Platform Engineer - Fintech/ Crypto
What engineering roles in crypto pay
243 salaries · our own dataMost engineering roles in crypto pay between $146k and $255k, with a median of $202k.
As a Platform Engineer at a leading cryptocurrency and blockchain security company, you will work closely with product engineering teams to improve developer experience and remove friction from the build, package, and deployment process. You will own and improve developer tooling, self-service platforms, golden paths, runners, registries, delivery tooling, and observability across CI/CD, artifact management, progressive delivery, and infrastructure automation.
What you'll do
- Own and evolve the self-hosted GitHub Actions runner fleet, including Linux runners managed via Actions Runner Controller (ARC), self-hosted macOS runners, and the Terraform modules that provision and scale self-hosted infrastructure.
- Right-size runner classes (CPU/memory/storage) against real workload profiles, balancing cost efficiency against engineering velocity, and support engineering teams in understanding and owning the resource footprint of their own jobs.
- Support the migration away from GitHub-hosted runners, including evaluating trade-offs between containerised and VM-based execution for workloads with special hardware requirements such as KVM access for Android emulators.
- Partner with embedded DevOps engineers on pipeline and dependency-graph optimisations (build triggers, job fan-out, monorepo change detection) to reduce queue times and unnecessary CI spend.
- Investigate and resolve macOS virtualisation performance issues such as with Tart and help evaluate alternative approaches such as remote simulator hosts.
- Administer the JFrog Platform (Artifactory, Xray, Curation) as the organization's primary artifact repository, including repository structure, access control, vulnerability scanning policies, and curation/allow-listing of upstream dependencies.
- Provide light-touch, minimal support for GitHub Container Registry (GHCR) and GitHub Packages where teams use them alongside JFrog.
- Operate and maintain ChartMuseum as the organization's Helm chart repository, hosted on S3, including storage lifecycle, access, and chart promotion workflows.
- Define and enforce container image ownership boundaries between platform-owned hardened/minimal base images such as Docker Hardened Images or Chainguard versus engineering-owned project extensions, and drive Dockerfile build and layer optimisation best practices across teams.
- Operate two ArgoCD / Argo Rollouts environments, one serving internal tooling and one serving product workloads supporting GitOps-based, progressive delivery patterns (canary/blue-green) for engineering teams.
- Author, maintain, and support Helm charts and Kustomize overlays as the standard configuration management approach for Kubernetes workloads, providing golden-path templates that reduce boilerplate for product teams.
- Design, review, and evolve Terraform and Terragrunt modules for infrastructure-as-code, including maintaining a public/internal module registry that product and platform teams can consume in a self-service manner.
- Improve and help unify the observability stack (Grafana, Prometheus, and Alertmanager) by fixing metric accuracy issues, building meaningful dashboards, and defining SLOs/alerting that reflect real platform and pipeline health.
- Work across Datadog and VictoriaLogs/VictoriaMetrics to reduce tool sprawl and help define a coherent strategy for where metrics, logs, and events should live.
- Provide platform-level telemetry (runner utilization, build queue times, artifact scan results, deployment health) that gives engineering teams and leadership a single, trustworthy view of pipeline and platform performance.
- Evaluate and help operate Crossplane as a control-plane layer for self-service, Kubernetes-native infrastructure provisioning, complementing the existing Terraform/Terragrunt IaC estate.
- Contribute to a developer portal / internal catalogue strategy such as Backstage, Cortex, or Port so engineers have a single place to discover services, ownership, docs, and golden-path templates.
- Implement and maintain policy-as-code guardrails using Kyverno and/or Open Policy Agent (OPA) across the Kubernetes and CI/CD estate such as image provenance, resource limits, and security baselines.
- Support Knative-based serverless/event-driven workloads on Kubernetes where teams need scale-to-zero or request-driven compute.
- Roll out OpenTelemetry instrumentation and pipelines to standardise traces, metrics, and logs across services, feeding the Grafana/Prometheus/Datadog/VictoriaLogs stack with consistent, correlated telemetry.
- Act as the platform's embedded point of contact for one or more product engineering teams, understanding their day-to-day friction, prioritising platform work accordingly, and closing the loop on delivery.
- Build self-service tooling, templates, and documentation (golden paths) so engineers can provision runners, publish artifacts, and deploy without needing deep platform expertise.
- Clearly document ownership boundaries between platform and product teams such as base images versus application extensions and help engineering teams operate confidently within them.
