The Senior DevOps Engineer - IAM will be responsible for the full lifecycle of CI/CD pipelines and Infrastructure as Code (IaC), with a focus on developing and operating Keycloak/RHSSO-based Identity and Access Management (IAM) capabilities on Kubernetes. This role enables secure Single Sign-On (SSO) and machine-to-machine access for internal products within one of Deutsche Telekom Group’s most important projects, directly impacting 30 million customers.
What You'll Do
- Designs, develops, tests and implements infrastructure for CI/CD pipelines and IaC
- Manages source code, configuration management, release management, build and deployment activities
- Setups and manages integration with partner applications
- Conducts performance analyses and tunings as well as error analyses and troubleshooting
- Consults and implements new innovative technologies to satisfy innovation strategy
- Creates concepts for further automation of services, processes and/or operating models
- Directly supports project teams in development, quality assurance accompanying development, and planning and implementation of product releases
- Continuously optimizes the development and system infrastructure
- Provides consulting to project teams on areas of expertise
- Prototypes/Proof of Concept solutions
- Researches and develops in assigned technology, determines business requirements, proposes changes and prepares implementation plans
What We're Looking For
- At least 3 years of work experience as DevOps / Platform Engineer (or SRE) with hands-on Kubernetes operations in production environments
- Solid understanding of OAuth 2.0 and OpenID Connect concepts for modern IAM integrations and SSO flows
- Practical experience with GitOps delivery using Argo CD (Git-driven continuous delivery for Kubernetes)
- Experience working with containers (Docker) and CI/CD pipelines (e.g. GitLab) from commit to production
- Comfortable scripting in Python and Bash for automation and troubleshooting tasks
- IAM fundamentals: authentication vs authorization, identity lifecycle and provisioning flows, role/permission model design, user types, and machine-to-machine concepts
- Keycloak/RHSSO: hands-on experience with realms, clients, roles, scopes, identity providers, and themes, including troubleshooting authentication and authorization flows end-to-end
- Configuration-as-code mindset for Keycloak: managing realms/clients/roles via versioned configuration and promoting changes across environments
- Operability: diagnose and resolve platform issues (CPU/memory pressure, pod health, configuration errors), contribute to incident response, and support upgrades and migrations
- Kubernetes & networking: experience with deployments, services, ingress, environment-specific configuration, and secure handling of secrets/config maps
- Packaging & delivery: Helm charts and Argo CD application management, including using Helm-based deployments through Argo CD for GitOps workflows
- Experience in CI/CD using GitLab, including building, testing, and deploying containerized workloads
- Infrastructure as Code (IaC) approach for managing environments and application infrastructure
- Observability: experience with Grafana/Prometheus, ELK stack, and basic Dynatrace usage for monitoring, alerting, and troubleshooting
- Experience with PostgreSQL in operational contexts (backups and restore, basic performance indicators, connection troubleshooting)
- General understanding of how Keycloak and IAM components rely on Postgres and what typical failure modes look like
- Experience with OAuth 2.0, OpenID Connect, and JWT-based authentication for Keycloak integrations
- Understanding of TLS/certificates and secure exposure of IAM endpoints
- Experience using monitoring and load-testing tools (e.g. Prometheus/Grafana, JMeter) to observe performance, capacity, and stability of IAM services
Technical Stack
- Kubernetes
- Keycloak
- RHSSO
- OAuth 2.0
- OpenID Connect
- Argo CD
- GitOps
- Docker
- GitLab
- Python
- Bash
- Helm
- PostgreSQL
- Grafana
- Prometheus
- ELK stack
- Dynatrace
- JMeter
- TLS
- Certificates
- Infrastructure as Code (IaC)
- CI/CD pipelines
- Configuration management
- Secrets management
- ConfigMaps
- Ingress
- Services
- Deployments
Team & Environment
- International Team
- Part of a team building greenfield software for a major Deutsche Telekom Group project
Work Mode
- Local position in Slovakia
We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, or disability status.







