

Search by job, company or skills

About Aleph
Aleph builds an AI-native process intelligence platform for the process industries: chemicals, pharmaceuticals, oil and gas, desalination, and water treatment. Engineers use it to analyse plant data, digitise engineering drawings, build and run simulations, train models, and operate automated monitoring and optimization, all through natural language.
We deliver it as enterprise software deployed inside each customer's own Azure tenant, so their data stays in their environment while we operate the platform for them. We are an early-stage, fast-growing company working with industrial enterprises across Asia, the Middle East, and Europe.
The role
We are hiring a DevSecOps and Platform Engineer to own how our platform is built, secured, deployed, and operated across enterprise customer environments. Because it runs inside our customers own Azure tenants, deployment, security, and operations are core to the product. You will turn our architecture into a repeatable, secure, and observable deployment that we can stand up in a new customer's cloud with confidence, and keep running.
This is a senior individual-contributor role. You will be hands-on building and operating the platform, while setting the standards, and, as we grow, shaping and mentoring a small platform and reliability team. You will work directly with the CTO and the founding team, with high autonomy and high ownership.
What you will own
· Deployment automation: Design, build, and maintain the deployment of the platform into customer Azure tenants using infrastructure-as-code (Terraform) and GitOps (ArgoCD), reproducibly and securely.
· Cross-tenant access: Own the management model with Azure Lighthouse including scoped delegations, service principals, least-privilege roles, and the templates customers review and apply.
· Container platform: Run and harden AKS, including networking (VNets, private endpoints, NSGs, private DNS), ingress, secrets in Key Vault, identity via Entra ID, and the container supply chain (registry, scanning, signing).
· Release engineering: Build and operate CI/CD across multiple customer deployments e.g. image mirroring into customer registries, versioning, safe rollout, and rollback.
· Reliability and observability: Own metrics, logs, and traces; monitoring and alerting; incident response; and service-level objectives.
· Security program: Drive secure-by-default architecture, secrets and key management, vulnerability and patch management, and our roadmap to SOC 2 Type II and ISO 27001, with an eye on IEC 62443 for industrial environments.
· Enterprise security due diligence: Lead responses to security questionnaires, own the architecture and security documentation, and engage customer IT and security teams directly.
· Deployment models Support everything from multi-tenant to fully isolated single-tenant and restricted-network (no public internet) variants, with strong data-residency guarantees.
· Standards and automation: Codify runbooks, standards, and tooling so the platform stays deployable, secure, and operable as it evolves.
What we are looking for
· At least 3 years of working experience in building and operating production cloud infrastructure, with a strong blend of platform engineering and security. We weigh depth and ownership more heavily than exact years.
· Experience and expertise in dealing with large enterprise/B2B deployments is a strong plus.
· Deep experience with Azure is preferred; alternatively, strong experience with another major cloud (AWS or GCP) and the appetite to go deep on Azure. Either way, you know Kubernetes, cloud networking (virtual networks, private endpoints, network security groups, DNS), cloud identity, secrets management, and container registries.
· Infrastructure-as-code with Terraform, and GitOps with ArgoCD or Flux. Strong with containers and Kubernetes tooling such as Helm or Kustomize.
· CI/CD and release engineering, secrets management, and software-supply-chain security (image scanning and signing).
· A real security-engineering mindset: least privilege, network segmentation, encryption, and threat modelling, plus familiarity with SOC 2 and ISO 27001 controls and what it takes to reach certification.
· Comfort deploying into and operating within customers cloud environments, and engaging enterprise IT and security stakeholders directly.
· An ownership mindset that thrives in an early-stage startup: comfortable with ambiguity and autonomy, hands-on as an IC, and able to lead by setting the bar.
Nice to have
· Azure Lighthouse or other cross-tenant and multi-tenant management experience.
· Industrial, OT, or process-industry exposure; IEC 62443; or regulated environments such as GxP, GAMP 5, and 21 CFR Part 11.
· Experience taking a startup through SOC 2 Type II or ISO 27001 certification.
· Data integration from on-premise or OT systems: historians, OPC-UA, REST APIs, or streaming such as Event Hubs.
· PostgreSQL operations including time-series workloads; AI/ML infrastructure (Azure OpenAI, Azure Machine Learning); and workflow orchestration such as Prefect.
· Strong Python for tooling and automation.
What success looks like
· First 30 days Ramp fast: get productive on our architecture and the deployment pipeline, and take over day-to-day platform operations.
· By month 2 Ship a hardened, repeatable customer-tenant deployment and a solid observability baseline, and own releases end to end.
· By month 3 Kick off and drive SOC 2 and ISO 27001, and standardise deployments across customers.
· By month 6 Reliability, incident response, and security posture on a strong footing, with the groundwork laid for a small platform team.
Why join
· A foundational role with genuine ownership of how a frontier product reaches heavy industry.
· Direct work with the CTO and founders in a small, senior team.
· Meaningful equity and competitive compensation, discussed on application.
· Hard, high-impact problems at the intersection of AI, cloud security, and industrial operations.
Job ID: 151356737