Senior DevOps Engineer
- Location
- Fully remote within the EU, with occasional presence in Zagreb
- Employment
- Full-time under Croatian law, 6-month probation
- Working hours
- Flexible, Zagreb time (CET/CEST) as the team default
- Languages
- Croatian and English
What you would be walking into
CRT builds CORA, a supervisory technology platform used by central banks and financial regulators in more than 20 jurisdictions. Regulatory reporting, supervisory workflows, analytics, AI-assisted processing — all of it in regulated production environments.
Our deployment setup is mixed, and some of that is deliberate. CORA runs in the cloud and on premises at client sites. Sometimes CRT has full operational access; sometimes we work inside infrastructure constraints we do not control. We are moving from Windows Server and Docker Compose toward more consistent container and Kubernetes delivery, while still supporting what our clients actually run today.
If you are looking for greenfield, this will frustrate you. If you like taking a working-but-varied estate and making it coherent, keep reading.
Delivery is about ten people. You would work alongside an engineer with deep knowledge of CORA's systems and deployments. This role is added capacity.
The role
You will own how CORA is built, packaged, released, observed, and operated. Senior individual contributor, and the target deployment and release model is yours to define.
What you will do
- Own and standardise our GitLab CI/CD patterns across modules: build, test, scan, package, publish, promote, deploy, roll back.
- Define a consistent release orchestration approach. Octopus Deploy is the current planned direction and needs validating.
- Align Dockerfiles, base images, runtime versions, health checks, and build parameters across modules.
- Lead the move toward Kubernetes delivery while keeping Docker Compose, Azure Container Apps, and Windows Server paths working.
- Set standards for logging, metrics, tracing, alerting, and operational evidence, including our OpenTelemetry rollout.
- Decide and implement a sanctioned approach to secrets across builds, internal package feeds, application configuration, and per-client deployment artefacts.
- Turn client-specific scripts, configuration, and runbooks into repeatable deployment patterns, without pretending client constraints away.
- Translate the relevant parts of our development lifecycle into pipeline checks and release controls.
- Work production incidents in CRT-managed environments, then improve the tooling and documentation that cut recovery time.
- Lead deployment, incident, and architecture conversations with clients when that is needed.
What you bring
- 5+ years in DevOps, platform engineering, systems engineering, or something comparable, with hands-on production responsibility.
- Shared CI/CD pipelines you designed and maintained in GitLab CI or a close equivalent.
- Strong production Docker: multi-stage builds, base image strategy, registries, image scanning.
- Confident Linux operations and troubleshooting across VMs and containers.
- Kubernetes or another container orchestration platform, used in anger.
- Working familiarity with Windows Server, IIS, and PowerShell. Some CORA components still depend on it.
- Experience building and publishing .NET applications and packages.
- Database deployment, backup, and migration discipline, preferably SQL Server.
- Identity infrastructure: Keycloak or another OIDC provider.
- A production message broker: RabbitMQ, Kafka, Azure Service Bus, or similar.
- Solid Bash and PowerShell, and a preference for automating things twice rather than doing them by hand five times.
- Croatian and English, written and spoken. We use both every day.
- Comfort talking directly to clients during deployment, incident, and architecture work.
- A considered view on AI-assisted tooling, including where it does not help.
You will not match every product in our stack. Nobody we have spoken to does.
Useful additional experience
- fintech, regtech, or suptech
- Azure Container Apps, AKS, or another managed Kubernetes service
- Helm and production Kubernetes operations
- Terraform, Bicep, ARM, or comparable infrastructure as code
- Octopus Deploy
- OpenTelemetry, OTLP, modern observability platforms
- Azure Key Vault or another production secrets platform
- SBOM, SCA, image scanning, DAST tooling
- MassTransit or Hazelcast operations
First 90 days
Understand the current delivery paths, take over day-to-day CI/CD and deployment decisions, and come back with an improvement sequence for releases, observability, and secrets that we can actually execute.
Working at CRT
- Remote anywhere in the EU, with occasional trips to Zagreb.
- Flexible hours. Zagreb time is when most of us overlap.
- This role is front-line for incidents in CRT-managed environments. We will walk you through the current support and escalation arrangement during hiring.
- Laptop and phone provided.
- Time off above the statutory minimum is negotiable.
How we hire
Three weeks from first call to offer is the target.
- Screening call. Fit, scope, working arrangement, support expectations.
- Technical interview or a representative case: a real deployment or platform problem and a conversation about it.
- Psychological assessment. We explain the format and purpose before this stage.
- Founder meeting, usually CEO and CTO.
- Offer.
How to apply
Use the application link with this ad and include your CV. No cover letter. Links to public work are welcome, not expected.
Include your CV.
Applying for Senior DevOps Engineer.
