Senior Platform Engineer

Bain & CompanyGeneral Information Job Title Senior Platform Engineer Job ID 105799 Work Areas Technology & Engineering Employment Type Permanent Full-Time Location(s) Atlanta, Boston, Chicago, Dallas, New York Description & Requirements WHAT MAKES US A GREAT PLACE TO WORKWe are proud to be consistently recognized as one of the world’s best places to work. We are currently the top ranked consulting firm on Glassdoor’s Best Places to Work list and have earned the #1 overall spot a record seven times.Extraordinary teams are at the heart of our business strategy, but these don’t happen by chance. They require intentional focus on bringing together a broad set of backgrounds, cultures, experiences, perspectives, and skills in a supportive and inclusive work environment. We hire people with exceptional talent and create an environment in which every individual can thrive professionally and personally.WHO YOU’LL WORK WITHAs the premier consulting partner for the private equity industry, Bain's PEG boasts a global practice that is over three times larger than any competitor. Our network of over 1,000 professionals supports private equity and institutional investor clients through every stage of the investment life cycle, from deal generation and due diligence to portfolio value creation and exit planning.Bain & Company is developing a suite of cutting-edge data and software solutions designed to revolutionize how the private equity industry uses data for investment insights and decision-making. The PEG Innovation team's mission is to create analytical solutions for Bain clients, teams, and the broader institutional investor space using proprietary software and data products. This includes the development, commercialization, and daily management of Bain's proprietary datasets, data, and software businesses.WHERE YOU’LL FIT WITHIN THE TEAMSenior Platform Engineers design and build the shared services that every product and data squad depends on: Auth, RBAC, Session Management, Audit, Notifications, File handling, Search, and more. Our platform runs on Microsoft Azure and Azure Kubernetes Service (AKS). You own your services end-to-end: design, build, test, deploy, monitor, and operate them. You set the standard for how platform services are built and contribute to the engineering standards and conventions that govern the broader estate. You collaborate closely with Security and Infrastructure to ensure services are secure-by-default, observable from day one, and operable under production on-call expectations.WHAT YOU'LL DOCore Platform Service Development, Deployment, and Operations (80%) Design, build, test, deploy, and operate core platform services to production quality standards (Auth, RBAC, Session, Audit, Notifications, File, Search).Own service APIs and contracts end-to-end: versioning, backwards compatibility, and consumer impact management across product squads.Write and maintain Postgres schemas and Alembic migrations using the expand/contract pattern; never ship a breaking schema change without a backwards-compatible transition.Implement and enforce authentication and authorisation patterns: JWT, refresh token rotation, RBAC, SAML/OIDC, and service-to-service auth where required.Design and operate Redis-backed patterns: caching, session storage, rate limiting, pub/sub, and distributed lock coordination where needed.Build and operate event-driven capabilities using Kafka domain events (CloudEvents envelope, schema registry integration) where platform services publish and consume.Instrument services with structured logs, distributed tracing, and Prometheus metrics from day one using OpenTelemetry and FastAPI instrumentation.Write and maintain Helm charts for owned services; contribute to Kubernetes manifests in the platform-infra repository (health checks, resource limits, HPA readiness).Participate in on-call rotation for platform incidents; drive incident response to resolution and maintain runbooks for owned services.Other (20%)Set and enforce engineering standards for platform service development: testing, observability, security, reliability, and operational hygiene.Conduct thorough code reviews; enforce standards on PRs and raise the bar for production practices across the platform estate.Mentor mid-level and junior platform engineers through pairing, design guidance, and ongoing review feedback.Use AI coding assistants to accelerate service scaffolding, API/router generation, migration drafts, and test creation; review all generated code against production and security standards before committing.Use LLMs to generate first-draft documentation (runbooks, service docs, API notes) and operational checklists; validate and refine outputs before publishing.Collaborate with the Security Engineer on Vault integration (Vault Agent Injector) and/or Azure Key Vault, dynamic secrets usage, policy scoping, mTLS policy, and software supply chain security requirements.ABOUT YOUBachelor’s degree in Computer Science, Engineering, Information Systems, or a related field (or equivalent practical experience).6+ years of experience building and operating backend services, APIs, or platform components in production environments, including on-call responsibility.Demonstrated experience owning production backend services end-to-end (design, build, test, deploy, monitor, and operate), including on-call operational responsibility.Production experience building and operating REST and event-driven microservices at scale in a Kubernetes environment.Experience designing and operating data stores in Postgres, including schema migration practices, query optimisation, and performance tuning.Experience implementing authentication and authorization systems (JWT, refresh token rotation, RBAC, SAML/OIDC) in production environments.Demonstrated ability to mentor other engineers and raise engineering standards through code review and shared conventions.Backend/Platform EngineeringStrong Python proficiency: FastAPI, Pydantic v2, SQLAlchemy 2.0 async, Alembic, pytest, Ruff, mypy (strict).Production microservices: REST APIs, event-driven patterns, idempotency, retries, backwards-compatible versioning, and consumer contract discipline.PostgreSQL: query plan analysis, indexing strategies, partitioning approaches, and schema evolution patterns for high-availability systems.Redis: caching strategies, session storage, pub/sub, and rate limiting patterns; understands operational trade-offs and failure modes.Apache Kafka: producing/consuming domain events, CloudEvents envelope conventions, schema registry integration, and consumer group semantics.Docker: multi-stage builds, non-root containers, image scanning (e.g., Trivy), and secure base-image practices.Kubernetes: Helm charts, pod lifecycle, probes/health checks, resource requests/limits, and HPA concepts; comfortable operating services on-cluster.Observability: OpenTelemetry instrumentation, structured logging (structlog), distributed tracing, and Prometheus metrics for FastAPI services; experience with Azure Monitor a plus.Secrets and security: familiarity with HashiCorp Vault (Vault Agent Injector, dynamic secrets, policy scoping) and/or Azure Key Vault, and secure service-to-service patterns.Generative AI and agentic systemsUses AI coding assistants (Cursor, GitHub Copilot, or equivalent) to accelerate feature development and reduce repetitive boilerplate; reviews all generated code against production and security standards before committing.Uses agents to generate first-draft Pydantic schemas, SQLAlchemy models, and FastAPI router skeletons; refines outputs to match domain conventions and security requirements.Uses LLM assistance to draft unit and integration test cases; validates coverage gaps and supplements with manually authored tests.Understands how platform services (Auth, RBAC, Audit) interact with the Agent Gateway and what security constraints (permissions, auditability, data minimisation) that interaction requires.GeneralTreats every service as a production system from the first commit: tests, observability, documentation, and runbooks are not optional.Communicates blockers early and escalates appropriately; does not quietly struggle for days before raising a risk.Uses AI tooling to move faster, but applies critical judgement and rigorous review to all generated code and documentation before it enters the codebase.Keeps runbooks and service documentation current as services evolve; treats operability as part of delivery.This role follows a hybrid model, requiring in-office presence at least 1 day per weekU.S. COMPENSATION INFORMATIONCompensation for this role includes base salary, annual discretionary performance bonus, 401(k) plan with an annual employer contribution based on years of service and Bain’s best in class benefits package (details listed below).Some local governments in the United States require a good-faith, reasonable salary range be included in job postings for open roles. The estimated annualized compensation for this role is as follows:In Atlanta, the good-faith, reasonable annualized full-time salary range for this role is between $140,875 - $153,750In Boston, the good-faith, reasonable annualized full-time salary range for this role is between $162,000 - $176,750In Dallas, the good-faith, reasonable annualized full-time salary range for this role is between $147,625 - $161,250In Chicago, the good-faith, reasonable annualized full-time salary range for this role is between $155,125 - $169,250In New York, the good-faith, reasonable annualized full-time salary range for this role is between $176,250 - $192,250Placement within these ranges will vary based on factors such as experience, education, training, and skill level.Compensation also includes a discretionary annual performance bonus, 401(k) plan with employer contribution, and Bain’s best-in-class benefits—including full premium coverage for medical, dental, and vision, generous paid time off, and more.Annual discretionary performance bonus This role may also be eligible for other elements of discretionary compensation4.5% 401(k) company contribution, which increases after 3 years of service and is 100% vested upon start dateBain & Company's comprehensive benefits and wellness program is designed to help employees achieve personal independence, protection and stability in the areas most important to you and your family.Bain pays 100% individual employee premiums for medical, dental and vision programs, offering one of the most comprehensive medical plans for employees without impacting your paycheckGenerous paid time off, including parental leave, sick leave and paid holidaysFully vested 401(k) company contributionPaid Life and Long-Term Disability insurance Go back Apply Share this job: LinkedIn X Emailfull timeSenior
$140.9K–192.3KActive

