
Job Description
Senior Infrastructure Engineer
About Us:
BlackSky is a real-time intelligence company. We own and operate the world's most advanced space-based intelligence platform and provide customers satellite imagery, automated analytics and high-frequency monitoring of strategic locations, economic assets and events from around the globe. BlackSky is trusted by the most demanding allied military and intelligence organizations and commercial companies to deliver foresight into critical matters that affect national security and the economy. BlackSky's data enables governments and businesses to see, understand and anticipate change as it happens, giving them the ultimate strategic advantage so they can act quickly. Our global team works with cutting-edge technology to make a difference around the world and prides itself on being people-first, customer-focused and fun.
The BlackSky Platform team is building the premier global intelligence platform to deliver timely, relevant, and actionable information to customers. As a Senior Infrastructure Engineer, you will design, build and operate platforms that run our customer workloads across public cloud, private data centers, and air-gapped/disconnected environments. This is a hands-on engineering role for someone who is equally comfortable writing Terraform against AWS, troubleshooting kubernetes deployments and packaging full application stacks for delivery and implementation in isolated network environments.
As one of the team, you will be engaged in all aspects of our our multi-environment delivery pipelines from development through production and business continuity (BCP) environments. You will directly be involved in the successful automated deployment of solutions that meet our customers’ business objectives. Your contribution matters! The ideal candidate brings deep Kubernetes and GitOps operational experience implementing in public, private and isolated environments. This position reports to the Manager, Infrastructure and while we have offices in Herndon, VA and Seattle, WA, we are open to remote candidates in certain states.
Responsibilities:
- Design and operate AWS infrastructure (VPC, subnets, NLB/ALB, IAM, EKS, EC2, S3, Route 53) and the hybrid connectivity that ties cloud to on-premises and private/air-gapped networks.
- Stand up and run production-grade Kubernetes clusters on EKS, Rancher (RKE2) and/or Red Hat OpenShift 4, including upgrades, capacity planning, networking, storage, and day-2 operations.
- Implement and own GitOps workflows with Argo CD — declarative cluster and application state, app-of-apps patterns, sync policies, drift detection, and progressive rollout strategies.
- Author, version, and maintain Helm charts for internal and third-party workloads, including values management, chart dependencies, and templating standards across environments.
- Build repeatable delivery into disconnected environments using Zarf (and equivalent packaging/mirroring tooling) — bundling images, charts, and manifests for air-gapped installs and reproducible deployments.
- Codify infrastructure and platform configuration as code (Terraform, Helm, Kustomize) with a clear build-once / promote-per-environment strategy.
- Build and harden CI/CD pipelines that move artifacts safely from dev through to restricted production and BCP targets.
- Integrate platform services — certificate management (cert-manager), secrets management, container registries, storage, and observability — as shared, reusable building blocks.
- Establish operational standards: monitoring, alerting, logging, runbooks, incident response, and capacity/cost management.
- Other responsibilities as assigned.
Required Qualifications:
- At least five years years in infrastructure, platform, DevOps, or SRE engineering, with at least 3 years running Kubernetes in production.
- Bachelor's degree in a relevant field of study or equivalent experience (four years).
- Strong hands-on AWS experience across networking, compute, storage, and IAM, including hybrid/on-prem connectivity patterns.
- Production experience operating Kubernetes in one or more enterprise distributions — Amazon EKS, Rancher/RKE2, or OpenShift 4.
- Demonstrated GitOps experience with Argo CD (or Flux) as the primary deployment mechanism.
- Proficiency authoring and maintaining Helm charts, and a solid grasp of Kubernetes primitives (workloads, networking, RBAC, storage, CRDs/operators).
- Experience with the Kubernetes Operator deployment model — deploying and managing workloads via operators and CRDs (OLM/OperatorHub).
- Strong infrastructure-as-code skills, ideally with Terraform.
- Comfort with Linux systems administration and scripting (Bash, plus Python or Go).
