…

Sr. Assoc, Devops Engineer

Revantage Global · Construction & Real Estate

  • Bengaluru
  • On-site
  • Posted today
  • IT & Infrastructure

About the job

ABOUT REVANTAGE

Revantage, a Blackstone Real Estate portfolio company, is a global provider of corporate services.

With a corporate purpose of ‘In Pursuit of Better,’ Revantage delivers value-added services and world-class talent for Blackstone Real Estate portfolio companies, spanning diverse asset classes, including residential, logistics, office, hospitality and retail sectors. The company’s footprint extends across North America, Europe and Asia Pacific.

Creating a culture that inspires impact and momentum requires the right team. We know what it takes to lead an industry, and are looking for leaders who seek constant growth, want to excel, and continuously improve upon themselves and the industry.

In addition to supporting Revantage, we also recruit for Blackstone Real Estate portfolio companies, giving you the unique opportunity to work within a network of best-in-class professionals across a broad real estate platform.

India

With offices in Bengaluru and Gurugram, our teams in India deliver expertise, innovation and operational excellence that support thousands of assets across logistics, data centers, residential, commercial and hospitality.

Whether you’re building new capabilities, driving critical initiatives or strengthening partnerships, you’ll have the opportunity to truly  Build What Matters.

Summary / Position Objective

The DevOps Engineer is responsible for building, automating, securing, and operating cloud infrastructure and delivery pipelines in Microsoft Azure, with a significant focus on infrastructure as code using Terraform and on the operation of the Databricks data platform. This position codifies infrastructure rather than clicking through portals, treats pipelines and environments as products, and is measured by the reliability, repeatability, security, and cost efficiency of what it builds.

Working as an integrated member of the Security and IT Operations organization alongside software developers, data engineers, cybersecurity engineers, and systems administrators, the DevOps Engineer partners early in the delivery lifecycle to make the secure path the easy path. This role also participates in on-call rotation, release and maintenance windows, and incident response for the platforms it owns. This position reports to the Director of IT Operations.

Critical Duties

Infrastructure as Code and Azure Platform Engineering

Design, write, review, and maintain Terraform code to provision and manage Azure infrastructure, including reusable modules, consistent naming and tagging standards, and version pinning of providers and modules.
Own Terraform state management, including remote backends, state locking, workspace and environment separation, drift detection, and safe remediation of drift without destructive changes.
Build and maintain Azure foundational infrastructure, including subscriptions and resource groups, virtual networks, subnets, network security groups, private endpoints, DNS, load balancing, and storage.
Implement guardrails as code, including Azure Policy, role assignments, resource locks, and budget and tagging enforcement, so environments are compliant by construction rather than by audit.
Manage environment promotion across development, test, and production with identical code paths and environment-specific configuration held outside of code.
Eliminate manual and portal-based infrastructure changes by bringing existing resources under Terraform management and documenting the exceptions that cannot be.

CI/CD and Release Engineering

Build, maintain, and optimize CI/CD pipelines (Azure DevOps Pipelines and/or GitHub Actions), including build, test, artifact publication, and multi-stage deployment with approvals.
Implement automated quality and security gates in pipelines, including linting, unit and integration test execution, Terraform plan review, static analysis, dependency scanning, and container image scanning.
Establish and enforce source control practices, including branching strategy, pull request review requirements, protected branches, and traceability from commit to deployed change.
Automate deployment and rollback so that releases are low-drama and reversible, and reduce lead time from merge to production.
Manage build agents, runners, service connections, and workload identity federation, eliminating long-lived credentials wherever possible.

Databricks and Data Platform Operations

Provision and manage Databricks workspaces and workspace configuration through Terraform rather than manual setup.
Administer Databricks platform operations, including cluster policies, instance pools, compute sizing, autoscaling, auto-termination, runtime version management, and job and workflow orchestration.
Implement and maintain Unity Catalog structure and governance, including metastore configuration, catalogs and schemas, external locations, storage credentials, and grants aligned to least privilege.
Integrate Databricks identity with Microsoft Entra ID, including SCIM provisioning of users and groups, and coordinate entitlement design with the Identity and Access Management team.
Secure the data platform, including secret scopes backed by Azure Key Vault, private connectivity to Azure Data Lake Storage, network isolation, and elimination of embedded credentials in notebooks and jobs.
Build CI/CD for data assets, including Databricks Repos or Git folders, notebook and job deployment automation, and environment-specific configuration for data pipelines.
Monitor platform health, job reliability, and cost; implement chargeback tagging, cluster cost controls, and alerting on runaway compute.
Partner with data engineering to troubleshoot job failures, performance problems, and Delta Lake and storage layer issues.

