{"id":1226027,"url":"https://alion.io/job/iceye-sovereign-infrastructure-operations-engineer","title":"Sovereign Infrastructure Operations Engineer","company":{"id":17599,"name":"ICEYE","domain":"iceye.com","url":"https://alion.io/company/iceyefi","size_band":"501-1000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Ashby","truth_index":{"grade":"A","score":88,"open_postings":30,"ghost_share":0,"stale_share":0.5,"repost_share":0,"time_to_fill_p50_days":57,"computed_at":"2026-10-02T05:45:00Z"}},"role":"DevOps","role_family":"DevOps","seniority":"senior","employment_type":"full_time","work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Espoo, Finland"],"countries":["FI"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":54000,"max_usd":140000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":2013},"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Ansible","optional":false},{"name":"Debian","optional":false},{"name":"DHCP","optional":false},{"name":"DNS","optional":false},{"name":"Git","optional":false},{"name":"GitLab","optional":false},{"name":"GitOps","optional":false},{"name":"IAM","optional":false},{"name":"ISO 27001","optional":false},{"name":"Keycloak","optional":false},{"name":"Kubernetes","optional":false},{"name":"Linux","optional":false},{"name":"PKI","optional":false},{"name":"Puppet","optional":false},{"name":"Terraform","optional":false},{"name":"Ubuntu","optional":false},{"name":"VLAN","optional":false},{"name":"VPN","optional":false},{"name":"Agile","optional":true}],"status":"live","first_seen_at":"2026-09-25T10:46:42Z","employer_posted_date":"2026-09-25","last_verified_at":"2026-10-03T01:13:10Z","board_verified":true,"closed_at":null,"days_open":7,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":7},"description":"Role highlights:\nSovereign Infrastructure Operations Engineer\n\nLocation: Espoo\n\nDepartment: IT\n\nReports to: Head of IT\n\nEmployment type: Permanent\n\nWorkplace model: Hybrid\n\nEmployment is subject to applicable security screening (incl. SUPO, where required)\n\nWhy this role matters:\nAs a Sovereign Infrastructure Operations Engineer, you'll take operational ownership of ICEYE's secure bare-metal infrastructure, virtualization platforms, and production Kubernetes environments, keeping the dedicated air gaped collaboration platform reliable, secure, and audit-ready under some of the strictest information security frameworks in Europe.\nWho We Are\n\n ICEYE is the world leader in sovereign intelligence from space. We deliver persistent monitoring capabilities to detect and respond to changes in any location on Earth.\nICEYE owns the world's largest and most advanced SAR (synthetic aperture radar) satellite constellation. To our customers we provide intelligence with unmatched quality, latency and revisit times, in any weather, day or night. To governments who choose to operate their own constellation we provide this proven capability as a sovereign system.\nICEYE-built constellations serve customers in defence and intelligence, environmental monitoring, insurance and emergency management. We enable fast decisions that contribute to a safer future.\nFounded and headquartered in Finland, ICEYE operates globally with over 1000 employees across Europe, North America, the Middle East, and Asia-Pacific.\n Your day-to-day responsibilities\nManage configuration state across physical and virtual assets using GitOps with Infrastructure as Code tools (Git/Gitlab, Ansible, Terraform, or Puppet), removing manual configuration drift in secure environments in alignment with the strict change policies of the given security controls\n\nMaintain and support production Kubernetes clusters in restricted environments, covering upgrades, storage integration, and registry management\n\nAdminister secure platform core services (Mattermost, Nextcloud, Keycloak, OpenBao), including deployment, upgrades, and integration with local IAM and storage\n\nRun weekly meetings (change management, vulnerability management) with stakeholders on the infrastructure side\n\nMaintain technical security controls to satisfy Finnish Katakri, German VS-NfD, and related European frameworks (e.g. NIS2, ISO 27001), including patch management, hardening, and access control\n\nMaintain secure infrastructure networking (VLAN isolation, mTLS, PKI) and identity integrations, in coordination with network and security teams\n\nExecute backup and disaster recovery procedures and routine hardware maintenance across air-gapped or high-security sites\n\nWhat