- Contribute to the platform roadmap, bringing a developer-experience lens to prioritisation and measuring success in terms of engineer-facing outcomes such as build time, queue time, and self-service adoption, not just infrastructure uptime.
What you bring
- 5+ years in a Platform Engineering, DevOps, SRE, or infrastructure engineering role, ideally supporting product engineering teams directly.
- Hands-on experience with GitHub Actions, including self-hosted runner architectures (Actions Runner Controller / Kubernetes-based Linux runners, self-hosted macOS runners) and provisioning them via Terraform.
- Practical knowledge of the JFrog Platform (Artifactory, Xray, and ideally Curation) for artifact management and dependency security.
- Familiarity with container registries beyond a single vendor (GHCR/GitHub Packages) and Helm chart repositories such as ChartMuseum on object storage (S3).
- Experience with GitOps continuous delivery using ArgoCD, and ideally Argo Rollouts for progressive delivery (canary/blue-green) across multiple clusters/environments.
- Strong Kubernetes configuration management skills with Helm and Kustomize.
- Solid Infrastructure-as-Code experience with Terraform and Terragrunt, including designing and consuming shared/reusable modules.
- Experience with Crossplane (or a comparable Kubernetes-native control-plane approach) for building self-service infrastructure APIs, alongside deep Terraform proficiency for the underlying IaC.
- Experience building or operating an internal developer portal/software catalogue such as Backstage, Cortex, or Port, including modelling service ownership and scorecards.
- Hands-on experience with policy-as-code enforcement in Kubernetes using Kyverno and/or Open Policy Agent (OPA / Gatekeeper), such as image provenance, resource limits, and security baselines.
- Familiarity with Knative or similar Kubernetes-native serverless/eventing frameworks for scale-to-zero or request-driven workloads.
- Experience building, hardening, and optimizing container images (Dockerfile best practices, minimal/hardened base images such as Docker Hardened Images or Chainguard).
- Working knowledge of an observability stack: Grafana, Prometheus, and Alertmanager, plus exposure to Datadog and/or VictoriaLogs/VictoriaMetrics, and practical experience instrumenting services and pipelines with OpenTelemetry (traces, metrics, logs).
- Comfortable in Linux/Unix environments, with solid scripting ability such as Bash, Python, or Go and strong Git fundamentals.
- Genuine product mindset toward internal platforms: you think in terms of the engineer as a customer and seek out and act on their feedback.
- Strong cross-functional collaborator, comfortable embedding with a product engineering team and building trust with people who don't share your infrastructure background.
- Clear written and verbal communicator, able to explain infrastructure concepts such as Kubernetes, runner sizing, and build performance to engineers without a platform background.
- Pragmatic and cost-conscious: able to balance reliability, security, developer speed, and infrastructure cost, and to make and explain trade-offs rather than defaulting to "more resources."
- Ownership mindset with strong personal accountability; comfortable working autonomously and driving initiatives from discovery through to rollout.
- Curious and continuously improving: proactively investigates root causes such as inconsistent metrics and flaky runners rather than just resolving symptoms.
- Comfortable with ambiguity and evolving priorities, and able to sequence and negotiate scope in a fast-moving, PI-based planning environment.
- Empathetic and collaborative when defining ownership boundaries between platform and product teams, favouring clarity and shared documentation over friction.
Nice to have
- AWS cloud experience (compute, storage/S3, networking fundamentals).
- Experience supporting mobile/device-testing CI such as Android emulator/KVM requirements and iOS simulators in a self-hosted runner context.
- Experience with developing platform API and CLI for developers to consume blueprints and patterns using either Kratix or Crossplane tooling.
- Experience with large Kubernetes cluster fleet automation from provisioning to upgrade to decommission.
- Experience operating in a large monorepo, including build-graph/dependency-aware CI triggering.
- Prior experience defining or operating SLOs/SLAs and error budgets for internal platform services.
What we offer
- B2B contract: 1,200-1,400 PLN net per day.
- Employment contract: 19,000-22,000 PLN gross per month.
- Choice of remote work or on-site in Łódź, Poland.
- Agile and friendly atmosphere with full respect for diversity.
About Incubly
Incubly supports tech companies and startups in scaling their teams quickly and with high quality. The role is embedded with a French-based leader in security and infrastructure solutions for cryptocurrencies and blockchain applications, with over 400 professionals developing products and services to safeguard cryptocurrency assets, including worldwide leading hardware wallets.
