Posted today · be early
Application Architect / Tech Lead (m/w/d)
DACHS IT
WorldwideremotePosted 1 day ago
Skill Required
Application-ArchitectureTechnical-LeadCloud-Infrastructure-EngineeringManaged-ServicesSaaS-EngineeringSenior-Application-ArchitectSenior-Application-Development-LeadApplications-ArchitectIT-Applications-ArchitectApplication-ArchitectSenior-Enterprise-Application-ArchitectEngineeringPostgreSQLKubernetesPrometheusGitHub ActionsObservabilitysecurityMySQLdesignDevOpsArgoCDGitCI/CDCloudHelmITILIAMDNSCICDFulltime
Key highlights
- Annual participation in company profits (in addition to fair fixed salary)
- Senior-level position with technical leadership but no disciplinary personnel responsibility
- 30 days vacation per year that do not expire
- ISO 27001 conformity ownership based on BSI IT-Grundschutz
- Multi-tenant SaaS architecture across multiple Kubernetes clusters with tenant isolation
- Company car option depending on role
Role overview
DACHS IT seeks an Application Architect / Tech Lead to lead the technical direction of their Managed Service, specifically the openDesk SaaS platform. This is a senior individual contributor role with technical leadership responsibilities but without direct personnel management. The role spans architecture design across multiple Kubernetes clusters, engineering standards, mentoring, ISO 27001 compliance, and ITIL process integration. DACHS IT operates as a remote-first organization with flexible hours, emphasis on work-life balance, and a collaborative culture that includes regular team gatherings despite distributed work.
Responsibilities
- Design target and deployment architecture for mandantenfähigen (multi-tenant) openDesk SaaS operation across multiple Kubernetes clusters
- Establish engineering standards and document decisions as ADRs; conduct design and code reviews
- Architect and maintain Helmfile-based openDesk deployment (35+ Helm Charts, Helm-Diff, Environments/Values) with GitLab CI delivery
- Deploy supporting services via GitOps where possible
- Develop database concept based on operated operators (CNPG for PostgreSQL, MariaDB Operator) including backup/restore and PITR
- Manage application secret management via ExternalSecrets against OpenBao
- Define application-side monitoring and alerting concepts (custom metrics, SLI/SLO) based on provided stack (kube-prometheus-stack, Thanos, Loki)
- Own technical side of ISO 27001 conformity based on BSI IT-Grundschutz: security contexts, technical controls, evidence collection
- Design ITSM processes per ITIL (Incident, Problem, Change, Release) and anchor them technically, including CI/CD integration in Change Management
- Define clear interfaces to Platform Team and make build-vs-buy decisions for the service
- Mentor DevOps, rollout, and support engineers
- Participate in on-call rotation
- Live and model a 360-degree feedback culture
Requirements
- Several years of experience in architecture and operation of complex, Kubernetes-based application landscapes as SaaS/Managed Service
- Deep knowledge of openDesk stack or comparable collaboration components (IAM/Keycloak/Nubus, Groupware, Nextcloud, Videoconferencing, Wiki/PM-Tools)
- Proficient with Helm and Helmfile (Multi-Chart Deployments, Helm-Diff, Values/Environments) as well as CI-driven rollout (e.g., GitLab CI) and GitOps (Flux)
- Experience with database operation in Kubernetes via operators, ideally CNPG/CloudNativePG (PostgreSQL) and/or MariaDB Operator, including backup/restore and PITR
- Experience with secret management (ExternalSecrets, Vault/OpenBao) and application-side monitoring/alerting (Prometheus ecosystem, Thanos, Loki)
- Experience in IT service management per ITIL: process design (Incident, Problem, Change, Release) and integration of CI/CD in ITSM processes
- Technical responsibility for information security per ISO 27001 based on BSI IT-Grundschutz
- Solid Linux skills and willingness to participate in on-call rotation
- German and English at business level (C1/C2) written and spoken
- Concrete production experience with openDesk and its deployment repository (Helmfile structure, release/patch process)
- Experience with multi-tenant SaaS operation (tenant isolation via namespaces, scaling, multi-customer migrations)
- Knowledge of openDesk supporting services (Redis/Memcached, object storage, mail/postfix infrastructure, ClamAV/ICAP, Coturn)
- Experience with multi-cluster operation and tenant separation
- Certifications (e.g., CKA/CKS, ITIL, ISO 27001 Lead Implementer/Auditor, BSI IT-Grundschutz Practitioner)
- Technical leadership strength without disciplinary responsibility: providing orientation, persuading, mentoring
- Very good analytical and conceptual skills; substantiating trade-offs in an understandable way
- Communication strength with engineers, service owners, and the Platform Team
- Hands-on mentality: ability to conceptualize and step in during emergencies
- Willingness to live and solicit 360-degree feedback
- Experience in moderation, conflict resolution, and de-escalation
- Experience in training and knowledge transfer (trainings, workshops)
Nice to have
- Zertifizierungen (z. B. CKA/CKS, ITIL, ISO 27001 Lead Implementer/Auditor, BSI IT-Grundschutz-Praktiker)
- Erfahrung in Moderation, Konfliktlösung und Deeskalation
- Erfahrung in Schulung und Knowledge-Transfer (Trainings, Workshops)
- Experience with openDesk supporting services not explicitly listed as must-have
Benefits
- Remote-First as lived model: decide where you are most productive (home office, shared office, or combination)
- Flexible working hours with personal responsibility: schedule work flexibly within projects, reliability and transparent communication valued over desk presence
- Exciting projects instead of routine tickets: find projects matching your profile and development
- Regular training, certifications, and knowledge exchange with cost coverage and release time
- Modern equipment: modern hardware, appropriate software, and necessary equipment for efficient and comfortable work
- Fair fixed salary plus annual participation in company profits
- Company car option depending on role
- 30 days vacation per year that do not expire
- Additional coverage through group accident insurance
- Regular team activities for personal exchange despite remote-first structure
- 360-degree feedback culture: regular honest conversations at eye level
- Transparent feedback culture and development: no annual mandatory dates, but regular open conversations
Additional details
- Application process: Screening of documents → 30-45 minute video call (team member) → 60-minute technical interview with 1-2 consultants → personal meeting with Managing Director Alexander → offer with transparent, comprehensible details with all important information
- Bewerbungsprozess includes clear structured steps with timely feedback at each phase
- DACHS IT emphasizes fitting work environment to life, strengths, and goals rather than treating position as mere job
- Team culture values personal exchange despite remote-first: get-togethers, workshops, active outings for genuine cohesion beyond screens