Skip to content

Open nowPosted 31 hours ago

Site Reliability Engineer (SRE) - II — Shape Security

Wing VC portfolio798 open roles

Pay
$124,800 – $187,200 a year
Where
San Jose, CA, USA
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSite Reliability Engineer (SRE) - II — Shape SecurityWing VC portfolio · San Jose, CA, USA
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Wing VC portfolio's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.1% of postings close within 7 days. Measured by our own scanner across the market. Wing VC portfolio postings stay open a median of 28 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.6%3 days
  3. 8.1%7 days
  4. 15.0%14 days
  5. 34.0%30 days
This job: posted 31 hours ago

Wing VC portfolio median: 28 days open

The posting

At F5, we strive to bring a better digital world to life. Our teams empower organizations across the globe to create, secure, and run applications that enhance how we experience our evolving digital world. We are passionate about cybersecurity, from protecting consumers from fraud to enabling companies to focus on innovation.

Everything we do centers around people. That means we obsess over how to make the lives of our customers, and their customers, better. And it means we prioritize a diverse F5 community where each individual can thrive.

Role Summary

We are seeking a proactive and detail-oriented Site Reliability Engineer II (SRE II) to join our 24/7 Operations team in a hybrid capacity. In this role, you will provide round-the-clock, eyes-on-glass monitoring, proactive incident response, operational maintenance, and continuous compliance support across our hybrid environment—spanning bare-metal on-premises Red Hat Enterprise Linux (RHEL) servers, AWS (Commercial and GovCloud), and Kubernetes (EKS) infrastructure operating under strict FedRAMP standards.

As an SRE II, your primary responsibility is maintaining platform availability, hardware reliability, and security posture through real-time telemetry monitoring via Prometheus and Grafana, log troubleshooting and root cause analysis in Kibana and Elasticsearch, rapid incident triage in Slack, execution of automated deployments and GitOps continuous delivery via GitLab CI/CD, ArgoCD, and Argo Workflows, and consistent enforcement of FedRAMP security controls (NIST SP 800-53). You will operate in a structured shift model covering weekdays and weekends to ensure 24/7/365 hybrid platform uptime.

24/7 Shift & On-Call Expectations

This position requires active participation in a 24/7/365 operational shift model:

• Round-the-Clock Coverage: Active "eyes-on-glass" monitoring during scheduled shifts (day, evening, night, and weekend rotations).

• Weekend & Holiday Rotation: Scheduled weekend shifts and holiday coverage to ensure continuous operational readiness across both on-premises data centers and cloud regions.

• On-Call Escalations: Primary and secondary on-call responsibilities during and outside regular shift windows to meet stringent FedRAMP Incident Response (IR) SLAs.

• Real-time Collaboration: Continuous presence in operational Slack channels and ChatOps bridge rooms for instant incident mobilization.

Key Responsibilities

1. 24/7 Eyes-on Monitoring, Log Troubleshooting & Incident Triage

• Maintain continuous monitoring of production telemetry across bare-metal RHEL servers, EKS clusters, and AWS cloud environments.

• Act as first responder to high-priority alerts generated by Prometheus and Alertmanager, performing immediate triage and root cause investigation.

• Perform deep-dive log troubleshooting using Elasticsearch and Kibana (building queries, analyzing container/application stdout logs, systemd/journald logs, and ingress traffic logs) to isolate error patterns and service failures.

• Coordinate incident resolution bridges in Slack, engaging secondary on-call engineers, security teams, or infrastructure engineers as required.

• Maintain rigorous adherence to Incident Response SLAs and document timeline logs for post-incident reviews (RCAs).

2. Bare-Metal On-Premises RHEL Server Support & Hardware Operations

• Provide operational support for bare-metal on-premises Linux servers (RHEL), including OS configuration, system maintenance, and day-to-day lifecycle administration.

• Diagnose physical network interface bonding, link aggregation, VLAN tagging, and local server connectivity issues on bare-metal systems.

• Coordinate vendor hardware dispatch requests for failing server components and oversee physical parts replacements.

3. FedRAMP Security & Vulnerability Remediation

• Execute day-to-day security operational duties aligned with FedRAMP High/Moderate (NIST SP 800-53) standards.

• Perform routine vulnerability patching (CVE remediation) across bare-metal RHEL servers, cloud AMIs, Kubernetes worker nodes, and container images within strict regulatory timelines.

• Apply operational system hardening based on DISA STIG guidelines and maintain FIPS 140 compliance configurations across both cloud and on-premise operating systems.

• Ensure strict Role-Based Access Control (RBAC), SSH key management, and security boundary enforcement across operational environments.

4. Kubernetes (EKS), AWS Infrastructure & Networking Operations

• Support day-to-day operations and node maintenance for Amazon EKS clusters across AWS Commercial and AWS GovCloud environments.

• Perform Layer 4 (L4) and Layer 7 (L7) secure load balancing troubleshooting, including AWS Application Load Balancers (ALB), Network Load Balancers (NLB), ingress controllers, SSL/TLS certificate termination, and traffic routing issues.

• Perform Linux administration tasks including kernel parameter tuning (sysctl), storage expansion, log rotation, and system troubleshooting.

• Execute infrastructure changes and updates using Infrastructure as Code (Terraform) in alignment with change control procedures.

• Monitor key AWS cloud infrastructure components including VPCs, Security Groups, EC2, IAM, S3, and KMS.

5. CI/CD & GitOps Deployment Operations (GitLab, ArgoCD, Argo Workflows)

• Execute, monitor, and troubleshoot automated deployment pipelines using GitLab CI/CD.