- Experience building on hardened, non-CVE / zero-known-vulnerability base images (e.g., Chainguard, Iron Bank, or distroless/minimal baselines) and supply-chain security practices.
- Production monitoring and observability with Prometheus and Grafana (exporters, PromQL, alerting, dashboards).
- Clear written and verbal communication, and the ability to work independently across the full lifecycle of a platform component.
Preferred Qualifications:
- Breadth across all three of EKS, Rancher/RKE2, and OpenShift 4, with the ability to move fluidly between them.
- Experience running Kubernetes in edge / resource-constrained environments (e.g., k3s), including the operational tradeoffs of lightweight and disconnected deployments.
- Direct experience packaging and deploying into air-gapped / disconnected environments using Zarf, image mirroring, and private registries.
- Container and image scanning experience (Trivy, Grype, Clair, or equivalents) integrated into CI/CD and registry workflows.
- Familiarity with secrets management (Vault, External Secrets Operator) and PKI/certificate automation.
- Experience with persistent storage at scale (Ceph, EBS/EFS-backed storage classes).
- Hands-on OpenTelemetry (OTEL) experience — instrumenting services, running the OTEL Collector, and standardizing traces, metrics, and logs across the platform.
- Centralized log aggregation and analysis with Elasticsearch / OpenSearch (and shippers such as Fluent Bit, Fluentd, or Logstash).
- Background supporting regulated, government, or other compliance-driven programs.
- Service mesh experience with Istio (traffic management, mTLS, ingress/egress gateways, and observability integration).
- Relevant certifications (CKA/CKAD/CKS, AWS Solutions Architect / DevOps Engineer, Red Hat OpenShift, Rancher).
Life at BlackSky for full-time US benefits eligible employees includes:
- Medical, dental, vision, disability, group term life and AD&D, voluntary life and AD&D insurance
- BlackSky pays 100% of employee-only premiums for medical, dental and vision and contributes $100/month for out-of-pocket expenses!
- 15 days of PTO, 11 Company holidays, four Floating Holidays (pro-rated based on hire date), one day of paid volunteerism leave per year, parental leave and more
- 401(k) pre-tax and Roth deferral options with employer match
- Flexible Spending Accounts
- Employee Stock Purchase Program
- Employee Assistance and Travel Assistance Programs
- Employer matching donations
- Professional development
- Mac or PC? Your choice!
- Awesome swag
The anticipated salary range for candidates in Seattle, WA is $135,000-$150,000 per year. The final compensation package offered to a successful candidate will be dependent on specific background and education. BlackSky is a multi-state employer, and this pay scale may not reflect salary ranges in other states or locations outside of Seattle, WA.
BlackSky is committed to hiring and retaining a diverse workforce. We are proud to be an Equal Opportunity/Affirmative Action Employer All Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, sexual orientation, gender identity, disability, protected veteran status or any other characteristic protected by law.
To conform to U.S. Government space technology export regulations, including the International Traffic in Arms Regulations (ITAR) you must be a U.S. citizen, lawful permanent resident of the U.S., protected individual as defined by 8 U.S.C. 1324b(a)(3), or eligible to obtain the required authorizations from the U.S. Department of State.
EEO/AAP/ Pay Transparency Statements:
https://www.dol.gov/ofccp/regs/compliance/posters/pdf/eeopost.pdf
https://www.dol.gov/ofccp/regs/compliance/posters/pdf/OFCCP_EEO_Supplement_Final_JRF_QA_508c.pdf
Optimize Your Resume for This Job
Get a match score and see exactly which keywords you're missing
Job Details
- Category
- Operations
- Employment Type
- Full Time
- Location
- Herndon, VA (Hybrid)
- Posted
- Compensation
- $135,000 - $150,000 per year
About BlackSky
BlackSky Global is a satellite-imaging-as-a-service startup.
More Roles at BlackSky





Similar Operations Roles



Found this role interesting?