we’re looking for\nMust haves:\n5+ years hands-on experience in Systems Administration, IT Systems Engineering, or Infrastructure Operations, with a focus on Linux environments\n\nPractical experience running and maintaining production Kubernetes clusters\n\nExpert-level Linux administration (Debian/Ubuntu or RHEL/Rocky), including system hardening and vulnerability patching\n\nPractical knowledge of Katakri, VS-NfD, or equivalent European security/compliance frameworks (ISO 27001, NIS2)\n\nSolid understanding of enterprise networking fundamentals (VLAN segmentation, firewalls, DNS/DHCP, VPN protocols, PKI)\n\nEligibility to obtain and maintain a high-level national security clearance in Finland\n\nNice to haves:\nExperience with Ceph or ZFS storage systems\n\nExperience with at least one Infrastructure as Code tool (Ansible, Terraform, or Puppet), with the ability to manage configurations\n\nExperience with Keycloak, Vault, or internal PKI management\n\nFamiliarity with Kubernetes operations specifically in secure or air-gapped environments\n\nApplication Process\nTA Screen (30 mins)\n\nInterview with Hiring Manager (30 mins)\n\nTechnical Deep-Dive Interview with Team (60 mins)\n\nStakeholder & Security Alignment Interview (30 mins)\n\nWorking at ICEYE\nAt ICEYE, you’ll join a diverse and highly engaged team united by the ambition to make the impossible possible. As a global scale-up, we combine speed and ambition with the opportunity to take real ownership from day one. Your growth, wellbeing, and success are a priority, with continuous professional development, training opportunities, and a culture where collaboration is how we win.\nHow We Work (Our Values)\nMake the impossible possible: We set ambitious goals and stay calm under pressure. We bring grit, optimism, and ownership when things get hard, and we keep moving until we find a way.\nBe curious: Go deep, ask questions, listen carefully, and think critically. Understand the “why” behind decisions.\n\nSee the big picture: Stay close to what’s happening across the company so you can make better decisions. Consider how your work affects others.\n\nDrive effective teamwork: Create psychological safety, invite different perspectives, and build inclusive teams. There are no bad questions.\n\nAct as one team: We win together. We match tasks to the right owner and stay agile as priorities shift.\n\nHave fun: What we do matters-and it should be enjoyable. Celebrate progress, take pride in results, and share the wins.\n\nBenefits\nOur benefits are designed to support your health and wellbeing, at work and beyond. We keep improving them based on employee feedback, and offerings vary by location. Talent Acquisition will confirm what applies for this role and location during the process.\nOur Commitment to Diversity, Equity, and Inclusion\nWe want ICEYE to be a place where people can be themselves and do great work. Different backgrounds and perspectives make us stronger, which is why we work to create an environment where people feel included, respected, and able to speak up. Whatever your background, we want you to bring your authentic self to the table.\nWe’re committed to fair, inclusive hiring and equal opportunity. Everyone is welcome to apply. If you need any adjustments or support during the recruitment process, tell us-we’ll do our best to help.\nApply now to start your ICEYE journey, and help us continue to make the impossible possible together. Read more about ICEYE and working with us at iceye.com.","description_format":"text","description_chars":6190,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Equity","Professional development"],"hiring_locations":[{"name":"Finland","iso":"FI","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Space & Aerospace","Geospatial Analytics","Satellite Manufacturing","Earth Observation"],"lifecycle":[{"event":"open","at":"2026-09-25T13:21:55Z"}],"liveness":{"score":63,"band":"ok","label":"Likely open","p_open":1,"p_active":0.632,"p_room":1,"age_days":6,"expected_fill_days":57,"reasons":["conf:12","stale_co","velocity","win:early","comp:brand"],"computed_at":"2026-10-02T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/iceye-sovereign-infrastructure-operations-engineer","json_url":"https://alion.io/job/iceye-sovereign-infrastructure-operations-engineer.json","meta":{"generated_at":"2026-10-03T03:44:40Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3759,"day_limit":5000,"remaining_today":1241,"minute_limit":60,"resets_at":"2026-10-04T00:00:00Z"}}}