Job description

General Information Job Title Senior Platform Engineer Job ID 105799 Work Areas Technology & Engineering Employment Type Permanent Full-Time Location(s) Atlanta, Boston, Chicago, Dallas, New York Description & Requirements WHAT MAKES US A GREAT PLACE TO WORKWe are proud to be consistently recognized as one of the world’s best places to work. We are currently the top ranked consulting firm on Glassdoor’s Best Places to Work list and have earned the #1 overall spot a record seven times.Extraordinary teams are at the heart of our business strategy, but these don’t happen by chance. They require intentional focus on bringing together a broad set of backgrounds, cultures, experiences, perspectives, and skills in a supportive and inclusive work environment. We hire people with exceptional talent and create an environment in which every individual can thrive professionally and personally.WHO YOU’LL WORK WITHAs the premier consulting partner for the private equity industry, Bain's PEG boasts a global practice that is over three times larger than any competitor. Our network of over 1,000 professionals supports private equity and institutional investor clients through every stage of the investment life cycle, from deal generation and due diligence to portfolio value creation and exit planning.Bain & Company is developing a suite of cutting-edge data and software solutions designed to revolutionize how the private equity industry uses data for investment insights and decision-making. The PEG Innovation team's mission is to create analytical solutions for Bain clients, teams, and the broader institutional investor space using proprietary software and data products. This includes the development, commercialization, and daily management of Bain's proprietary datasets, data, and software businesses.WHERE YOU’LL FIT WITHIN THE TEAMSenior Platform Engineers design and build the shared services that every product and data squad depends on: Auth, RBAC, Session Management, Audit, Notifications, File handling, Search, and more. Our platform runs on Microsoft Azure and Azure Kubernetes Service (AKS). You own your services end-to-end: design, build, test, deploy, monitor, and operate them. You set the standard for how platform services are built and contribute to the engineering standards and conventions that govern the broader estate. You collaborate closely with Security and Infrastructure to ensure services are secure-by-default, observable from day one, and operable under production on-call expectations.WHAT YOU'LL DOCore Platform Service Development, Deployment, and Operations (80%) Design, build, test, deploy, and operate core platform services to production quality standards (Auth, RBAC, Session, Audit, Notifications, File, Search).Own service APIs and contracts end-to-end: versioning, backwards compatibility, and consumer impact management across product squads.Write and maintain Postgres schemas and Alembic migrations using the expand/contract pattern; never ship a breaking schema change without a backwards-compatible transition.Implement and enforce authentication and authorisation patterns: JWT, refresh token rotation, RBAC, SAML/OIDC, and service-to-service auth where required.Design and operate Redis-backed patterns: caching, session storage, rate limiting, pub/sub, and distributed lock coordination where needed.Build and operate event-driven capabilities using Kafka domain events (CloudEvents envelope, schema registry integration) where platform services publish and consume.Instrument services with structured logs, distributed tracing, and Prometheus metrics from day one using OpenTelemetry and FastAPI instrumentation.Write and maintain Helm charts for owned services; contribute to Kubernetes manifests in the platform-infra repository (health checks, resource limits, HPA readiness).Participate in on-call rotation for platform incidents; drive incident response to resolution and maintain runbooks for owned services.Other (20%)Set and enforce engineering standards for platform service development: testing, observability, security, reliability, and operational hygiene.Conduct thorough code reviews; enforce standards on PRs and raise the bar for production practices across the platform estate.Mentor mid-level and junior platform engineers through pairing, design guidance, and ongoing review feedback.Use AI coding assistants to accelerate service scaffolding, API/router generation, migration drafts, and test creation; review all generated code against production and security standards before committing.Use LLMs to generate first-draft documentation (runbooks, service docs, API notes) and operational checklists; validate and refine outputs before publishing.Collaborate with the Security Engineer on Vault integration (Vault Agent Injector) and/or Azure Key Vault, dynamic secrets usage, policy scoping, mTLS policy, and software supply chain security requirements.ABOUT YOUBachelor’s degree in Computer Science, Engineering, Information Systems, or a related field (or equivalent practical experience).6+ years of experience building and operating backend services, APIs, or platform components in production environments, including on-call responsibility.Demonstrated experience owning production backend services end-to-end (design, build, test, deploy, monitor, and operate), including on-call operational responsibility.Production experience building and operating REST and event-driven microservices at scale in a Kubernetes environment.Experience designing and operating data stores in Postgres, including schema migration practices, query optimisation, and performance tuning.Experience implementing authentication and authorization systems (JWT, refresh token rotation, RBAC, SAML/OIDC) in production environments.Demonstrated ability to mentor other engineers and raise engineering standards through code review and shared conventions.Backend/Platform EngineeringStrong Python proficiency: FastAPI, Pydantic v2, SQLAlchemy 2.0 async, Alembic, pytest, Ruff, mypy (strict).Production microservices: REST APIs, event-driven patterns, idempotency, retries, backwards-compatible versioning, and consumer contract discipline.PostgreSQL: query plan analysis, indexing strategies, partitioning approaches, and schema evolution patterns for high-availability systems.Redis: caching strategies, session storage, pub/sub, and rate limiting patterns; understands operational trade-offs and failure modes.Apache Kafka: producing/consuming domain events, CloudEvents envelope conventions, schema registry integration, and consumer group semantics.Docker: multi-stage builds, non-root containers, image scanning (e.g., Trivy), and secure base-image practices.Kubernetes: Helm charts, pod lifecycle, probes/health checks, resource requests/limits, and HPA concepts; comfortable operating services on-cluster.Observability: OpenTelemetry instrumentation, structured logging (structlog), distributed tracing, and Prometheus metrics for FastAPI services; experience with Azure Monitor a plus.Secrets and security: familiarity with HashiCorp Vault (Vault Agent Injector, dynamic secrets, policy scoping) and/or Azure Key Vault, and secure service-to-service patterns.Generative AI and agentic systemsUses AI coding assistants (Cursor, GitHub Copilot, or equivalent) to accelerate feature development and reduce repetitive boilerplate; reviews all generated code against production and security standards before committing.Uses agents to generate first-draft Pydantic schemas, SQLAlchemy models, and FastAPI router skeletons; refines outputs to match domain conventions and security requirements.Uses LLM assistance to draft unit and integration test cases; validates coverage gaps and supplements with manually authored tests.Understands how platform services (Auth, RBAC, Audit) interact with the Agent Gateway and what security constraints (permissions, auditability, data minimisation) that interaction requires.GeneralTreats every service as a production system from the first commit: tests, observability, documentation, and runbooks are not optional.Communicates blockers early and escalates appropriately; does not quietly struggle for days before raising a risk.Uses AI tooling to move faster, but applies critical judgement and rigorous review to all generated code and documentation before it enters the codebase.Keeps runbooks and service documentation current as services evolve; treats operability as part of delivery.This role follows a hybrid model, requiring in-office presence at least 1 day per weekU.S. COMPENSATION INFORMATIONCompensation for this role includes base salary, annual discretionary performance bonus, 401(k) plan with an annual employer contribution based on years of service and Bain’s best in class benefits package (details listed below).Some local governments in the United States require a good-faith, reasonable salary range be included in job postings for open roles. The estimated annualized compensation for this role is as follows:In Atlanta, the good-faith, reasonable annualized full-time salary range for this role is between $140,875 - $153,750In Boston, the good-faith, reasonable annualized full-time salary range for this role is between $162,000 - $176,750In Dallas, the good-faith, reasonable annualized full-time salary range for this role is between $147,625 - $161,250In Chicago, the good-faith, reasonable annualized full-time salary range for this role is between $155,125 - $169,250In New York, the good-faith, reasonable annualized full-time salary range for this role is between $176,250 - $192,250Placement within these ranges will vary based on factors such as experience, education, training, and skill level.Compensation also includes a discretionary annual performance bonus, 401(k) plan with employer contribution, and Bain’s best-in-class benefits—including full premium coverage for medical, dental, and vision, generous paid time off, and more.Annual discretionary performance bonus This role may also be eligible for other elements of discretionary compensation4.5% 401(k) company contribution, which increases after 3 years of service and is 100% vested upon start dateBain & Company's comprehensive benefits and wellness program is designed to help employees achieve personal independence, protection and stability in the areas most important to you and your family.Bain pays 100% individual employee premiums for medical, dental and vision programs, offering one of the most comprehensive medical plans for employees without impacting your paycheckGenerous paid time off, including parental leave, sick leave and paid holidaysFully vested 401(k) company contributionPaid Life and Long-Term Disability insurance Go backGeneral Information Job Title Senior Platform Engineer Job ID 105799 Work Areas Technology & Engineering Employment Type Permanent Full-Time Location(s) Atlanta, Boston, Chicago, Dallas, New York Description & Requirements WHAT MAKES US A GREAT PLACE TO WORKWe are proud to be consistently recognized as one of the world’s best places to work. We are currently the top ranked consulting firm on Glassdoor’s Best Places to Work list and have earned the #1 overall spot a record seven times.Extraordinary teams are at the heart of our business strategy, but these don’t happen by chance. They require intentional focus on bringing together a broad set of backgrounds, cultures, experiences, perspectives, and skills in a supportive and inclusive work environment. We hire people with exceptional talent and create an environment in which every individual can thrive professionally and personally.WHO YOU’LL WORK WITHAs the premier consulting partner for the private equity industry, Bain's PEG boasts a global practice that is over three times larger than any competitor. Our network of over 1,000 professionals supports private equity and institutional investor clients through every stage of the investment life cycle, from deal generation and due diligence to portfolio value creation and exit planning.Bain & Company is developing a suite of cutting-edge data and software solutions designed to revolutionize how the private equity industry uses data for investment insights and decision-making. The PEG Innovation team's mission is to create analytical solutions for Bain clients, teams, and the broader institutional investor space using proprietary software and data products. This includes the development, commercialization, and daily management of Bain's proprietary datasets, data, and software businesses.WHERE YOU’LL FIT WITHIN THE TEAMSenior Platform Engineers design and build the shared services that every product and data squad depends on: Auth, RBAC, Session Management, Audit, Notifications, File handling, Search, and more. Our platform runs on Microsoft Azure and Azure Kubernetes Service (AKS). You own your services end-to-end: design, build, test, deploy, monitor, and operate them. You set the standard for how platform services are built and contribute to the engineering standards and conventions that govern the broader estate. You collaborate closely with Security and Infrastructure to ensure services are secure-by-default, observable from day one, and operable under production on-call expectations.WHAT YOU'LL DOCore Platform Service Development, Deployment, and Operations (80%) Design, build, test, deploy, and operate core platform services to production quality standards (Auth, RBAC, Session, Audit, Notifications, File, Search).Own service APIs and contracts end-to-end: versioning, backwards compatibility, and consumer impact management across product squads.Write and maintain Postgres schemas and Alembic migrations using the expand/contract pattern; never ship a breaking schema change without a backwards-compatible transition.Implement and enforce authentication and authorisation patterns: JWT, refresh token rotation, RBAC, SAML/OIDC, and service-to-service auth where required.Design and operate Redis-backed patterns: caching, session storage, rate limiting, pub/sub, and distributed lock coordination where needed.Build and operate event-driven capabilities using Kafka domain events (CloudEvents envelope, schema registry integration) where platform services publish and consume.Instrument services with structured logs, distributed tracing, and Prometheus metrics from day one using OpenTelemetry and FastAPI instrumentation.Write and maintain Helm charts for owned services; contribute to Kubernetes manifests in the platform-infra repository (health checks, resource limits, HPA readiness).Participate in on-call rotation for platform incidents; drive incident response to resolution and maintain runbooks for owned services.Other (20%)Set and enforce engineering standards for platform service development: testing, observability, security, reliability, and operational hygiene.Conduct thorough code reviews; enforce standards on PRs and raise the bar for production practices across the platform estate.Mentor mid-level and junior platform engineers through pairing, design guidance, and ongoing review feedback.Use AI coding assistants to accelerate service scaffolding, API/router generation, migration drafts, and test creation; review all generated code against production and security standards before committing.Use LLMs to generate first-draft documentation (runbooks, service docs, API notes) and operational checklists; validate and refine outputs before publishing.Collaborate with the Security Engineer on Vault integration (Vault Agent Injector) and/or Azure Key Vault, dynamic secrets usage, policy scoping, mTLS policy, and software supply chain security requirements.ABOUT YOUBachelor’s degree in Computer Science, Engineering, Information Systems, or a related field (or equivalent practical experience).6+ years of experience building and operating backend services, APIs, or platform components in production environments, including on-call responsibility.Demonstrated experience owning production backend services end-to-end (design, build, test, deploy, monitor, and operate), including on-call operational responsibility.Production experience building and operating REST and event-driven microservices at scale in a Kubernetes environment.Experience designing and operating data stores in Postgres, including schema migration practices, query optimisation, and performance tuning.Experience implementing authentication and authorization systems (JWT, refresh token rotation, RBAC, SAML/OIDC) in production environments.Demonstrated ability to mentor other engineers and raise engineering standards through code review and shared conventions.Backend/Platform EngineeringStrong Python proficiency: FastAPI, Pydantic v2, SQLAlchemy 2.0 async, Alembic, pytest, Ruff, mypy (strict).Production microservices: REST APIs, event-driven patterns, idempotency, retries, backwards-compatible versioning, and consumer contract discipline.PostgreSQL: query plan analysis, indexing strategies, partitioning approaches, and schema evolution patterns for high-availability systems.Redis: caching strategies, session storage, pub/sub, and rate limiting patterns; understands operational trade-offs and failure modes.Apache Kafka: producing/consuming domain events, CloudEvents envelope conventions, schema registry integration, and consumer group semantics.Docker: multi-stage builds, non-root containers, image scanning (e.g., Trivy), and secure base-image practices.Kubernetes: Helm charts, pod lifecycle, probes/health checks, resource requests/limits, and HPA concepts; comfortable operating services on-cluster.Observability: OpenTelemetry instrumentation, structured logging (structlog), distributed tracing, and Prometheus metrics for FastAPI services; experience with Azure Monitor a plus.Secrets and security: familiarity with HashiCorp Vault (Vault Agent Injector, dynamic secrets, policy scoping) and/or Azure Key Vault, and secure service-to-service patterns.Generative AI and agentic systemsUses AI coding assistants (Cursor, GitHub Copilot, or equivalent) to accelerate feature development and reduce repetitive boilerplate; reviews all generated code against production and security standards before committing.Uses agents to generate first-draft Pydantic schemas, SQLAlchemy models, and FastAPI router skeletons; refines outputs to match domain conventions and security requirements.Uses LLM assistance to draft unit and integration test cases; validates coverage gaps and supplements with manually authored tests.Understands how platform services (Auth, RBAC, Audit) interact with the Agent Gateway and what security constraints (permissions, auditability, data minimisation) that interaction requires.GeneralTreats every service as a production system from the first commit: tests, observability, documentation, and runbooks are not optional.Communicates blockers early and escalates appropriately; does not quietly struggle for days before raising a risk.Uses AI tooling to move faster, but applies critical judgement and rigorous review to all generated code and documentation before it enters the codebase.Keeps runbooks and service documentation current as services evolve; treats operability as part of delivery.This role follows a hybrid model, requiring in-office presence at least 1 day per weekU.S. COMPENSATION INFORMATIONCompensation for this role includes base salary, annual discretionary performance bonus, 401(k) plan with an annual employer contribution based on years of service and Bain’s best in class benefits package (details listed below).Some local governments in the United States require a good-faith, reasonable salary range be included in job postings for open roles. The estimated annualized compensation for this role is as follows:In Atlanta, the good-faith, reasonable annualized full-time salary range for this role is between $140,875 - $153,750In Boston, the good-faith, reasonable annualized full-time salary range for this role is between $162,000 - $176,750In Dallas, the good-faith, reasonable annualized full-time salary range for this role is between $147,625 - $161,250In Chicago, the good-faith, reasonable annualized full-time salary range for this role is between $155,125 - $169,250In New York, the good-faith, reasonable annualized full-time salary range for this role is between $176,250 - $192,250Placement within these ranges will vary based on factors such as experience, education, training, and skill level.Compensation also includes a discretionary annual performance bonus, 401(k) plan with employer contribution, and Bain’s best-in-class benefits—including full premium coverage for medical, dental, and vision, generous paid time off, and more.Annual discretionary performance bonus This role may also be eligible for other elements of discretionary compensation4.5% 401(k) company contribution, which increases after 3 years of service and is 100% vested upon start dateBain & Company's comprehensive benefits and wellness program is designed to help employees achieve personal independence, protection and stability in the areas most important to you and your family.Bain pays 100% individual employee premiums for medical, dental and vision programs, offering one of the most comprehensive medical plans for employees without impacting your paycheckGenerous paid time off, including parental leave, sick leave and paid holidaysFully vested 401(k) company contributionPaid Life and Long-Term Disability insuranceGeneral InformationGeneral Information

