Jobs · Consulting

SaaS Implementation Engineer (Contract)

RBA, Inc. · United States · 1 wk ago
RemoteRemoteConsultingFull-time

About the role

We are seeking a SaaS Implementation Engineer to lead the hands-on implementation of an AI platform as it transitions from an internal Kubernetes environment to a customer-facing SaaS offering hosted in Microsoft Azure. In this role, you will work within an established architecture to build the infrastructure, automation, application capabilities, and provisioning processes required to support a hybrid tenancy model. You will be responsible for day-to-day technical execution and will work independently with architectural guidance and project oversight.

Responsibilities

  • Azure Platform Implementation: Re-host existing AI platform components from an internal AKS environment into a dedicated Azure subscription, including shared and customer-dedicated services.
  • Infrastructure as Code: Design reusable Terraform modules that provision complete, isolated customer environments, including AKS namespaces, databases, storage, Event Hub resources, private DNS, networking, and API routing.
  • Tenant Provisioning Automation: Build repeatable, parameterized workflows that automate the creation and validation of new customer environments using Azure DevOps and existing automation tooling.
  • Multi-Tenant Architecture: Implement shared-instance tenancy capabilities, including tenant context propagation, Row-Level Security (RLS), tenant-scoped data access, and API Management tenant resolution.
  • Application Modernization: Understand and modify an existing multi-component application—including APIs, SDKs, backend services, and event-driven workflows—to operate securely within the new SaaS architecture.
  • Event Streaming: Migrate event-driven integrations from Kafka to Azure Event Hubs using its Kafka-compatible interface while minimizing changes to existing producers and consumers.
  • SDK Development: Enhance .NET and Python SDKs to support tenant-aware endpoints, authentication, and routing across shared and dedicated services.
  • Identity & Security: Integrate a customer-facing identity provider and implement secure authentication and authorization patterns appropriate for an externally accessible SaaS platform.
  • Observability: Establish monitoring and telemetry using Azure Log Analytics and Application Insights, including tenant-aware logging and diagnostics.
  • Validation & Documentation: Validate customer environments end-to-end for connectivity, authentication, SDK access, and data isolation, and create clear provisioning and onboarding documentation that enables other engineers to operate the process independently.

Requirements

  • Terraform Expertise: Strong hands-on experience designing reusable Terraform modules, managing state across environments, and implementing parameterized infrastructure provisioning patterns.
  • Microsoft Azure: Deep experience with Azure services including AKS, Azure SQL and/or PostgreSQL Flexible Server, Storage Accounts, Event Hubs, API Management, Key Vault, Managed Identities/Workload Identity, VNets, private endpoints, and private DNS.
  • Software Engineering: Strong enterprise application development experience with the ability to understand and safely modify complex, distributed applications—not solely infrastructure or DevOps experience.
  • SaaS Architecture: Experience building or operating SaaS platforms using multi-tenant, dedicated-tenant, or hybrid tenancy models.
  • Tenant Isolation: Hands-on experience implementing tenant-aware application patterns such as tenant context middleware, Row-Level Security, and tenant-scoped data access.
  • Application Development: Proficiency with .NET and Python and experience working with APIs, SDKs, backend services, and distributed systems.
  • Event-Driven Systems: Experience designing or supporting event-driven architectures using Kafka or Kafka-compatible messaging platforms.
  • CI/CD & Automation: Strong experience building automated CI/CD and infrastructure provisioning workflows; Azure DevOps experience is preferred.
  • Identity & Access Management: Experience integrating external identity providers such as Okta, Microsoft Entra External ID, Auth0, Clerk, or similar customer identity platforms.
  • Independent Delivery: Ability to take architectural direction and independently drive implementation, technical decisions, troubleshooting, and delivery.
  • Technical Communication: Strong written communication skills with the ability to produce implementation and operational documentation that other engineers can follow independently.

Nice to Have

  • Experience implementing customer provisioning or “infrastructure-per-tenant” patterns for SaaS platforms.
  • Hands-on experience with Okta Customer Identity, Microsoft Entra External ID, or Clerk.
  • Experience with Azure Front Door, Application Gateway, and Web Application Firewall (WAF) for SaaS ingress.
  • Experience migrating Kafka workloads to Azure Event Hubs.
  • Familiarity with AI platforms, AI agent orchestration, agent registries, LLM routing, or related concepts.
  • Experience bringing an existing application and its deployment automation into Azure for the first time.

Similar jobs