Observability, Reliability, and Automation

Implement and maintain monitoring, logging, and alerting using Azure Monitor, Log Analytics, and Application Insights, with alerts that are actionable and tuned to reduce noise.
Define and track service level indicators and objectives for owned platforms, and drive down recurring failure modes rather than repeatedly remediating them.
Write and maintain automation and tooling in PowerShell, Python, and/or Bash to eliminate repeatable operational work.
Build and operate containerized workloads where applicable, including Docker images, Azure Kubernetes Service, and container registry lifecycle and image hygiene.
Author and maintain runbooks, architecture diagrams, and operational documentation sufficient for another engineer to operate the platform unaided.
Participate in incident response for owned platforms, including triage, mitigation, restoration, and blameless post-incident review with corrective actions tracked to closure.
Design and validate backup, recovery, and business continuity capability for infrastructure and platform configuration, including periodic restore testing.

Security, Governance, and Cost

Apply DevSecOps practices throughout the pipeline, shifting security checks left and treating security findings as build-blocking defects rather than backlog items.
Implement least-privilege access using Azure role-based access control, managed identities, and workload identity federation; route all human entitlement and privileged access requests through the Identity and Access Management team in accordance with company policy.
Manage secrets and certificates in Azure Key Vault, including rotation, and remediate any secrets found in code, pipelines, or configuration.
Partner with Information Security on vulnerability remediation, cloud security posture findings (including Microsoft Defender for Cloud), hardening standards such as CIS benchmarks, and evidence for control reviews.
Follow change management for all production changes, including documented change records, tested rollback plans, and adherence to approved change windows.
Monitor and optimize cloud spend, including rightsizing, reservation and savings plan recommendations, orphaned resource cleanup, and cost visibility reporting to leadership.

Coverage, On-Call, and Business Continuity

Maintain overlap with U.S. Central Time business hours for collaboration with U.S.-based engineering, data, and security teams.
Participate in a rotating holiday coverage schedule, including Indian holidays, to ensure uninterrupted support for a U.S.-based enterprise.
Provide support outside normal business hours as operational needs dictate, including incident response and critical production events.
Support a 24×7 operational environment through scheduled rotation, on-call responsibilities, and business continuity requirements.
Execute planned deployments, patching, and maintenance during approved windows, which may fall on U.S. nights or weekends.

Essential Duties

Partner with software developers and data engineers early in design to make infrastructure, pipeline, and platform decisions that hold up in production.
Review peers' infrastructure and pipeline code, and accept review on your own, treating code review as a quality control rather than a formality.
Document and continuously improve platform standards, reference architectures, and repeatable patterns to create consistency and increase efficiency.
Identify and retire technical debt, including unmanaged resources, deprecated runtimes, unsupported provider versions, and one-off snowflake environments.
Evaluate new Azure and Databricks capabilities against real needs, pilot deliberately, and recommend adoption with a clear cost, risk, and operational impact assessment.
Provide knowledge transfer and enablement to IT Operations and application teams so platform ownership is not concentrated in a single person.
Contribute to capacity planning, platform roadmap input, and cloud budget forecasting.
Maintain ongoing working knowledge of cloud platform engineering, infrastructure as code, and data platform best practices, and proactively bring applicable improvements to the team and leadership.

OTHER DUTIES MAY BE ASSIGNED

Qualifications

To perform this job successfully, an individual must be able to perform each critical duty satisfactorily. The requirements listed are representative of the minimum knowledge, skills, and/or abilities required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

Education / Experience

5+ years' experience in DevOps, cloud platform engineering, site reliability engineering, or cloud infrastructure engineering.
3+ years' hands-on production experience with Microsoft Azure, including networking, identity, storage, and compute.
2+ years' hands-on production experience authoring and maintaining Terraform at scale, including modules and remote state management.
2+ years' hands-on experience administering or operating Databricks, including cluster policies, jobs, and workspace configuration; Unity Catalog experience strongly preferred.
Demonstrated experience building and maintaining CI/CD pipelines in Azure DevOps and/or GitHub Actions.
Strong scripting and automation ability in PowerShell, Python, and/or Bash.
Working experience with Git-based source control workflows and code review practices.
Experience with containers and orchestration (Docker, Azure Kubernetes Service) preferred.
Experience with Microsoft Entra ID, managed identities, service principals, and role-based access control.
Working knowledge of SQL and data pipeline concepts sufficient to support a data platform and troubleshoot alongside data engineers.
Experience supporting a U.S.-based enterprise from an offshore location, including on-call rotation, strongly preferred.
Excellent spoken and written English with proven ability to communicate effectively with U.S.-based technical teams and to document clearly.