General Information

Job Title Senior Platform Engineer Job ID 105799 Work Areas Technology & Engineering Employment Type Permanent Full-Time Location(s) Atlanta, Boston, Chicago, Dallas, New YorkJob Title Senior Platform Engineer Job ID 105799 Work Areas Technology & Engineering Employment Type Permanent Full-Time Location(s) Atlanta, Boston, Chicago, Dallas, New YorkJob Title Senior Platform EngineerJob TitleSenior Platform EngineerJob ID 105799Job ID105799Work Areas Technology & EngineeringWork AreasTechnology & EngineeringEmployment Type Permanent Full-TimeEmployment TypePermanent Full-TimeLocation(s) Atlanta, Boston, Chicago, Dallas, New YorkLocation(s)Atlanta, Boston, Chicago, Dallas, New YorkDescription & RequirementsDescription & Requirements

Description & Requirements

WHAT MAKES US A GREAT PLACE TO WORKWe are proud to be consistently recognized as one of the world’s best places to work. We are currently the top ranked consulting firm on Glassdoor’s Best Places to Work list and have earned the #1 overall spot a record seven times.Extraordinary teams are at the heart of our business strategy, but these don’t happen by chance. They require intentional focus on bringing together a broad set of backgrounds, cultures, experiences, perspectives, and skills in a supportive and inclusive work environment. We hire people with exceptional talent and create an environment in which every individual can thrive professionally and personally.WHO YOU’LL WORK WITHAs the premier consulting partner for the private equity industry, Bain's PEG boasts a global practice that is over three times larger than any competitor. Our network of over 1,000 professionals supports private equity and institutional investor clients through every stage of the investment life cycle, from deal generation and due diligence to portfolio value creation and exit planning.Bain & Company is developing a suite of cutting-edge data and software solutions designed to revolutionize how the private equity industry uses data for investment insights and decision-making. The PEG Innovation team's mission is to create analytical solutions for Bain clients, teams, and the broader institutional investor space using proprietary software and data products. This includes the development, commercialization, and daily management of Bain's proprietary datasets, data, and software businesses.WHERE YOU’LL FIT WITHIN THE TEAMSenior Platform Engineers design and build the shared services that every product and data squad depends on: Auth, RBAC, Session Management, Audit, Notifications, File handling, Search, and more. Our platform runs on Microsoft Azure and Azure Kubernetes Service (AKS). You own your services end-to-end: design, build, test, deploy, monitor, and operate them. You set the standard for how platform services are built and contribute to the engineering standards and conventions that govern the broader estate. You collaborate closely with Security and Infrastructure to ensure services are secure-by-default, observable from day one, and operable under production on-call expectations.WHAT YOU'LL DOCore Platform Service Development, Deployment, and Operations (80%) Design, build, test, deploy, and operate core platform services to production quality standards (Auth, RBAC, Session, Audit, Notifications, File, Search).Own service APIs and contracts end-to-end: versioning, backwards compatibility, and consumer impact management across product squads.Write and maintain Postgres schemas and Alembic migrations using the expand/contract pattern; never ship a breaking schema change without a backwards-compatible transition.Implement and enforce authentication and authorisation patterns: JWT, refresh token rotation, RBAC, SAML/OIDC, and service-to-service auth where required.Design and operate Redis-backed patterns: caching, session storage, rate limiting, pub/sub, and distributed lock coordination where needed.Build and operate event-driven capabilities using Kafka domain events (CloudEvents envelope, schema registry integration) where platform services publish and consume.Instrument services with structured logs, distributed tracing, and Prometheus metrics from day one using OpenTelemetry and FastAPI instrumentation.Write and maintain Helm charts for owned services; contribute to Kubernetes manifests in the platform-infra repository (health checks, resource limits, HPA readiness).Participate in on-call rotation for platform incidents; drive incident response to resolution and maintain runbooks for owned services.Other (20%)Set and enforce engineering standards for platform service development: testing, observability, security, reliability, and operational hygiene.Conduct thorough code reviews; enforce standards on PRs and raise the bar for production practices across the platform estate.Mentor mid-level and junior platform engineers through pairing, design guidance, and ongoing review feedback.Use AI coding assistants to accelerate service scaffolding, API/router generation, migration drafts, and test creation; review all generated code against production and security standards before committing.Use LLMs to generate first-draft documentation (runbooks, service docs, API notes) and operational checklists; validate and refine outputs before publishing.Collaborate with the Security Engineer on Vault integration (Vault Agent Injector) and/or Azure Key Vault, dynamic secrets usage, policy scoping, mTLS policy, and software supply chain security requirements.ABOUT YOUBachelor’s degree in Computer Science, Engineering, Information Systems, or a related field (or equivalent practical experience).6+ years of experience building and operating backend services, APIs, or platform components in production environments, including on-call responsibility.Demonstrated experience owning production backend services end-to-end (design, build, test, deploy, monitor, and operate), including on-call operational responsibility.Production experience building and operating REST and event-driven microservices at scale in a Kubernetes environment.Experience designing and operating data stores in Postgres, including schema migration practices, query optimisation, and performance tuning.Experience implementing authentication and authorization systems (JWT, refresh token rotation, RBAC, SAML/OIDC) in production environments.Demonstrated ability to mentor other engineers and raise engineering standards through code review and shared conventions.Backend/Platform EngineeringStrong Python proficiency: FastAPI, Pydantic v2, SQLAlchemy 2.0 async, Alembic, pytest, Ruff, mypy (strict).Production microservices: REST APIs, event-driven patterns, idempotency, retries, backwards-compatible versioning, and consumer contract discipline.PostgreSQL: query plan analysis, indexing strategies, partitioning approaches, and schema evolution patterns for high-availability systems.Redis: caching strategies, session storage, pub/sub, and rate limiting patterns; understands operational trade-offs and failure modes.Apache Kafka: producing/consuming domain events, CloudEvents envelope conventions, schema registry integration, and consumer group semantics.Docker: multi-stage builds, non-root containers, image scanning (e.g., Trivy), and secure base-image practices.Kubernetes: Helm charts, pod lifecycle, probes/health checks, resource requests/limits, and HPA concepts; comfortable operating services on-cluster.Observability: OpenTelemetry instrumentation, structured logging (structlog), distributed tracing, and Prometheus metrics for FastAPI services; experience with Azure Monitor a plus.Secrets and security: familiarity with HashiCorp Vault (Vault Agent Injector, dynamic secrets, policy scoping) and/or Azure Key Vault, and secure service-to-service patterns.Generative AI and agentic systemsUses AI coding assistants (Cursor, GitHub Copilot, or equivalent) to accelerate feature development and reduce repetitive boilerplate; reviews all generated code against production and security standards before committing.Uses agents to generate first-draft Pydantic schemas, SQLAlchemy models, and FastAPI router skeletons; refines outputs to match domain conventions and security requirements.Uses LLM assistance to draft unit and integration test cases; validates coverage gaps and supplements with manually authored tests.Understands how platform services (Auth, RBAC, Audit) interact with the Agent Gateway and what security constraints (permissions, auditability, data minimisation) that interaction requires.GeneralTreats every service as a production system from the first commit: tests, observability, documentation, and runbooks are not optional.Communicates blockers early and escalates appropriately; does not quietly struggle for days before raising a risk.Uses AI tooling to move faster, but applies critical judgement and rigorous review to all generated code and documentation before it enters the codebase.Keeps runbooks and service documentation current as services evolve; treats operability as part of delivery.This role follows a hybrid model, requiring in-office presence at least 1 day per weekU.S. COMPENSATION INFORMATIONCompensation for this role includes base salary, annual discretionary performance bonus, 401(k) plan with an annual employer contribution based on years of service and Bain’s best in class benefits package (details listed below).Some local governments in the United States require a good-faith, reasonable salary range be included in job postings for open roles. The estimated annualized compensation for this role is as follows:In Atlanta, the good-faith, reasonable annualized full-time salary range for this role is between $140,875 - $153,750In Boston, the good-faith, reasonable annualized full-time salary range for this role is between $162,000 - $176,750In Dallas, the good-faith, reasonable annualized full-time salary range for this role is between $147,625 - $161,250In Chicago, the good-faith, reasonable annualized full-time salary range for this role is between $155,125 - $169,250In New York, the good-faith, reasonable annualized full-time salary range for this role is between $176,250 - $192,250Placement within these ranges will vary based on factors such as experience, education, training, and skill level.Compensation also includes a discretionary annual performance bonus, 401(k) plan with employer contribution, and Bain’s best-in-class benefits—including full premium coverage for medical, dental, and vision, generous paid time off, and more.Annual discretionary performance bonus This role may also be eligible for other elements of discretionary compensation4.5% 401(k) company contribution, which increases after 3 years of service and is 100% vested upon start dateBain & Company's comprehensive benefits and wellness program is designed to help employees achieve personal independence, protection and stability in the areas most important to you and your family.Bain pays 100% individual employee premiums for medical, dental and vision programs, offering one of the most comprehensive medical plans for employees without impacting your paycheckGenerous paid time off, including parental leave, sick leave and paid holidaysFully vested 401(k) company contributionPaid Life and Long-Term Disability insuranceWHAT MAKES US A GREAT PLACE TO WORKWe are proud to be consistently recognized as one of the world’s best places to work. We are currently the top ranked consulting firm on Glassdoor’s Best Places to Work list and have earned the #1 overall spot a record seven times.Extraordinary teams are at the heart of our business strategy, but these don’t happen by chance. They require intentional focus on bringing together a broad set of backgrounds, cultures, experiences, perspectives, and skills in a supportive and inclusive work environment. We hire people with exceptional talent and create an environment in which every individual can thrive professionally and personally.WHO YOU’LL WORK WITHAs the premier consulting partner for the private equity industry, Bain's PEG boasts a global practice that is over three times larger than any competitor. Our network of over 1,000 professionals supports private equity and institutional investor clients through every stage of the investment life cycle, from deal generation and due diligence to portfolio value creation and exit planning.Bain & Company is developing a suite of cutting-edge data and software solutions designed to revolutionize how the private equity industry uses data for investment insights and decision-making. The PEG Innovation team's mission is to create analytical solutions for Bain clients, teams, and the broader institutional investor space using proprietary software and data products. This includes the development, commercialization, and daily management of Bain's proprietary datasets, data, and software businesses.WHERE YOU’LL FIT WITHIN THE TEAMSenior Platform Engineers design and build the shared services that every product and data squad depends on: Auth, RBAC, Session Management, Audit, Notifications, File handling, Search, and more. Our platform runs on Microsoft Azure and Azure Kubernetes Service (AKS). You own your services end-to-end: design, build, test, deploy, monitor, and operate them. You set the standard for how platform services are built and contribute to the engineering standards and conventions that govern the broader estate. You collaborate closely with Security and Infrastructure to ensure services are secure-by-default, observable from day one, and operable under production on-call expectations.WHAT YOU'LL DOCore Platform Service Development, Deployment, and Operations (80%) Design, build, test, deploy, and operate core platform services to production quality standards (Auth, RBAC, Session, Audit, Notifications, File, Search).Own service APIs and contracts end-to-end: versioning, backwards compatibility, and consumer impact management across product squads.Write and maintain Postgres schemas and Alembic migrations using the expand/contract pattern; never ship a breaking schema change without a backwards-compatible transition.Implement and enforce authentication and authorisation patterns: JWT, refresh token rotation, RBAC, SAML/OIDC, and service-to-service