Edge Compute Engineer
Position Overview
We are seeking a Edge Compute Engineer to join the Latvia Design Center as the primary owner of our ground-segment compute and storage stack running the edge workloads running across all AST ground gateway stations. The Edge Compute Engineer owns the design, provisioning, and lifecycle of this platform across the full gateway fleet globally.
This is a design-and-operate role for a senior engineer who can define the edge compute reference architecture, build an IaC-driven fleet management stack, and take hands-on operational ownership. As the fleet scales, this role will also shape the edge compute platform for future edge functions beyond the current scope.
Key Responsibilities:
Define and own the edge compute reference architecture: virtualization platform (VMware-based virtualization or Kubernetes), VM/container topology, storage layout, virtual networking, and resource governance across the gateway fleet
Design the platform to support confirmed edge workloads with headroom and architectural provision for deployment of future edge workloads
Maintain architecture documentation, platform design records, and operational runbooks
Build and maintain Terraform-based provisioning pipelines and PXE/TFTP-based boot and instance management for consistent, repeatable gateway node deployment
Implement Ansible-based configuration management and GitOps workflows to enforce auditable configuration state across all hypervisor nodes remotely
Manage virtualization cluster operations (VMware-based virtualization or Kubernetes): VM/pod lifecycle, HA, storage pools, virtual networking, and patching automation
Maintain platform-level observability integrated into the central Prometheus/Grafana/VictoriaMetrics stack and support capacity planning as the fleet expands
Enforce OS hardening baselines, PKI/certificate lifecycle (IAM Roles Anywhere, mTLS), encrypted storage, and firewall rules aligned with AST’s security governance
Coordinate with on-site teams or vendors for server firmware, BIOS, and RAID configuration as needed; maintain accurate hardware and software inventory across the fleet
Qualifications
Education:
Bachelor’s or Master’s degree in Computer Science, Telecommunications Engineering, or a related field — or equivalent professional experience.
Experience:
A minimum of 5 to 8 years of hands-on experience in infrastructure or platform engineering, with a strong focus on hypervisor administration, Linux systems, and infrastructure-as-code. Demonstrated experience designing and operating distributed or edge compute environments.
Deep hands-on VMware-based virtualization or Kubernetes (K8s) — cluster management, HA/DRS, virtual networking, storage pools
Advanced administration (RHEL, Ubuntu, Debian) — systemd, network stack tuning, performance profiling, security hardening
Terraform for infrastructure provisioning; PXE/TFTP-based boot and instance management; fleet-scale state management
Ansible and GitOps workflows for drift-free, pipeline-driven configuration enforcement
Cisco/Juniper networking (switching/routing), VLANs, VPN (IPsec/WireGuard), PrivateLink/private connectivity, last-mile network management, firewall management
AWS hybrid cloud - Direct Connect, Site-to-Site VPN, PrivateLink integration with on-premises infrastructure
Certificate lifecycle management, mTLS, IAM Roles Anywhere, access control for production edge infrastructure
Prometheus, Grafana, VictoriaMetrics — hypervisor and VM health dashboards and alerting
Docker and Kubernetes sufficient to support containerized workloads on the edge platform
English proficiency at B2 level or above; able to collaborate effectively with peers in a globally distributed team
Soft Skills:
Platform ownership mindset - treats the edge compute fleet as a product to be designed, documented, and evolved, not just kept alive
Proactive risk awareness - spots capacity constraints, configuration drift, and security gaps before they become incidents
Disciplined remote operator - rigorous about change management, rollback planning, and validation procedures when working on live infrastructure without physical access
Clear technical communicator - documents architecture and runbooks precisely enough that a new team member can operate the fleet independently
Collaborative across disciplines - works naturally with OSS architects, DevOps engineers, security, and network teams without needing a detailed brief for each interaction
Composed under pressure - methodical and structured during incident response, even when coordinating across time zones with remote site teams
Technology Stack:
VMware-based virtualization or Kubernetes (K8s)
Terraform, PXE/TFTP, Packer
Ansible, GitOps (GitHub Actions, GitLab CI, Azure DevOps)
RHEL, Ubuntu, Debian
Docker, Kubernetes
Cisco / Juniper (or equivalent), VLANs, IPsec / WireGuard VPN, PrivateLink, last-mile network management, firewall management (pfSense / OPNsense or equivalent)
mTLS, cert-manager or equivalent
Prometheus, Grafana, VictoriaMetrics, ELK stack
AWS EC2, PrivateLink, Site-to-Site VPN / Direct Connect, IAM Roles Anywhere
Git, Jira, Confluence, draw.io
Physical Requirements
Ability to work in a standard office or remote home-office environment and use a computer for extended periods
Ability to participate in occasional after-hours incident response actions
This job description may not be inclusive to the duties and responsibilities listed. Additional tasks may be assigned to the employee from time to time or the scope of the job may change as needed by business demands.