Senior DevOps / Linux Infrastructure & Security Engineer
Orçamento: $35.0
FIXED /
⭐ 4.93 (97)
India
linux-system-administration, devops, network-security, kubernetes, linux, docker, system-administration, network-administration
Qualificações preferidas
- Experiência: Especialista
Part-Time | Long-Term Monthly Retainer | NDA Required
About the Role
We're a small tech-driven startup (BikeFixUp) looking for a reliable, hands-on DevOps/Linux engineer to own, secure, monitor, and maintain our production infrastructure on an ongoing basis.
This is not a one-time setup job. We need a trusted technical partner who can investigate real production issues across the full stack, identify root causes, apply safe fixes, and keep clear documentation someone who takes responsibility, not just tasks.
Our Stack
OS: Ubuntu (VPS)
Reverse Proxy: Caddy
DNS/CDN/Security: Cloudflare
Databases: PostgreSQL (primary), MySQL/MariaDB, MongoDB (basic)
Cache/Queues: Redis
Backend: Laravel (existing), NestJS (active development)
Frontend: Next.js, React Native
Version Control: Git / GitHub
Containerization: Docker (used selectively, not default — approved case-by-case)
Scale: ~4 active projects, small team, production APIs and backend services
Responsibilities
Server Administration & Security
Harden Ubuntu servers firewalls, SSH, open ports, unnecessary services
Apply security patches and OS updates on a regular schedule
Monitor CPU, RAM, disk, network, and critical services
Manage credentials, keys, and secrets securely (no secrets in Git, ever)
Investigate suspicious activity, brute-force attempts, and unauthorized access
Minimize public-facing attack surface
Caddy & Cloudflare
Configure and maintain reverse proxy routing
Manage domains, DNS records, and SSL/TLS certificates
Maintain Cloudflare security rules and proxy settings
Protect origin servers from direct public exposure
Troubleshoot routing, DNS propagation, and certificate issues
Deployments & Production Operations
Deploy and maintain applications across environments (staging/production)
Manage GitHub-based release workflows
Handle rollbacks and service recovery when deployments fail
Manage workers, queues, and scheduled jobs
Verify deployments and document all production changes
Databases & Redis
PostgreSQL: backups, restores, permissions, query troubleshooting, performance
MySQL/MariaDB: general administration
MongoDB: basic troubleshooting
Redis: connectivity, memory, queue/worker failures
Application-Level Troubleshooting
You must go beyond the server. When something breaks, you should be able to trace the issue across:
Application config and environment variables
PHP or Node.js runtime errors
Database or Redis connectivity
File permissions
Queue/worker failures
Caddy routing or Cloudflare rules
DNS resolution
Server resource exhaustion
We need root cause analysis not "I restarted the service and it's working now."
Backups, Monitoring & Recovery
Maintain automated backups for databases, files, and configurations
Verify backup integrity and test restores periodically
Monitor uptime, SSL expiry, Redis, queues, and application health
Maintain documented rollback and disaster recovery procedures
Respond to critical production incidents promptly
Uptime & Incident Response
Our target is maximum possible uptime. This means:
Proactive monitoring don't wait for things to break
Strong DDoS/DoS and brute-force mitigation via Cloudflare and firewall rules
SSH hardening and access control
Immediate response to critical incidents (downtime, data exposure, security breach)
Prompt investigation of any malware or intrusion attempts
Regular security audits and vulnerability checks
Documentation Requirement
You must maintain a living infrastructure runbook that any new engineer could use to understand and recover our environment. It must cover:
Servers, services, ports, and dependencies
Caddy and Cloudflare configuration
Deployment and rollback procedures
Database and Redis setup
Backup and restore procedures
Security configuration
Common troubleshooting steps
Disaster recovery playbook
Security & Confidentiality
An NDA is required before any production access is granted. You must:
Use individual accounts wherever possible
Follow least-privilege access principles
Never share credentials or production data
Never commit secrets to any repository
Never create undocumented access paths
Never expose internal services without explicit approval
Report any security incidents immediately
All infrastructure, source code, credentials, and business information are confidential property of BikeFixUp.
Requirements
4+ years of hands-on DevOps/Linux experience (Ubuntu production environments)
Strong PostgreSQL experience (required)
Solid experience with Caddy or Nginx
Redis administration experience
Cloudflare setup and security configuration
Real-world production incident experience — you should be able to describe actual incidents you diagnosed and resolved
Comfortable with long-term, part-time retainer work
Available for critical production incidents with a fast response time
What You'll Get
Real ownership of production infrastructure across multiple live projects
Direct communication with the founding team no middlemen
Exposure to a growing multi-tech stack (Laravel, NestJS, Next.js, React Native)
A stable long-term engagement with room to grow
A relationship built on trust, not just tickets
How to Apply
Start your proposal with: "TRUSTED DEVOPS"
Then include:
Years of DevOps/Linux experience
Specific experience with Ubuntu, PostgreSQL, Redis, Caddy/Nginx, and Cloudflare
One real production incident you diagnosed and resolved (brief, specific)
Your backup and disaster recovery experience
Your availability and typical response time for critical incidents
Your expected monthly fee
Confirmation you're comfortable signing an NDA
Retainer Budget: $35/month (fixed) long-term engagement
We're a small startup with a limited budget but serious infrastructure needs. We're looking for someone who values trust, ownership, and a long-term working relationship over a high one-time payday.
Abrir na Upwork
AI proposal draft
Generate a short cover letter for this job. Edit before sending.
Sign in to generate an AI proposal draft.
Entrar