auth where required.Design and operate Redis-backed patterns: caching, session storage, rate limiting, pub/sub, and distributed lock coordination where needed.Build and operate event-driven capabilities using Kafka domain events (CloudEvents envelope, schema registry integration) where platform services publish and consume.Instrument services with structured logs, distributed tracing, and Prometheus metrics from day one using OpenTelemetry and FastAPI instrumentation.Write and maintain Helm charts for owned services; contribute to Kubernetes manifests in the platform-infra repository (health checks, resource limits, HPA readiness).Participate in on-call rotation for platform incidents; drive incident response to resolution and maintain runbooks for owned services.Other (20%)Set and enforce engineering standards for platform service development: testing, observability, security, reliability, and operational hygiene.Conduct thorough code reviews; enforce standards on PRs and raise the bar for production practices across the platform estate.Mentor mid-level and junior platform engineers through pairing, design guidance, and ongoing review feedback.Use AI coding assistants to accelerate service scaffolding, API/router generation, migration drafts, and test creation; review all generated code against production and security standards before committing.Use LLMs to generate first-draft documentation (runbooks, service docs, API notes) and operational checklists; validate and refine outputs before publishing.Collaborate with the Security Engineer on Vault integration (Vault Agent Injector) and/or Azure Key Vault, dynamic secrets usage, policy scoping, mTLS policy, and software supply chain security requirements.ABOUT YOUBachelor’s degree in Computer Science, Engineering, Information Systems, or a related field (or equivalent practical experience).6+ years of experience building and operating backend services, APIs, or platform components in production environments, including on-call responsibility.Demonstrated experience owning production backend services end-to-end (design, build, test, deploy, monitor, and operate), including on-call operational responsibility.Production experience building and operating REST and event-driven microservices at scale in a Kubernetes environment.Experience designing and operating data stores in Postgres, including schema migration practices, query optimisation, and performance tuning.Experience implementing authentication and authorization systems (JWT, refresh token rotation, RBAC, SAML/OIDC) in production environments.Demonstrated ability to mentor other engineers and raise engineering standards through code review and shared conventions.Backend/Platform EngineeringStrong Python proficiency: FastAPI, Pydantic v2, SQLAlchemy 2.0 async, Alembic, pytest, Ruff, mypy (strict).Production microservices: REST APIs, event-driven patterns, idempotency, retries, backwards-compatible versioning, and consumer contract discipline.PostgreSQL: query plan analysis, indexing strategies, partitioning approaches, and schema evolution patterns for high-availability systems.Redis: caching strategies, session storage, pub/sub, and rate limiting patterns; understands operational trade-offs and failure modes.Apache Kafka: producing/consuming domain events, CloudEvents envelope conventions, schema registry integration, and consumer group semantics.Docker: multi-stage builds, non-root containers, image scanning (e.g., Trivy), and secure base-image practices.Kubernetes: Helm charts, pod lifecycle, probes/health checks, resource requests/limits, and HPA concepts; comfortable operating services on-cluster.Observability: OpenTelemetry instrumentation, structured logging (structlog), distributed tracing, and Prometheus metrics for FastAPI services; experience with Azure Monitor a plus.Secrets and security: familiarity with HashiCorp Vault (Vault Agent Injector, dynamic secrets, policy scoping) and/or Azure Key Vault, and secure service-to-service patterns.Generative AI and agentic systemsUses AI coding assistants (Cursor, GitHub Copilot, or equivalent) to accelerate feature development and reduce repetitive boilerplate; reviews all generated code against production and security standards before committing.Uses agents to generate first-draft Pydantic schemas, SQLAlchemy models, and FastAPI router skeletons; refines outputs to match domain conventions and security requirements.Uses LLM assistance to draft unit and integration test cases; validates coverage gaps and supplements with manually authored tests.Understands how platform services (Auth, RBAC, Audit) interact with the Agent Gateway and what security constraints (permissions, auditability, data minimisation) that interaction requires.GeneralTreats every service as a production system from the first commit: tests, observability, documentation, and runbooks are not optional.Communicates blockers early and escalates appropriately; does not quietly struggle for days before raising a risk.Uses AI tooling to move faster, but applies critical judgement and rigorous review to all generated code and documentation before it enters the codebase.Keeps runbooks and service documentation current as services evolve; treats operability as part of delivery.This role follows a hybrid model, requiring in-office presence at least 1 day per weekU.S. COMPENSATION INFORMATIONCompensation for this role includes base salary, annual discretionary performance bonus, 401(k) plan with an annual employer contribution based on years of service and Bain’s best in class benefits package (details listed below).Some local governments in the United States require a good-faith, reasonable salary range be included in job postings for open roles. The estimated annualized compensation for this role is as follows:In Atlanta, the good-faith, reasonable annualized full-time salary range for this role is between $140,875 - $153,750In Boston, the good-faith, reasonable annualized full-time salary range for this role is between $162,000 - $176,750In Dallas, the good-faith, reasonable annualized full-time salary range for this role is between $147,625 - $161,250In Chicago, the good-faith, reasonable annualized full-time salary range for this role is between $155,125 - $169,250In New York, the good-faith, reasonable annualized full-time salary range for this role is between $176,250 - $192,250Placement within these ranges will vary based on factors such as experience, education, training, and skill level.Compensation also includes a discretionary annual performance bonus, 401(k) plan with employer contribution, and Bain’s best-in-class benefits—including full premium coverage for medical, dental, and vision, generous paid time off, and more.Annual discretionary performance bonus This role may also be eligible for other elements of discretionary compensation4.5% 401(k) company contribution, which increases after 3 years of service and is 100% vested upon start dateBain & Company's comprehensive benefits and wellness program is designed to help employees achieve personal independence, protection and stability in the areas most important to you and your family.Bain pays 100% individual employee premiums for medical, dental and vision programs, offering one of the most comprehensive medical plans for employees without impacting your paycheckGenerous paid time off, including parental leave, sick leave and paid holidaysFully vested 401(k) company contributionPaid Life and Long-Term Disability insuranceWHAT MAKES US A GREAT PLACE TO WORKWe are proud to be consistently recognized as one of the world’s best places to work. We are currently the top ranked consulting firm on Glassdoor’s Best Places to Work list and have earned the #1 overall spot a record seven times.Extraordinary teams are at the heart of our business strategy, but these don’t happen by chance. They require intentional focus on bringing together a broad set of backgrounds, cultures, experiences, perspectives, and skills in a supportive and inclusive work environment. We hire people with exceptional talent and create an environment in which every individual can thrive professionally and personally.WHO YOU’LL WORK WITHAs the premier consulting partner for the private equity industry, Bain's PEG boasts a global practice that is over three times larger than any competitor. Our network of over 1,000 professionals supports private equity and institutional investor clients through every stage of the investment life cycle, from deal generation and due diligence to portfolio value creation and exit planning.Bain & Company is developing a suite of cutting-edge data and software solutions designed to revolutionize how the private equity industry uses data for investment insights and decision-making. The PEG Innovation team's mission is to create analytical solutions for Bain clients, teams, and the broader institutional investor space using proprietary software and data products. This includes the development, commercialization, and daily management of Bain's proprietary datasets, data, and software businesses.WHERE YOU’LL FIT WITHIN THE TEAMSenior Platform Engineers design and build the shared services that every product and data squad depends on: Auth, RBAC, Session Management, Audit, Notifications, File handling, Search, and more. Our platform runs on Microsoft Azure and Azure Kubernetes Service (AKS). You own your services end-to-end: design, build, test, deploy, monitor, and operate them. You set the standard for how platform services are built and contribute to the engineering standards and conventions that govern the broader estate. You collaborate closely with Security and Infrastructure to ensure services are secure-by-default, observable from day one, and operable under production on-call expectations.WHAT YOU'LL DOCore Platform Service Development, Deployment, and Operations (80%) Design, build, test, deploy, and operate core platform services to production quality standards (Auth, RBAC, Session, Audit, Notifications, File, Search).Own service APIs and contracts end-to-end: versioning, backwards compatibility, and consumer impact management across product squads.Write and maintain Postgres schemas and Alembic migrations using the expand/contract pattern; never ship a breaking schema change without a backwards-compatible transition.Implement and enforce authentication and authorisation patterns: JWT, refresh token rotation, RBAC, SAML/OIDC, and service-to-service auth where required.Design and operate Redis-backed patterns: caching, session storage, rate limiting, pub/sub, and distributed lock coordination where needed.Build and operate event-driven capabilities using Kafka domain events (CloudEvents envelope, schema registry integration) where platform services publish and consume.Instrument services with structured logs, distributed tracing, and Prometheus metrics from day one using OpenTelemetry and FastAPI instrumentation.Write and maintain Helm charts for owned services; contribute to Kubernetes manifests in the platform-infra repository (health checks, resource limits, HPA readiness).Participate in on-call rotation for platform incidents; drive incident response to resolution and maintain runbooks for owned services.Other (20%)Set and enforce engineering standards for platform service development: testing, observability, security, reliability, and operational hygiene.Conduct thorough code reviews; enforce standards on PRs and raise the bar for production practices across the platform estate.Mentor mid-level and junior platform engineers through pairing, design guidance, and ongoing review feedback.Use AI coding assistants to accelerate service scaffolding, API/router generation, migration drafts, and test creation; review all generated code against production and security standards before committing.Use LLMs to generate first-draft documentation (runbooks, service docs, API notes) and operational checklists; validate and refine outputs before publishing.Collaborate with the Security Engineer on Vault integration (Vault Agent Injector) and/or Azure Key Vault, dynamic secrets usage, policy scoping, mTLS policy, and software supply chain security requirements.ABOUT YOUBachelor’s degree in Computer Science, Engineering, Information Systems, or a related field (or equivalent practical experience).6+ years of experience building and operating backend services, APIs, or platform components in production environments, including on-call responsibility.Demonstrated experience owning production backend services end-to-end (design, build, test, deploy, monitor, and operate), including on-call operational responsibility.Production experience building and operating REST and event-driven microservices at scale in a Kubernetes environment.Experience designing and operating data stores in Postgres, including schema migration practices, query optimisation, and performance tuning.Experience implementing authentication and authorization systems (JWT, refresh token rotation, RBAC, SAML/OIDC) in production environments.Demonstrated ability to mentor other engineers and raise engineering standards through code review and shared conventions.Backend/Platform EngineeringStrong Python proficiency: FastAPI, Pydantic v2, SQLAlchemy 2.0 async, Alembic, pytest, Ruff, mypy (strict).Production microservices: REST APIs, event-driven patterns, idempotency, retries, backwards-compatible versioning, and consumer contract discipline.PostgreSQL: query plan analysis, indexing strategies, partitioning approaches, and schema evolution patterns for high-availability systems.Redis: caching strategies, session storage, pub/sub, and rate limiting patterns; understands operational trade-offs and failure modes.Apache Kafka: producing/consuming domain events, CloudEvents envelope conventions, schema registry integration, and consumer group semantics.Docker: multi-stage builds, non-root containers, image scanning (e.g., Trivy), and secure base-image practices.Kubernetes: Helm charts, pod lifecycle, probes/health checks, resource requests/limits, and HPA concepts; comfortable operating services on-cluster.Observability: OpenTelemetry instrumentation, structured logging (structlog), distributed tracing, and