespaces, queues, topics, subscriptions, filters, and shared access policies and permissions — all deployed and updated as code.
  • Support the MLOps team's deployment needs across Azure AI Foundry, Databricks, and model-serving workloads (detailed below).
  • Automate security, compliance, cost, and resource-usage controls; monitor and continuously improve every deployment path.
  • Own operational excellence: establish and maintain business-focused KPIs and reliability targets, and use them both to drive improvement and to make the team's impact visible.
  • Participate fully in the agile process — own your sprint tasks, log time worked, and keep details current.

MLOps and AI Platform Support

A distinct part of this role is enabling our MLOps team. You will be their platform-side partner for:

  • Deploying and configuring Azure AI Foundry projects, model deployments, and endpoints via Terraform and pipelines.
  • Databricks workspace deployment and configuration, including Unity Catalog, clusters, access control, and secret scopes.
  • Databricks job and workflow deployment pipelines, and promotion of notebooks, jobs, and DLT pipelines across environments.
  • Implementing and enforcing AI guardrails and content-safety controls, plus the networking, private endpoints, and identity plumbing that keep model traffic and data private.
  • Building repeatable, auditable deployment pipelines for models and AI services so the MLOps team can ship without manual steps.

Required Skills and Experience

Azure Platform

  • Compute (PaaS and serverless): Deep hands-on experience with Azure Web Apps / App Service, Azure Function Apps, and Azure Container Apps — deployment slots, scaling rules, VNet integration, and configuration management.
  • Networking and edge: Application Gateway and WAF — rewrite rules, path-based routing, listeners, backend pools, health probes, custom WAF rules and exclusions, and TLS/certificate management. Traffic Manager profiles and routing methods.
  • Cloud networking: VNets, subnets, NSGs, route tables, hub-and-spoke architecture, Private Endpoints, and Private DNS.
  • Messaging and integration: Azure Service Bus — namespaces, queues, topics, subscriptions, subscription filters and rules, and shared access policies and permissions.
  • API Management: APIM configuration and policy authoring (inbound, outbound, backend, and on-error), products and subscriptions, named values, versioning and revisions, and managing APIM changes through code and pipelines rather than the portal.
  • Identity and access: Entra ID — app registrations, API permissions and consent, service principals and managed identities, OAuth 2.0 and OIDC flows, token and claims configuration, and Azure RBAC design and assignment.
  • B2C and SSO: Azure AD B2C user flows and custom policies, including hands-on work with SSO XML policy files (Identity Experience Framework), and SAML/OIDC federation with external identity providers.
  • Supporting services: Storage Accounts, Key Vault, Azure Cache for Redis, and Azure Monitor / Log Analytics / Application Insights.

Infrastructure as Code and Automation

  • Terraform — full working command, not just familiarity: authoring reusable modules, managing remote state and workspaces, provider and version pinning, plan/apply review discipline, import and drift remediation, and using Terraform as the single path for all resource changes — including APIM configuration and policy and Service Bus topology and access policies.
  • Strong CI/CD experience with Azure DevOps — YAML pipelines (and comfort with classic pipelines), multi-stage deployments, environments, approvals, service connections, and variable/secret management.
  • Strong scripting skills in PowerShell and/or Bash; fluent with Azure CLI.
  • Solid Git and source-control practice — branching strategy, pull requests, and code review.

Engineering and Professional

  • Proven success managing and optimizing infrastructure and CI/CD for an Azure-based SaaS product at scale.
  • Strong understanding of security principles — least privilege, secrets management, network isolation, certificate lifecycle, and compliance-driven controls.
  • Working knowledge of databases, both SQL and NoSQL.
  • Excellent communication and collaboration skills, with the ability to work across multiple disciplines and explain platform decisions to engineers who are not infrastructure specialists.
  • Strong analytical skills and a track record of driving measurable reliability improvements.
  • Experience working in an agile SDLC in a fast-paced environment with high demand and high standards.
  • Ability to assimilate information quickly under pressure, and strong planning skills to ensure projects are delivered on time.
  • Bachelor's degree in Computer Science or a similar field, or equivalent practical experience.

Preferred Experience

  • Hands-on Azure AI Foundry, Azure OpenAI, or comparable managed AI platform deployment experience.
  • Databricks administration and deployment automation — Unity Catalog, Databricks Asset Bundles, or the Databricks Terraform provider.
  • Experience supporting MLOps or data engineering teams, including model deployment, guardrails, and content safety.
  • Azure Data Factory or comparable data orchestration tooling.
  • Authoring or heavily customizing B2C custom policy XML from scratch.
  • Containers and Docker for microservice or service-oriented architectures. Note: we do not use Kubernetes, and Kubernetes experience is not required for this role.
  • Monitoring and security tooling such as New Relic, Rapid7, Azure Monitor workbooks, or similar.
  • Relevant Azure certifications (AZ-104, AZ-400, AZ-500, or similar).
  • Familiarity with C#, Java, Python, or JavaScript/React — enough to read application code and debug deployment and configuration issues alongside product teams.

Sphera is proud to be an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all colleagues.

This job description is intended to convey information essential to understanding the scope of the job and the general nature and level of work performed by job holders within this job. This job description is not intended to be an exhaustive list of qualifications, skills, efforts, duties, responsibilities or working conditions associated with the position.

Similar roles