About the job
About Ditto:
Ditto is revolutionizing data movement at the edge, with a mission to empower developers in creating resilient, real-time applications under any network conditions. Whether in a stadium, on an airplane, or at a remote military base, Ditto’s peer-to-peer synchronization engine guarantees that devices remain connected and data stays consistent, even without internet access. Backed by over $145 million in funding and trusted by leading organizations such as Chick-fil-A, Delta Airlines, and the U. S. military, Ditto facilitates mission-critical experiences across various sectors including aviation, retail, travel, hospitality, and defense. As a rapidly expanding, globally distributed startup, we are dedicated to fostering a diverse and inclusive team that embodies a wide spectrum of perspectives needed to tackle the world's toughest connectivity challenges.
We are on the lookout for a Platform Engineer to take charge of and architect Ditto's multi-cloud Kubernetes infrastructure. In this pivotal role, you will develop the platform that enables enterprise customer deployments across Azure, AWS, and GCP—from cluster provisioning to cross-cloud identity federation to secure access management. This role involves greenfield infrastructure work with a direct impact on business outcomes: enterprise customers are eagerly anticipating these capabilities, and the company’s product roadmap hinges on your contributions. You will define the methods for deployment and operation across cloud providers, addressing genuinely challenging distributed systems issues while creating infrastructure that is consistent and reliable, no matter where it operates.
What You'll Be Responsible For:
Leading the architecture and evolution of Ditto's managed Kubernetes platform across AKS, EKS, and GKE, ensuring operational excellence across cloud provider boundaries.
Designing and implementing cross-cloud identity and authentication systems, incorporating OIDC delegation and identity federation patterns to facilitate secure service communication across AWS, Azure, and GCP.
Creating secure access infrastructure that allows auditable cluster access for operations teams, including automated emergency access procedures and compliance controls.
Architecting cloud account governance systems that encompass provisioning, resource management, policy enforcement, and multi-tenant isolation across providers.
Designing ingress and traffic management strategies that replace legacy components with cloud-native solutions integrated into each provider's ecosystem.
Developing infrastructure lifecycle tooling that provisions, configures, and migrates Kubernetes environments, including migration pathways from legacy self-managed clusters to managed solutions.