Prometheus metrics for FastAPI services; experience with Azure Monitor a plus.Secrets and security: familiarity with HashiCorp Vault (Vault Agent Injector, dynamic secrets, policy scoping) and/or Azure Key Vault, and secure service-to-service patterns.Generative AI and agentic systemsUses AI coding assistants (Cursor, GitHub Copilot, or equivalent) to accelerate feature development and reduce repetitive boilerplate; reviews all generated code against production and security standards before committing.Uses agents to generate first-draft Pydantic schemas, SQLAlchemy models, and FastAPI router skeletons; refines outputs to match domain conventions and security requirements.Uses LLM assistance to draft unit and integration test cases; validates coverage gaps and supplements with manually authored tests.Understands how platform services (Auth, RBAC, Audit) interact with the Agent Gateway and what security constraints (permissions, auditability, data minimisation) that interaction requires.GeneralTreats every service as a production system from the first commit: tests, observability, documentation, and runbooks are not optional.Communicates blockers early and escalates appropriately; does not quietly struggle for days before raising a risk.Uses AI tooling to move faster, but applies critical judgement and rigorous review to all generated code and documentation before it enters the codebase.Keeps runbooks and service documentation current as services evolve; treats operability as part of delivery.This role follows a hybrid model, requiring in-office presence at least 1 day per weekU.S. COMPENSATION INFORMATIONCompensation for this role includes base salary, annual discretionary performance bonus, 401(k) plan with an annual employer contribution based on years of service and Bain’s best in class benefits package (details listed below).Some local governments in the United States require a good-faith, reasonable salary range be included in job postings for open roles. The estimated annualized compensation for this role is as follows:In Atlanta, the good-faith, reasonable annualized full-time salary range for this role is between $140,875 - $153,750In Boston, the good-faith, reasonable annualized full-time salary range for this role is between $162,000 - $176,750In Dallas, the good-faith, reasonable annualized full-time salary range for this role is between $147,625 - $161,250In Chicago, the good-faith, reasonable annualized full-time salary range for this role is between $155,125 - $169,250In New York, the good-faith, reasonable annualized full-time salary range for this role is between $176,250 - $192,250Placement within these ranges will vary based on factors such as experience, education, training, and skill level.Compensation also includes a discretionary annual performance bonus, 401(k) plan with employer contribution, and Bain’s best-in-class benefits—including full premium coverage for medical, dental, and vision, generous paid time off, and more.Annual discretionary performance bonus This role may also be eligible for other elements of discretionary compensation4.5% 401(k) company contribution, which increases after 3 years of service and is 100% vested upon start dateBain & Company's comprehensive benefits and wellness program is designed to help employees achieve personal independence, protection and stability in the areas most important to you and your family.Bain pays 100% individual employee premiums for medical, dental and vision programs, offering one of the most comprehensive medical plans for employees without impacting your paycheckGenerous paid time off, including parental leave, sick leave and paid holidaysFully vested 401(k) company contributionPaid Life and Long-Term Disability insuranceWHAT MAKES US A GREAT PLACE TO WORKWe are proud to be consistently recognized as one of the world’s best places to work. We are currently the top ranked consulting firm on Glassdoor’s Best Places to Work list and have earned the #1 overall spot a record seven times.Extraordinary teams are at the heart of our business strategy, but these don’t happen by chance. They require intentional focus on bringing together a broad set of backgrounds, cultures, experiences, perspectives, and skills in a supportive and inclusive work environment. We hire people with exceptional talent and create an environment in which every individual can thrive professionally and personally.WHO YOU’LL WORK WITHAs the premier consulting partner for the private equity industry, Bain's PEG boasts a global practice that is over three times larger than any competitor. Our network of over 1,000 professionals supports private equity and institutional investor clients through every stage of the investment life cycle, from deal generation and due diligence to portfolio value creation and exit planning.Bain & Company is developing a suite of cutting-edge data and software solutions designed to revolutionize how the private equity industry uses data for investment insights and decision-making. The PEG Innovation team's mission is to create analytical solutions for Bain clients, teams, and the broader institutional investor space using proprietary software and data products. This includes the development, commercialization, and daily management of Bain's proprietary datasets, data, and software businesses.WHERE YOU’LL FIT WITHIN THE TEAMSenior Platform Engineers design and build the shared services that every product and data squad depends on: Auth, RBAC, Session Management, Audit, Notifications, File handling, Search, and more. Our platform runs on Microsoft Azure and Azure Kubernetes Service (AKS). You own your services end-to-end: design, build, test, deploy, monitor, and operate them. You set the standard for how platform services are built and contribute to the engineering standards and conventions that govern the broader estate. You collaborate closely with Security and Infrastructure to ensure services are secure-by-default, observable from day one, and operable under production on-call expectations.WHAT YOU'LL DOCore Platform Service Development, Deployment, and Operations (80%) Design, build, test, deploy, and operate core platform services to production quality standards (Auth, RBAC, Session, Audit, Notifications, File, Search).Own service APIs and contracts end-to-end: versioning, backwards compatibility, and consumer impact management across product squads.Write and maintain Postgres schemas and Alembic migrations using the expand/contract pattern; never ship a breaking schema change without a backwards-compatible transition.Implement and enforce authentication and authorisation patterns: JWT, refresh token rotation, RBAC, SAML/OIDC, and service-to-service auth where required.Design and operate Redis-backed patterns: caching, session storage, rate limiting, pub/sub, and distributed lock coordination where needed.Build and operate event-driven capabilities using Kafka domain events (CloudEvents envelope, schema registry integration) where platform services publish and consume.Instrument services with structured logs, distributed tracing, and Prometheus metrics from day one using OpenTelemetry and FastAPI instrumentation.Write and maintain Helm charts for owned services; contribute to Kubernetes manifests in the platform-infra repository (health checks, resource limits, HPA readiness).Participate in on-call rotation for platform incidents; drive incident response to resolution and maintain runbooks for owned services.Other (20%)Set and enforce engineering standards for platform service development: testing, observability, security, reliability, and operational hygiene.Conduct thorough code reviews; enforce standards on PRs and raise the bar for production practices across the platform estate.Mentor mid-level and junior platform engineers through pairing, design guidance, and ongoing review feedback.Use AI coding assistants to accelerate service scaffolding, API/router generation, migration drafts, and test creation; review all generated code against production and security standards before committing.Use LLMs to generate first-draft documentation (runbooks, service docs, API notes) and operational checklists; validate and refine outputs before publishing.Collaborate with the Security Engineer on Vault integration (Vault Agent Injector) and/or Azure Key Vault, dynamic secrets usage, policy scoping, mTLS policy, and software supply chain security requirements.ABOUT YOUBachelor’s degree in Computer Science, Engineering, Information Systems, or a related field (or equivalent practical experience).6+ years of experience building and operating backend services, APIs, or platform components in production environments, including on-call responsibility.Demonstrated experience owning production backend services end-to-end (design, build, test, deploy, monitor, and operate), including on-call operational responsibility.Production experience building and operating REST and event-driven microservices at scale in a Kubernetes environment.Experience designing and operating data stores in Postgres, including schema migration practices, query optimisation, and performance tuning.Experience implementing authentication and authorization systems (JWT, refresh token rotation, RBAC, SAML/OIDC) in production environments.Demonstrated ability to mentor other engineers and raise engineering standards through code review and shared conventions.Backend/Platform EngineeringStrong Python proficiency: FastAPI, Pydantic v2, SQLAlchemy 2.0 async, Alembic, pytest, Ruff, mypy (strict).Production microservices: REST APIs, event-driven patterns, idempotency, retries, backwards-compatible versioning, and consumer contract discipline.PostgreSQL: query plan analysis, indexing strategies, partitioning approaches, and schema evolution patterns for high-availability systems.Redis: caching strategies, session storage, pub/sub, and rate limiting patterns; understands operational trade-offs and failure modes.Apache Kafka: producing/consuming domain events, CloudEvents envelope conventions, schema registry integration, and consumer group semantics.Docker: multi-stage builds, non-root containers, image scanning (e.g., Trivy), and secure base-image practices.Kubernetes: Helm charts, pod lifecycle, probes/health checks, resource requests/limits, and HPA concepts; comfortable operating services on-cluster.Observability: OpenTelemetry instrumentation, structured logging (structlog), distributed tracing, and Prometheus metrics for FastAPI services; experience with Azure Monitor a plus.Secrets and security: familiarity with HashiCorp Vault (Vault Agent Injector, dynamic secrets, policy scoping) and/or Azure Key Vault, and secure service-to-service patterns.Generative AI and agentic systemsUses AI coding assistants (Cursor, GitHub Copilot, or equivalent) to accelerate feature development and reduce repetitive boilerplate; reviews all generated code against production and security standards before committing.Uses agents to generate first-draft Pydantic schemas, SQLAlchemy models, and FastAPI router skeletons; refines outputs to match domain conventions and security requirements.Uses LLM assistance to draft unit and integration test cases; validates coverage gaps and supplements with manually authored tests.Understands how platform services (Auth, RBAC, Audit) interact with the Agent Gateway and what security constraints (permissions, auditability, data minimisation) that interaction requires.GeneralTreats every service as a production system from the first commit: tests, observability, documentation, and runbooks are not optional.Communicates blockers early and escalates appropriately; does not quietly struggle for days before raising a risk.Uses AI tooling to move faster, but applies critical judgement and rigorous review to all generated code and documentation before it enters the codebase.Keeps runbooks and service documentation current as services evolve; treats operability as part of delivery.This role follows a hybrid model, requiring in-office presence at least 1 day per weekU.S. COMPENSATION INFORMATIONCompensation for this role includes base salary, annual discretionary performance bonus, 401(k) plan with an annual employer contribution based on years of service and Bain’s best in class benefits package (details listed below).Some local governments in the United States require a good-faith, reasonable salary range be included in job postings for open roles. The estimated annualized compensation for this role is as follows:In Atlanta, the good-faith, reasonable annualized full-time salary range for this role is between $140,875 - $153,750In Boston, the good-faith, reasonable annualized full-time salary range for this role is between $162,000 - $176,750In Dallas, the good-faith, reasonable annualized full-time salary range for this role is between $147,625 - $161,250In Chicago, the good-faith, reasonable annualized full-time salary range for this role is between $155,125 - $169,250In New York, the good-faith, reasonable annualized full-time salary range for this role is between $176,250 - $192,250Placement within these ranges will vary based on factors such as experience, education, training, and skill level.Compensation also includes a discretionary annual performance bonus, 401(k) plan with employer contribution, and Bain’s best-in-class benefits—including full premium coverage for medical, dental, and vision, generous paid time off, and more.Annual discretionary performance bonus This role may also be eligible for other elements of discretionary compensation4.5% 401(k) company contribution, which increases after 3 years of service and is 100% vested upon start dateBain & Company's comprehensive benefits and wellness program is designed to help employees achieve personal independence, protection and stability in the areas most important to you and your family.Bain pays 100% individual employee premiums for medical, dental and vision programs, offering one of the most comprehensive medical plans for employees without impacting your paycheckGenerous paid time off, including parental leave, sick leave and paid holidaysFully vested 401(k) company contributionPaid Life and Long-Term Disability insurance