• Manage application state, synchronization, and rollouts across Kubernetes clusters using ArgoCD (GitOps paradigm).

• Monitor, execute, and troubleshoot operational batch processes, system maintenance tasks, and automated pipelines using Argo Workflows.

• Facilitate application releases and configuration rollouts using Helm charts, Kustomize, and GitOps workflows.

• Validate build pipeline compliance, container security scanning results, and image signature verifications prior to production deployment.

6. Documentation & Operational Runbooks

• Maintain accurate, step-by-step incident runbooks, standard operating procedures (SOPs), and triage workflows for both cloud and bare-metal environments.

• Write detailed post-incident reports and post-mortems for production impact events.

• Identify manual operational overhead (toil) and implement shell scripts (Bash/Python) to streamline routine monitoring, hardware checks, and maintenance tasks.

Technical Skills & Qualifications

Required Qualifications

• Citizenship & Regulatory Standard: US Citizenship required due to FedRAMP / AWS GovCloud security requirements.

• Experience: 3–5 years of hands-on experience in SRE, DevOps, Systems Administration, or Hybrid Infrastructure Support roles.

• 24/7 Shift Availability: Willingness and capability to work in a 24/7 rotational shift schedule (including nights, weekends, and holidays).

• Bare-Metal & On-Premises Linux Administration: Strong hands-on experience administering bare-metal Linux servers (Red Hat Enterprise Linux / RHEL), including hardware diagnostics, out-of-band management (IPMI, iDRAC, iLO), RAID configuration, LVM, and physical NIC bonding.

• Log Troubleshooting (Kibana/Elasticsearch): Direct experience querying and analyzing log streams in Kibana and Elasticsearch (KQL/Lucene queries, index management, log pattern matching for microservices and cluster components).

• L4/L7 Secure Load Balancing: Practical experience troubleshooting Layer 4 (NLB) and Layer 7 (ALB / Ingress Controllers) secure load balancing, mTLS, TLS termination, health checks, and secure traffic routing.

• AWS & GovCloud: Solid operational experience with AWS core services (EC2, VPC, IAM, S3, KMS) and familiarity with AWS GovCloud operating models.

• Kubernetes (EKS): Hands-on operational experience with Amazon EKS / Kubernetes (kubectl, Helm, pod lifecycle management, node pool maintenance).

• Observability Tools: Experience working with Prometheus, PromQL metrics queries, Alertmanager, and Grafana dashboard visualization.

• CI/CD & Continuous Delivery: Hands-on operational experience executing and troubleshooting deployments with GitLab CI/CD, managing GitOps syncing with ArgoCD, and orchestrating Kubernetes workflows using Argo Workflows.

• ChatOps & Communication: Experience utilizing Slack for operational messaging, ChatOps commands, and incident war rooms.

• FedRAMP / Security Hardening: Understanding of FedRAMP/NIST SP 800-53 controls, vulnerability patching cycles, and DISA STIG hardening on both bare-metal and cloud Linux systems.

Preferred Qualifications

• Experience with automation scripting using Python or Bash.

• Basic working knowledge of Terraform for infrastructure maintenance.

• Red Hat Certified System Administrator (RHCSA) or Red Hat Certified Engineer (RHCE).

• AWS Certified SysOps Administrator or Certified Kubernetes Administrator (CKA).

Key Performance Indicators (KPIs)

• Monitoring MTTA (Mean Time to Acknowledge): Rapid response times for eyes-on alert notifications.

• MTTR (Mean Time to Resolve): Efficient triage, log analysis in Kibana, and mitigation of production service disruptions across cloud and bare-metal environments.

• Hardware Availability & Uptime: Rapid isolation and remediation of physical server component failures and RAID disk faults.

• Deployment & GitOps Stability: High release success rates and swift remediation of failed ArgoCD syncs or Argo Workflows runs.

• Shift Readiness & Escalation Precision: Clear shift handovers and timely escalation management during 24/7 windows.

• CVE Remediation Timeliness: Strict compliance with patching SLAs for bare-metal OS, container images, and cloud AMIs.

• Runbook Currency: Continuous refinement of operational runbooks based on shift learnings.

#LI-KA1

The Job Description is intended to be a general representation of the responsibilities and requirements of the job. However, the description may not be all-inclusive, and responsibilities and requirements are subject to change.

The annual base pay for this position is: $124,800.00 - $187,200.00

F5 maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, geographic locations, and market conditions, as well as to reflect F5’s differing products, industries, and lines of business. The pay range referenced is as of the time of the job posting and is subject to change.

You may also be offered incentive compensation, bonus, restricted stock units, and benefits. More details about F5’s benefits can be found at the following link: https://www.f5.com/company/careers/benefits. F5 reserves the right to change or terminate any benefit plan without notice.

Please note that F5 only contacts candidates through F5 email address (ending with @f5.com) or auto email notification from Workday (ending with f5.com or @myworkday.com).

Equal Employment Opportunity

It is the policy of F5 to provide equal employment opportunities to all employees and employment applicants without regard to unlawful considerations of race, religion, color, national origin, sex, sexual orientation, gender identity or expression, age, sensory, physical, or mental disability, marital status, veteran or military status, genetic information, or any other classification protected by applicable local, state, or federal laws. This policy applies to all aspects of employment, including, but not limited to, hiring, job assignment, compensation, promotion, benefits, training, discipline, and termination. F5 offers a variety of reasonable accommodations for candidates. Requesting an accommodation is completely voluntary. F5 will assess the need for accommodations in the application process separately from those that may be needed to perform the job. Request by contacting [email protected].

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Wing VC portfolio's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Wing VC portfolio's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Wing VC portfolio's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.