<p><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt">At Mad Monkey, we’re not just building hostels, we’re building a global community of travelers, dreamers, and changemakers. Our mission is to create life changing experiences through adventure, connection, and positive impact. With hostels across Southeast Asia and Australia we’re one of the fastest growing hostel brands in the world - and we’re just getting started.</span></p>
<p><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt">We believe in meaningful travel, social experiences, and doing good wherever we go. Sound like your vibe? Keep reading.</span></p>
<p><br></p>
<p><span style="font-size: 12pt"><span style="font-weight: bold">The Role</span></span></p>
<p><span style="color: rgb(67, 67, 67); font-family: Arial, sans-serif; font-size: 10pt">You will be the primary owner of Mad Monkey's cloud infrastructure, deployment pipelines, and platform security. You will work closely with the Head of Technology and the engineering team to harden our current environment, drive the platform to properly isolated network architecture, and build the operational foundation that the product team builds on top of.</span></p>
<p><span style="color: rgb(67, 67, 67); font-family: Arial, sans-serif; font-size: 10pt">In your first 30 days, you will:</span></p>
<ul>
<li><span style="color: rgb(67, 67, 67); font-family: Arial, sans-serif; font-size: 10pt">Audit and remediate the most critical open infrastructure security items</span></li>
<li><span style="color: rgb(67, 67, 67); font-family: Arial, sans-serif; font-size: 10pt">Establish visibility into all running workloads across Kubernetes, DigitalOcean droplets, and Cloudflare</span></li>
<li><span style="color: rgb(67, 67, 67); font-family: Arial, sans-serif; font-size: 10pt">Get familiar with our CI/CD pipelines, deployment processes, and environment configuration</span><br></li>
</ul>
<p><br></p>
<p><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt; font-weight: bold">The role can be based in any location within South East Asia.</span></p>
<p><br></p>
<p><span style="color: rgb(67, 67, 67); font-family: Arial, sans-serif; font-size: 14pt; font-weight: bold">Key Responsibilities</span></p>
<p><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 12pt; font-weight: bold">Infrastructure & Cloud</span></p>
<ul>
<li><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 10pt">Own and operate all DigitalOcean infrastructure: Kubernetes cluster (3-node SGP1), managed droplets, VPC configuration, firewall rules, and databases</span></li>
<li><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 10pt">Manage Cloudflare configuration across all zones: DNS, proxying, Zero Trust access, SSL/TLS, WAF rules, and Workers</span></li>
<li><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 10pt">Drive the VPC migration to move internal services off public network exposure</span></li>
<li><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 10pt">Maintain and improve infrastructure-as-code practices (Terraform or equivalent)</span></li>
<li><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 10pt">Manage all environment secrets, API key rotation schedules, and credential hygiene across services</span></li>
</ul>
<p><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 12pt; font-weight: bold">Security</span></p>
<ul>
<li><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 10pt">Own the infrastructure security posture end-to-end — firewalls, network segmentation, access control, secrets management</span></li>
<li><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 10pt">Implement and maintain Zero Trust access for internal tools (n8n, Plane, Hasura, Kubernetes dashboard)</span></li>
<li><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 10pt">Define and enforce Cloudflare security policies across all domains</span></li>
<li><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 10pt">Establish server-level monitoring and intrusion detection</span></li>
<li><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 10pt">Conduct regular reviews of open ports, service exposure, and dependency vulnerabilities</span></li>
<li><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 10pt">Own the incident response process for infrastructure-level security events</span></li>
</ul>
<p><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 12pt; font-weight: bold">Kubernetes & Containers</span></p>
<ul>
<li><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 10pt">Manage and harden the Kubernetes cluster: RBAC, network policies, pod security standards, ingress configuration</span></li>
<li><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 10pt">Build and maintain Docker images and container registries</span></li>
<li><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 10pt">Define resource requests/limits, HPA policies, and cluster autoscaling</span></li>
<li><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 10pt">Implement proper secrets management within the cluster (Sealed Secrets, External Secrets, or equivalent)</span></li>
</ul>
<p><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 12pt; font-weight: bold">CI/CD & Developer Experience</span></p>