WHAT MAKES US A GREAT PLACE TO WORK

WHAT MAKES US A GREAT PLACE TO WORKWHAT MAKES US A GREAT PLACE TO WORK

We are proud to be consistently recognized as one of the world’s best places to work. We are currently the top ranked consulting firm on Glassdoor’s Best Places to Work list and have earned the #1 overall spot a record seven times.

We are proud to be consistently recognized as one of the world’s best places to work. We are currently the top ranked consulting firm on Glassdoor’s Best Places to Work list and have earned the #1 overall spot a record seven times.

Extraordinary teams are at the heart of our business strategy, but these don’t happen by chance. They require intentional focus on bringing together a broad set of backgrounds, cultures, experiences, perspectives, and skills in a supportive and inclusive work environment. We hire people with exceptional talent and create an environment in which every individual can thrive professionally and personally.

Extraordinary teams are at the heart of our business strategy, but these don’t happen by chance. They require intentional focus on bringing together a broad set of backgrounds, cultures, experiences, perspectives, and skills in a supportive and inclusive work environment. We hire people with exceptional talent and create an environment in which every individual can thrive professionally and personally.

WHO YOU’LL WORK WITH

WHO YOU’LL WORK WITHWHO YOU’LL WORK WITH

As the premier consulting partner for the private equity industry, Bain's PEG boasts a global practice that is over three times larger than any competitor. Our network of over 1,000 professionals supports private equity and institutional investor clients through every stage of the investment life cycle, from deal generation and due diligence to portfolio value creation and exit planning.

As the premier consulting partner for the private equity industry, Bain's PEG boasts a global practice that is over three times larger than any competitor. Our network of over 1,000 professionals supports private equity and institutional investor clients through every stage of the investment life cycle, from deal generation and due diligence to portfolio value creation and exit planning.

Bain & Company is developing a suite of cutting-edge data and software solutions designed to revolutionize how the private equity industry uses data for investment insights and decision-making.

Bain & Company is developing a suite of cutting-edge data and software solutions designed to revolutionize how the private equity industry uses data for investment insights and decision-making.

The PEG Innovation team's mission is to create analytical solutions for Bain clients, teams, and the broader institutional investor space using proprietary software and data products. This includes the development, commercialization, and daily management of Bain's proprietary datasets, data, and software businesses.

The PEG Innovation team's mission is to create analytical solutions for Bain clients, teams, and the broader institutional investor space using proprietary software and data products. This includes the development, commercialization, and daily management of Bain's proprietary datasets, data, and software businesses.

WHERE YOU’LL FIT WITHIN THE TEAM

WHERE YOU’LL FIT WITHIN THE TEAMWHERE YOU’LL FIT WITHIN THE TEAM

Senior Platform Engineers design and build the shared services that every product and data squad depends on: Auth, RBAC, Session Management, Audit, Notifications, File handling, Search, and more. Our platform runs on Microsoft Azure and Azure Kubernetes Service (AKS). You own your services end-to-end: design, build, test, deploy, monitor, and operate them. You set the standard for how platform services are built and contribute to the engineering standards and conventions that govern the broader estate. You collaborate closely with Security and Infrastructure to ensure services are secure-by-default, observable from day one, and operable under production on-call expectations.

