SaaS Implementation Engineer (Contract)
RBA, Inc. · United States · 1 wk ago
RemoteRemoteConsultingFull-time
About the role
We are seeking a SaaS Implementation Engineer to lead the hands-on implementation of an AI platform as it transitions from an internal Kubernetes environment to a customer-facing SaaS offering hosted in Microsoft Azure. In this role, you will work within an established architecture to build the infrastructure, automation, application capabilities, and provisioning processes required to support a hybrid tenancy model. You will be responsible for day-to-day technical execution and will work independently with architectural guidance and project oversight.
Responsibilities
- Azure Platform Implementation: Re-host existing AI platform components from an internal AKS environment into a dedicated Azure subscription, including shared and customer-dedicated services.
- Infrastructure as Code: Design reusable Terraform modules that provision complete, isolated customer environments, including AKS namespaces, databases, storage, Event Hub resources, private DNS, networking, and API routing.
- Tenant Provisioning Automation: Build repeatable, parameterized workflows that automate the creation and validation of new customer environments using Azure DevOps and existing automation tooling.
- Multi-Tenant Architecture: Implement shared-instance tenancy capabilities, including tenant context propagation, Row-Level Security (RLS), tenant-scoped data access, and API Management tenant resolution.
- Application Modernization: Understand and modify an existing multi-component application—including APIs, SDKs, backend services, and event-driven workflows—to operate securely within the new SaaS architecture.
- Event Streaming: Migrate event-driven integrations from Kafka to Azure Event Hubs using its Kafka-compatible interface while minimizing changes to existing producers and consumers.
- SDK Development: Enhance .NET and Python SDKs to support tenant-aware endpoints, authentication, and routing across shared and dedicated services.
- Identity & Security: Integrate a customer-facing identity provider and implement secure authentication and authorization patterns appropriate for an externally accessible SaaS platform.
- Observability: Establish monitoring and telemetry using Azure Log Analytics and Application Insights, including tenant-aware logging and diagnostics.
- Validation & Documentation: Validate customer environments end-to-end for connectivity, authentication, SDK access, and data isolation, and create clear provisioning and onboarding documentation that enables other engineers to operate the process independently.
Requirements
- Terraform Expertise: Strong hands-on experience designing reusable Terraform modules, managing state across environments, and implementing parameterized infrastructure provisioning patterns.
- Microsoft Azure: Deep experience with Azure services including AKS, Azure SQL and/or PostgreSQL Flexible Server, Storage Accounts, Event Hubs, API Management, Key Vault, Managed Identities/Workload Identity, VNets, private endpoints, and private DNS.
- Software Engineering: Strong enterprise application development experience with the ability to understand and safely modify complex, distributed applications—not solely infrastructure or DevOps experience.
- SaaS Architecture: Experience building or operating SaaS platforms using multi-tenant, dedicated-tenant, or hybrid tenancy models.
- Tenant Isolation: Hands-on experience implementing tenant-aware application patterns such as tenant context middleware, Row-Level Security, and tenant-scoped data access.
- Application Development: Proficiency with .NET and Python and experience working with APIs, SDKs, backend services, and distributed systems.
- Event-Driven Systems: Experience designing or supporting event-driven architectures using Kafka or Kafka-compatible messaging platforms.
- CI/CD & Automation: Strong experience building automated CI/CD and infrastructure provisioning workflows; Azure DevOps experience is preferred.
- Identity & Access Management: Experience integrating external identity providers such as Okta, Microsoft Entra External ID, Auth0, Clerk, or similar customer identity platforms.
- Independent Delivery: Ability to take architectural direction and independently drive implementation, technical decisions, troubleshooting, and delivery.
- Technical Communication: Strong written communication skills with the ability to produce implementation and operational documentation that other engineers can follow independently.
Nice to Have
- Experience implementing customer provisioning or “infrastructure-per-tenant” patterns for SaaS platforms.
- Hands-on experience with Okta Customer Identity, Microsoft Entra External ID, or Clerk.
- Experience with Azure Front Door, Application Gateway, and Web Application Firewall (WAF) for SaaS ingress.
- Experience migrating Kafka workloads to Azure Event Hubs.
- Familiarity with AI platforms, AI agent orchestration, agent registries, LLM routing, or related concepts.
- Experience bringing an existing application and its deployment automation into Azure for the first time.