<ul>
<li><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 10pt">Own and improve CI/CD pipelines for all services (backend API, Next.js web app, mobile app builds)</span></li>
<li><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 10pt">Reduce deployment friction for the engineering team while maintaining gates for security and quality</span></li>
<li><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 10pt">Manage environment promotion across development, staging, and production</span></li>
</ul>
<p><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 12pt; font-weight: bold">Reliability & Observability</span></p>
<ul>
<li><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 10pt">Implement and maintain monitoring, alerting, and log aggregation across all services</span></li>
<li><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 10pt">Define and report on uptime and error-rate metrics for critical services</span></li>
<li><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 10pt">Own backup schedules and disaster recovery procedures for databases and stateful services</span></li>
<li><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 10pt">Lead post-mortems on infrastructure incidents and drive preventative improvements</span></li>
</ul>
<p><br></p>
<p><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 12pt; font-weight: bold">What We Are Looking For</span></p>
<p><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 12pt; font-weight: bold">Must Have</span></p>
<ul>
<li><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 10pt">3-6 years of hands-on cloud infrastructure experience in a production environment</span></li>
<li><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 10pt">Strong Kubernetes experience: cluster administration, RBAC, network policies, ingress, Helm</span></li>
<li><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 10pt">Proven cloud security mindset: firewall rules, VPC design, secrets management, least-privilege access</span></li>
<li><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 10pt">Experience with DigitalOcean, AWS, GCP or equivalent cloud providers</span></li>
<li><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 10pt">Cloudflare configuration: DNS, proxying, SSL/TLS, WAF, Zero Trust Access</span></li>
<li><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 10pt">Comfortable working across Linux servers, shell scripting, and infrastructure automation</span></li>
<li><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 10pt">Experience managing CI/CD pipelines (GitHub Actions, GitLab CI, or equivalent)</span></li>
</ul>
<p><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 12pt; font-weight: bold">Strongly Preferred</span></p>
<ul>
<li><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 10pt">Infrastructure as Code experience (Terraform, Pulumi, or equivalent)</span></li>
<li><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 10pt">Experience hardening Kubernetes clusters in production environments</span></li>
<li><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 10pt">Familiarity with VPN/Zero Trust tooling (Cloudflare Access, Tailscale, WireGuard)</span></li>
<li><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 10pt">Monitoring and observability stack experience (Grafana, Prometheus, Wazuh, or equivalent)</span></li>
<li><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 10pt">Understanding of PostgreSQL administration, backup strategy, and connection pooling</span></li>
<li><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 10pt">Experience with RabbitMQ or other message brokers in production</span></li>
<li><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 10pt">Knowledge of container security scanning and supply chain hardening</span></li>
</ul>
<p><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 12pt; font-weight: bold">Nice to Have</span></p>
<ul>
<li><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 10pt">Experience in a startup or small engineering team where you were the primary infrastructure owner</span></li>
<li><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 10pt">Familiarity with n8n or similar workflow automation platforms</span></li>
<li><span style="color: rgb(0, 0, 0); font-family: Arial, sans-serif; font-size: 10pt">Security certifications (CKS, AWS Security Specialty, or equivalent)</span></li>
</ul>
<p><br></p>
<p><span style="font-size: 12pt"><span style="font-weight: bold">Why You’ll Love It Here</span></span></p>
<ul>
<li><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt">Work with an international team of passionate, purpose-driven people.</span></li>
<li><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt">Be part of a fast-growing global travel brand with a social impact mission.</span></li>
<li><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt">Enjoy travel perks across our hostels and the chance to see your ideas come to life.</span></li>
<li><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt">Flexible work setup and a culture that values creativity, adventure, and community.</span></li>
</ul>