Careers · Open Role · 1 open

Platform Engineer (DevOps)

Amsterdam / remote-first · Employee or contractor · Full-time · Open

Runspace builds AI agents that do real work in the back office of banks and insurers. Not a chatbot, not a copilot: our agents work independently through claims files, verifications, fraud signals and compliance checks, inside the same systems and screens a human employee uses. That's why we need no integration project — and it's also why, on the infrastructure side, we're a different kind of company than the average SaaS startup.

Every customer gets their own isolated environment: their own cluster, their own data, their own models. Those environments get provisioned, scaled, monitored and audited. That's your domain.

We're a focused, experienced team — people who have built and shipped this kind of thing before — serving customers in financial services and insurance. Infrastructure here isn't a side concern that "also needs sorting"; it's the product.

Three things make this work different from plain Kubernetes administration.

  1. i.

    Making it run where it's hardest.

    The real challenge isn't Kubernetes — it's getting autonomous AI agents to run, provably and safely, inside the most tightly regulated environments there are: banks, insurers, and increasingly sectors like defense. Every constraint that makes those industries hard — data that can't leave the building, air-gapped or private-cloud deployments, an auditor who wants evidence for every claim — lands on the infrastructure. Making the technology viable there at all is the job.

  2. ii.

    Our customers get to audit us.

    DORA, ISO 27001, SOC 2, and a major bank's security team that literally wants to see your Terraform. Hardening isn't a backlog you clear later — it's a condition of getting in the door.

  3. iii.

    The workload is unusual.

    What we run doesn't look like a typical web service — long-running, stateful, resource-hungry processes that behave, fail and recover in their own way. There's no playbook for running them cleanly — that's part of what you'll figure out.

  • Own the provisioning layer: Terraform and Helm that stand up a complete, isolated environment per customer.
  • The reconciler that keeps the desired and actual state of all those environments aligned.
  • Autoscaling and cost optimisation, including scale-to-zero and right-sizing node SKUs per workload.
  • Observability: knowing what an agent run cost, where it got stuck and why, without having to dig through logs.
  • Keeping the runtime reliable under load.
  • Contributing to the security baseline and the evidence for it: RBAC, pod security, network policy, secrets, key management.
  • Talking to customers' security officers and auditors. Not as a formality, but because you built it.
  • Azure / AKS
  • Terraform
  • Helm
  • Cilium (eBPF dataplane)
  • Node Auto-Provisioning
  • SingleStore
  • GitHub Actions

An important part of the job: not every customer runs on our platform. Some run Runspace entirely themselves — bring-your-own, deployed inside their own private cloud, operated by their own teams. So what you build has to be portable and reproducible enough that another organisation can stand it up and run it in their environment, not just ours. Designing for that is a core requirement, not an afterthought.

You don't need to have done all of this. But you do want to be comfortable with the question "what exactly is happening here" at every level between a YAML file and a cloud invoice.

  • You've carried production Kubernetes, not just set it up. You know what it feels like when it breaks at night.
  • You're at home in infrastructure-as-code and you consider manual clicks in a cloud portal a bug.
  • You can be the only infra person in the room and still make choices that hold up two years later.
  • You find cost interesting. Not out of thrift, but because efficient infrastructure is what makes the business work.
  • You're comfortable in direct contact with customers — in this role you'll sit across from their security, compliance and platform teams yourself, not behind a wall of account managers.

What we're not looking for: someone who needs a fully spec'd ticket. There's no platform team around you yet. That's the attractive side and the hard side of the same role.

Location
Netherlands, fully remote. In-person when the work calls for it.
Employment
Employee or contractor — both work.
Compensation
At market.
Start
To be discussed.

Tell us what you've worked on. No cover letter needed — a few lines about the hardest infrastructure problem you've solved tells us more.

We read everything ourselves.

We reply to every application, usually within a few days.