Senior Platform Engineers design and build the shared services that every product and data squad depends on: Auth, RBAC, Session Management, Audit, Notifications, File handling, Search, and more. Our platform runs on Microsoft Azure and Azure Kubernetes Service (AKS). You own your services end-to-end: design, build, test, deploy, monitor, and operate them. You set the standard for how platform services are built and contribute to the engineering standards and conventions that govern the broader estate. You collaborate closely with Security and Infrastructure to ensure services are secure-by-default, observable from day one, and operable under production on-call expectations.

WHAT YOU'LL DO

WHAT YOU'LL DOWHAT YOU'LL DO

Core Platform Service Development, Deployment, and Operations (80%)

Core Platform Service Development, Deployment, and Operations (80%)Core Platform Service Development, Deployment, and Operations (80%)
  • Design, build, test, deploy, and operate core platform services to production quality standards (Auth, RBAC, Session, Audit, Notifications, File, Search).
  • Own service APIs and contracts end-to-end: versioning, backwards compatibility, and consumer impact management across product squads.
  • Write and maintain Postgres schemas and Alembic migrations using the expand/contract pattern; never ship a breaking schema change without a backwards-compatible transition.
  • Implement and enforce authentication and authorisation patterns: JWT, refresh token rotation, RBAC, SAML/OIDC, and service-to-service auth where required.
  • Design and operate Redis-backed patterns: caching, session storage, rate limiting, pub/sub, and distributed lock coordination where needed.
  • Build and operate event-driven capabilities using Kafka domain events (CloudEvents envelope, schema registry integration) where platform services publish and consume.
  • Instrument services with structured logs, distributed tracing, and Prometheus metrics from day one using OpenTelemetry and FastAPI instrumentation.
  • Write and maintain Helm charts for owned services; contribute to Kubernetes manifests in the platform-infra repository (health checks, resource limits, HPA readiness).
  • Participate in on-call rotation for platform incidents; drive incident response to resolution and maintain runbooks for owned services.

Other (20%)

Other (20%)Other (20%)
  • Set and enforce engineering standards for platform service development: testing, observability, security, reliability, and operational hygiene.
  • Conduct thorough code reviews; enforce standards on PRs and raise the bar for production practices across the platform estate.
  • Mentor mid-level and junior platform engineers through pairing, design guidance, and ongoing review feedback.
  • Use AI coding assistants to accelerate service scaffolding, API/router generation, migration drafts, and test creation; review all generated code against production and security standards before committing.
  • Use LLMs to generate first-draft documentation (runbooks, service docs, API notes) and operational checklists; validate and refine outputs before publishing.
  • Collaborate with the Security Engineer on Vault integration (Vault Agent Injector) and/or Azure Key Vault, dynamic secrets usage, policy scoping, mTLS policy, and software supply chain security requirements.

ABOUT YOU

ABOUT YOUABOUT YOU
  • Bachelor’s degree in Computer Science, Engineering, Information Systems, or a related field (or equivalent practical experience).
  • 6+ years of experience building and operating backend services, APIs, or platform components in production environments, including on-call responsibility.
  • Demonstrated experience owning production backend services end-to-end (design, build, test, deploy, monitor, and operate), including on-call operational responsibility.
  • Production experience building and operating REST and event-driven microservices at scale in a Kubernetes environment.
  • Experience designing and operating data stores in Postgres, including schema migration practices, query optimisation, and performance tuning.
  • Experience implementing authentication and authorization systems (JWT, refresh token rotation, RBAC, SAML/OIDC) in production environments.
  • Demonstrated ability to mentor other engineers and raise engineering standards through code review and shared conventions.

Backend/Platform Engineering

Backend/Platform EngineeringBackend/Platform Engineering
  • Strong Python proficiency: FastAPI, Pydantic v2, SQLAlchemy 2.0 async, Alembic, pytest, Ruff, mypy (strict).
  • Production microservices: REST APIs, event-driven patterns, idempotency, retries, backwards-compatible versioning, and consumer contract discipline.
  • PostgreSQL: query plan analysis, indexing strategies, partitioning approaches, and schema evolution patterns for high-availability systems.
  • Redis: caching strategies, session storage, pub/sub, and rate limiting patterns; understands operational trade-offs and failure modes.
  • Apache Kafka: producing/consuming domain events, CloudEvents envelope conventions, schema registry integration, and consumer group semantics.
  • Docker: multi-stage builds, non-root containers, image scanning (e.g., Trivy), and secure base-image practices.
  • Kubernetes: Helm charts, pod lifecycle, probes/health checks, resource requests/limits, and HPA concepts; comfortable operating services on-cluster.
  • Observability: OpenTelemetry instrumentation, structured logging (structlog), distributed tracing, and Prometheus metrics for FastAPI services; experience with Azure Monitor a plus.
  • Secrets and security: familiarity with HashiCorp Vault (Vault Agent Injector, dynamic secrets, policy scoping) and/or Azure Key Vault, and secure service-to-service patterns.

Generative AI and agentic systems

Generative AI and agentic systemsGenerative AI and agentic systems
  • Uses AI coding assistants (Cursor, GitHub Copilot, or equivalent) to accelerate feature development and reduce repetitive boilerplate; reviews all generated code against production and security standards before committing.
  • Uses agents to generate first-draft Pydantic schemas, SQLAlchemy models, and FastAPI router skeletons; refines outputs to match domain conventions and security requirements.
  • Uses LLM assistance to draft unit and integration test cases; validates coverage gaps and supplements with manually authored tests.
  • Understands how platform services (Auth, RBAC, Audit) interact with the Agent Gateway and what security constraints (permissions, auditability, data minimisation) that interaction requires.

General

GeneralGeneral
  • Treats every service as a production system from the first commit: tests, observability, documentation, and runbooks are not optional.
  • Communicates blockers early and escalates appropriately; does not quietly struggle for days before raising a risk.
  • Uses AI tooling to move faster, but applies critical judgement and rigorous review to all generated code and documentation before it enters the codebase.
  • Keeps runbooks and service documentation current as services evolve; treats operability as part of delivery.
  • This role follows a hybrid model, requiring in-office presence at least 1 day per week

U.S. COMPENSATION INFORMATION

U.S. COMPENSATION INFORMATIONU.S. COMPENSATION INFORMATION

Compensation for this role includes base salary, annual discretionary performance bonus, 401(k) plan with an annual employer contribution based on years of service and Bain’s best in class benefits package (details listed below).

Compensation for this role includes base salary, annual discretionary performance bonus, 401(k) plan with an annual employer contribution based on years of service and Bain’s best in class benefits package (details listed below).

Some local governments in the United States require a good-faith, reasonable salary range be included in job postings for open roles. The estimated annualized compensation for this role is as follows:

Some local governments in the United States require a good-faith, reasonable salary range be included in job postings for open roles. The estimated annualized compensation for this role is as follows:

In Atlanta, the good-faith, reasonable annualized full-time salary range for this role is between $140,875 - $153,750In Boston, the good-faith, reasonable annualized full-time salary range for this role is between $162,000 - $176,750

In Atlanta, the good-faith, reasonable annualized full-time salary range for this role is between $140,875 - $153,750In Boston, the good-faith, reasonable annualized full-time salary range for this role is between $162,000 - $176,750In Boston, the good-faith, reasonable annualized full-time salary range for this role is between $162,000 - $176,750

In Dallas, the good-faith, reasonable annualized full-time salary range for this role is between $147,625 - $161,250

In Dallas, the good-faith, reasonable annualized full-time salary range for this role is between $147,625 - $161,250

In Chicago, the good-faith, reasonable annualized full-time salary range for this role is between $155,125 - $169,250

In Chicago, the good-faith, reasonable annualized full-time salary range for this role is between $155,125 - $169,250

In New York, the good-faith, reasonable annualized full-time salary range for this role is between $176,250 - $192,250

In New York, the good-faith, reasonable annualized full-time salary range for this role is between $176,250 - $192,250In New York, the good-faith, reasonable annualized full-time salary range for this role is between $176,250 - $192,250

Placement within these ranges will vary based on factors such as experience, education, training, and skill level.

Placement within these ranges will vary based on factors such as experience, education, training, and skill level.

Compensation also includes a discretionary annual performance bonus, 401(k) plan with employer contribution, and Bain’s best-in-class benefits—including full premium coverage for medical, dental, and vision, generous paid time off, and more.

Compensation also includes a discretionary annual performance bonus, 401(k) plan with employer contribution, and Bain’s best-in-class benefits—including full premium coverage for medical, dental, and vision, generous paid time off, and more.

Annual discretionary performance bonus

Annual discretionary performance bonus

This role may also be eligible for other elements of discretionary compensation

This role may also be eligible for other elements of discretionary compensation

4.5% 401(k) company contribution, which increases after 3 years of service and is 100% vested upon start date

4.5% 401(k) company contribution, which increases after 3 years of service and is 100% vested upon start date

Bain & Company's comprehensive benefits and wellness program is designed to help employees achieve personal independence, protection and stability in the areas most important to you and your family.

Bain & Company's comprehensive benefits and wellness program is designed to help employees achieve personal independence, protection and stability in the areas most important to you and your family.

