Job Description
We are looking for a skilled DevOps Engineer with hands-on experience in managing API gateways using OpenResty and Lua, implementing OIDC-based authentication, and deploying containerized applications using Helm into Kubernetes clusters (EKS/AKS).
The ideal candidate should also have strong networking knowledge, cloud-native experience, and a solid grasp of modern DevOps practices.
Key responsibilities
- Design, implement, and manage Nginx configurations to support M2M and H2M pre-authentication.
- Integrate Nginx with identity and access management (IAM) systems, including, OpenID Connect, and SAML.
- Develop and enforce security policies ensuring robust pre-authentication for M2M and H2M communications.
- Build, containerize, and deploy authentication components using Docker and Helm.
- Manage deployments across AKS and EKS clusters in production and staging environments.
- Work closely with security, DevOps, and application teams to ensure seamless integration and high security standards.
- Optimize Nginx settings for performance, security, and scalability.
- Monitor, troubleshoot, and resolve Nginx-related issues, ensuring system reliability and performance.
- Stay current with the latest Nginx features, security updates, and industry best practices.
- Document configurations, procedures, and system changes to maintain accurate records and facilitate knowledge sharing.
Qualifications
Preferred Qualifications
- Networking & Protocols:
- Deep understanding of networking fundamentals (IP, DNS, routing, firewalls, WAF).
- Strong knowledge of HTTP/HTTPS, including headers, methods, caching, and status codes.
- Experience with SSL/TLS, certificate management, and secure communication best practices.
- Familiarity with reverse proxies, load balancing, and ingress traffic handling.
- Containerization:
- Experience with Docker for building, managing, and debugging containers.
- Ability to write and optimize Dockerfiles for performance and security.
- Understanding of container best practices (e.g., multi-stage builds, image hardening).
- Knowledge of container networking, volumes, and logging.
- Authentication & Authorization:
- Implementing and troubleshooting OIDC (OpenID Connect) integrations.
- Experience integrating with Azure EntraID or other identity providers.
- Working knowledge of JWTs, scopes, claims, and token validation.
- Implementing pre-authentication logic in front of internal applications.
- OpenResty & Lua
- Hands-on experience managing OpenResty (Nginx + LuaJIT) for custom reverse proxy setups.
- Writing and maintaining Lua scripts for request handling, authentication, routing, and logging.
- Familiarity with Nginx internals and Lua phases in the HTTP request lifecycle.
- Kubernetes (AKS/EKS) & Helm
- Writing, templating, and maintaining Helm charts for complex applications.
- Knowledge of K8s primitives: Deployments, Services, Ingress, ConfigMaps, Secrets, RBAC.
- Cert-Manager, ExternalDNS
- Understanding of rolling deployments, health checks, and zero-downtime upgrades
- CI/CD & Infrastructure Automation
- Familiarity with CI/CD pipelines for deploying Helm charts and Docker images.
- Exposure to Terraform, focused on Terraform Cloud
- Scripting in Bash, Python, or similar for automation and tooling.
Required Qualifications
- Bachelor’s degree in Computer Science, Information Technology, or a related field.
- 3+ years of experience with Nginx, including extensive configuration and performance tuning.
- In-depth understanding of pre-authentication techniques for both M2M and H2M communications.
- Strong knowledge in Linux kernel Systems.
- Strong knowledge in containerized platforms (Docker/Podman)
- Experience with IAM systems such as OAuth2, OpenID Connect, and SAML.
- Strong scripting skills in languages such as Python, Bash, or similar.
- Excellent analytical and problem-solving skills.
- Strong communication and collaboration abilities.
Additional Information
We support your development! Do you feel you don’t match 100% of the requirements?
Don’t hesitate to apply anyway! Eurofins companies are committed to supporting your career development.
We embrace diversity! As an Equal Opportunity Employer, the Eurofins network of companies believes in strength and innovation through diversity. We prohibit discrimination against employees or applications based on gender identity and/or expression, race, nationality, age, religion, sexual orientation, disability, and everything else that makes employees of Eurofins companies unique.
Sustainability matters to us! We are well on our way to achieving our objective of carbon neutrality by 2025, through a combination of emission reduction and compensation initiatives.
We encourage our laboratory leaders to make sustainable changes at their local level, and in addition to their initiatives we count on our dedicated carbon reduction team to help us to achieve this goal!