Certificates / Licenses — sample of some preferred certificates and licenses:

Microsoft Certified: DevOps Engineer Expert (AZ-400).
Microsoft Certified: Azure Administrator Associate (AZ-104).
HashiCorp Certified: Terraform Associate.
Databricks Certified Data Engineer Associate or Databricks Certified Associate Platform Administrator.
Microsoft Certified: Azure Security Engineer Associate (AZ-500).
Microsoft Certified: Azure Solutions Architect Expert (AZ-305) (a plus).
Certified Kubernetes Administrator (CKA) (a plus).
CompTIA SecAI+ (Security AI+) (a plus).

Knowledge / Skills / Abilities

Knowledge of:

Proficient in the best practices secure use of GenAI tools like ChatGPT, Claude, MS Co-Pilot, and Gemini, including appropriate data handling and never exposing source code, secrets, or infrastructure detail to unapproved tools.
Applying AI coding assistants such as GitHub Copilot to infrastructure and pipeline work, with the judgment to review generated code rather than trusting it, particularly where it touches security, networking, or state.
Securing AI-enabled applications and services by applying identity, authentication, authorization, privileged access, and governance best practices to AI workloads and platforms.
Infrastructure as code principles, including idempotency, immutability, declarative configuration, and the practical failure modes of state-based tooling.
Azure platform architecture, including landing zone concepts, subscription and management group design, networking, and private connectivity patterns.
Databricks platform architecture and governance, including compute management, Unity Catalog, and cost control levers.
CI/CD design, release strategies, artifact and dependency management, and pipeline security.
Cloud security and governance practices, including least privilege, secret management, workload identity, and posture management tooling.
Observability practices, including metrics, logs, traces, alert design, and service level objective definition.
ITIL change, incident, and problem management processes as they apply to production platform changes.
Cloud cost management and optimization practices.
Working with cross-functional teams in a fast-growing, rapidly changing environment.
Exercising initiative and using good judgment to make sound decisions, and translating business requirements into technical solutions.

Ability to:

Automate by default and treat any manual production change as a defect to be engineered away.
Work independently as a self-starter with a hands-on approach, and know when to stop and ask rather than guess on a production system.
Define problems, collect data, establish facts, and draw valid conclusions.
Remain calm, methodical, and communicative during outages and high-pressure production events.
Reason about blast radius before making a change, and design changes that fail safely.
Balance delivery speed against reliability, security, and cost, and explain the tradeoff to non-specialist stakeholders.
Quickly learn new concepts and services and maintain a proactive attitude toward platform enhancements.
Remain detail oriented while multitasking and meeting multiple deadlines.
Work remotely without direct supervision and effectively with other remote team members across time zones.
Write reports, runbooks, architecture documentation, business correspondence, and procedural manuals.

Performance Measures

Percentage of infrastructure under Terraform management, and reduction in manual and portal-based changes.
Deployment frequency and lead time from merge to production.
Change failure rate and mean time to restore for owned platforms.
Platform availability and Databricks job reliability against defined objectives.
Pipeline security gate coverage and time to remediate critical findings.
Zero long-lived credentials or secrets stored outside of Key Vault.
Cloud cost variance against forecast, and realized savings from optimization work.
Completeness and accuracy of runbooks and architecture documentation, validated by another engineer operating from them.

Job Applicant Privacy Notice

EEO Statement

The Company is an equal opportunity employer. In accordance with applicable law, we prohibit discrimination against any applicant, employee, or other covered person based on any legally recognized basis, including, but not limited to: veteran status, uniformed servicemember status, race, color, caste, immigration status, religion, religious creed (including religious dress and grooming practices), sex, gender, gender expression, gender identity, marital status, sexual orientation, pregnancy (including childbirth, lactation or related medical conditions), age, national origin or ancestry, citizenship, physical or mental disability, genetic information (including testing and characteristics), protected leave status, domestic violence victim status, or any other consideration protected by federal, state or local law. We are committed to providing reasonable accommodations, if you need an accommodation to complete the application process, please email TalentAcquisitionIndia@revantage.com