Bain pays 100% individual employee premiums for medical, dental and vision programs, offering one of the most comprehensive medical plans for employees without impacting your paycheck

Bain pays 100% individual employee premiums for medical, dental and vision programs, offering one of the most comprehensive medical plans for employees without impacting your paycheck

Generous paid time off, including parental leave, sick leave and paid holidays

Generous paid time off, including parental leave, sick leave and paid holidays

Fully vested 401(k) company contribution

Fully vested 401(k) company contribution

Paid Life and Long-Term Disability insurance

Paid Life and Long-Term Disability insurance

Similar jobs

General Information Job Title Lead Platform Engineer Job ID 100975 Work Areas Technology & Engineering Employment Type Permanent Full-Time Location(s) Bengaluru, Mumbai, New Delhi Description & Requirements WHAT MAKES US A GREAT PLACE TO WORKWe are proud to be consistently recognized as one of the world’s best places to work. We are currently the top ranked consulting firm on Glassdoor’s Best Places to Work list and have earned the #1 overall spot a record seven times.Extraordinary teams are at the heart of our business strategy, but these don’t happen by chance. They require intentional focus on bringing together a broad set of backgrounds, cultures, experiences, perspectives, and skills in a supportive and inclusive work environment. We hire people with exceptional talent and create an environment in which every individual can thrive professionally and personally. WHO YOU’LL WORK WITH Vector is Bain’s integrated digital and analytics capability, bringing together Enterprise Technology and AI, Insights & Solutions (AIS) to deliver cutting-edge innovation. AIS, formed through the merger of Bain's Advanced Analytics and Innovation & Design teams, is a diverse group of experts in analytics, engineering, product management, and design. Together, we create human-centric solutions that leverage the power of data and artificial intelligence to drive competitive advantage for our clients. WHAT YOU’LL DOAs a Lead, Platform Engineering, you will design and build cloud-based distributed systems that solve complex business challenges for some of the world’s largest companies. You will draw on your deep software engineering, cloud engineering, and DevOps expertise to design and build technology stacks and platform components that enable cross-functional AI Engineering teams to create robust, observable, and scalable solutions.Participate in code reviews and contribute to the establishment and enforcement of coding standards and best practices to ensure high-quality, maintainable codeUtilize Kubernetes and containerization technologies to deploy, manage, and scale analytics applications in cloud environments, ensuring optimal performance and availability. Develop and maintain APIs and microservices to expose analytics functionality to internal and external consumers, adhering to best practices for API design and documentationImplement robust security measures to protect sensitive data and ensure compliance with data privacy regulations and organizational policies. Continuously monitor and troubleshoot application performance, identifying and resolving issues that impact system reliability, latency, and user experience. Influence, educate and directly support the platform engineering capabilities of our clientsStay current with emerging trends and technologies in cloud computing, data analysis, and software engineering, and proactively identify opportunities to enhance the capabilities of the analytics platformABOUT YOURequired6+ years minimum experience and 3+ years at Senior or Staff level, or equivalentMaster’s degree in Computer Science, Engineering, or a related technical fieldProven experience as a cloud engineer and software engineer within either product engineering or professional services organizationsTechnical Skills and Knowledge:Experience designing and delivering cloud-based distributed solutions GCP, AWS, or Azure certifications are a plusExperience building infrastructure as code with tools such as Terraform (preferred), Cloud Formation, Pulumi, AWS CDK, CDKTF, etc.Experience building backend APIs, services and/or integrations with PythonDeep familiarity with nuances of software development lifecycleOne or more configuration management tools: Ansible, Salt, Puppet, or ChefOne or more monitoring and analytics platforms: Grafana, Prometheus, Splunk, SumoLogic, NewRelic, DataDog, CloudWatch, Nagios/IcingaCI/CD deployment pipelines (e.g. Github Actions, Jenkins, Travis CI, Gitlab CI, Circle CI)Practitioner experience with Kubernetes through services like GKE, EKS or AKS is a benefit Experience implementation of large-scale structured or unstructured databases, orchestration and container technologies such as Docker, Kubernetes or TerraformExperience with workflow orchestration such as dbt, Beam, Airflow, Luigy, Metaflow, Kubeflow, or any other Use Git as your main tool for versioning and collaboratingExposure to LLMs, Prompt engineering, Langchain a plusStrong knowledge in designing API interfaces Strong computer science fundaments in data structures, algorithms, automated testing, object-oriented programming, performance complexity, and implications of computer architecture on software performanceKnowledge of data architecture, database schema design, database scalabilityKnowledge of agile development methodologies and principlesTravel frequency and destinations will vary based on project needs. Hybrid roleInterpersonal Skills:Strong interpersonal and communication skills, including the ability to explain and discuss technicalities of solutions, algorithms and techniques with colleagues and clients from other disciplinesCuriosity, proactivity and critical thinkingAbility to collaborate with people at all levels and with multi-office/region teams Go back Apply Share this job: LinkedIn X Emailfull timeLead
posted 2 months ago
General Information Job Title Senior Associate – DevOps Engineer (D&T Techpod) Job ID 107769 Work Areas Analytics, Data & Research Employment Type Permanent Full-Time Location(s) New Delhi Description & Requirements About usBain & Company is a global management consulting that helps the world’s most ambitious change makers define the future. Across 65 offices in 40 countries, we work alongside our clients as one team with a shared ambition to achieve extraordinary results, outperform the competition and redefine industries. Since our founding in 1973, we have measured our success by the success of our clients, and we proudly maintain the highest level of client advocacy in the industry.In 2004, the firm established its presence in the Indian market by opening the Bain Capability Center (BCC) in New Delhi. The BCC is now known as BCN (Bain Capability Network) with its nodes across various geographies. BCN is an integral and largest unit of (ECD) Expert Client Delivery. ECD plays a critical role as it adds value to Bain's case teams globally by supporting them with analytics and research solutioning across all industries, specific domains for corporate cases, client development, private equity diligence or Bain intellectual property. The BCN comprises of Consulting Services, Knowledge Services and Shared Services.Who you will work with Pyxis leverages a broad portfolio of 50+ alternative datasets to provide real-time market intelligence and customer insights through a unique business model that enables us to provide our clients with competitive intelligence unrivaled in the market today. We provide insights and data via custom one-time projects or ongoing subscriptions to data feeds and visualization tools. We also offer custom data and analytics projects to suit our clients’ needs. Pyxis can help teams answer core questions about market dynamics, products, customer behavior, and ad spending on Amazon with a focus on providing our data and insights to clients in the way that best suits their needs. Refer to: www.pyxisbybain.com Your role would be to support the current infrastructure and manage the deployment pipeline (CI/CD Pipeline)which powers the Pyxis data analytics platform (AWS, Python and Snowflake) and Pyxis visualization platform (built on AWS and Angular)What you’ll do Design and manage enterprise-scale CI/CD pipelines using Jenkins, GitHub Actions, GitLab CI/CD, or Azure DevOps.Build and maintain Infrastructure as Code (IaC) using Terraform and CloudFormation.Deploy and manage containerized workloads on Kubernetes (EKS, AKS, GKE) and Docker.Architect and support cloud environments across AWS, Azure, or GCP.Implement DevSecOps practices using Snyk, Wiz, SonarQube, and security scanning tools.Establish cloud security posture management, vulnerability management, and compliance controls.Develop automation solutions using Python, Bash, or PowerShell.Configure monitoring and observability using Prometheus, Cloudwatch, , Datadog, or Splunk.Manage Linux-based production environments with high availability and disaster recovery capabilities.Implement networking, IAM, secrets management, SSL/TLS, load balancing, and zero-trust security principles.Drive platform reliability, scalability, and performance optimization initiatives.Troubleshoot complex infrastructure and production issues, conducting RCA and remediation.Collaborate with engineering, security, and architecture teams to deliver secure and efficient platforms.Experience with ArgoCD, Helm, Ansible, GitOps, and cloud governance frameworks is highly preferred.5+ years of DevOps/SRE experience with strong expertise in Terraform, Kubernetes, cloud security, and automation. Monitoring the processes during the entire lifecycle for its adherence and updating or creating new processes for improvement and minimizing the wastageEncouraging and building automated processes wherever possibleIdentifying and deploying cybersecurity measures by continuously performing vulnerability assessment and risk managementIncidence management and root cause analysisMentoring and guiding the team members Managing periodic reporting on the progress to the management About youA Bachelor’s or Master’s degree in Computer Science or related field7 + years of software development experience with 5+ years as a devops engineerHigh proficiency in cloud management (AWS heavily preferred) including Networking, API Gateways, infra deployment automation, and cloud opsKnowledge of Dev Ops/Code/Infra Management Tools: (GitHub, SonarQube, Snyk, AWS X-ray, Docker, Datadog and containerization)Infra automation using Terraform, environment creation and management, containerization using Docker Proficiency with PythonDisaster recovery, implementation of high availability apps / infra, business continuity planningWhat makes us a great place to workWe are proud to be consistently recognized as one of the world's best places to work, a champion of diversity and a model of social responsibility. We are currently ranked the #1 consulting firm on Glassdoor’s Best Places to Work list, and we have maintained a spot in the top four on Glassdoor's list for the last 12 years. We believe that diversity, inclusion and collaboration is key to building extraordinary teams. We hire people with exceptional talents, abilities and potential, then create an environment where you can become the best version of yourself and thrive both professionally and personally. We are publicly recognized by external parties such as Fortune, Vault, Mogul, Working Mother, Glassdoor and the Human Rights Campaign for being a great place to work for diversity and inclusion, women, LGBTQ and parents. Go back Apply Share this job: LinkedIn X Emailfull timeMid Level
posted 14 days ago
General Information Job Title Senior Engineer, DevOps & Assurance Job ID 106395 Work Areas Technology & Engineering Employment Type Permanent Full-Time Location(s) New Delhi Description & Requirements WHAT MAKES US A GREAT PLACE TO WORKWe are proud to be consistently recognized as one of the world’s best places to work. We are currently the #1 ranked consulting firm on Glassdoor’s Best Places to Work list and have maintained a spot in the top four on Glassdoor’s list since its founding in 2009.Extraordinary teams are at the heart of our business strategy, but these don’t happen by chance. They require intentional focus on bringing together a broad set of backgrounds, cultures, experiences, perspectives, and skills in a supportive and inclusive work environment. We hire people with exceptional talent and create an environment in which every individual can thrive professionally and personally.WHERE YOU’LL FIT WITHIN THE TEAMYou’ll be part of the DevOps and Assurance team within Bain’s Next Generation Software Solutions (NGSS) department — a multidisciplinary engineering organization responsible for building, operating, and scaling Bain’s next-generation digital products and platforms.The DevOps and Assurance team plays a critical role in enabling secure, efficient, and reliable delivery of technology solutions across Bain’s global ecosystem. The group focuses on both technical operations and platform assurance, ensuring that every deployment meets the firm’s high standards for quality, security, and compliance.WHAT YOU’LL DOWe are looking for an accomplished DevOps engineer to drive the design, implementation, and continuous improvement of cloud infrastructure and software delivery processes. In this role, you will lead efforts to build and scale CI/CD pipelines, provision and operate Azure infrastructure, and ensure security and reliability across the deployment lifecycle.The ideal candidate will work in close partnership with software development, QA, and security teams to foster a culture of automation, performance excellence, and operational resilience. This position requires both strong technical expertise and the ability to guide best practices and mentor engineers across teams.KEY RESPONSIBILITIESInfrastructure & Automation – 30%Design, provision, and manage cloud infrastructure using Terraform and Terraform Cloud. Automate deployments to ensure scalability, consistency, and security across environments.Architect and manage Azure networking: VNet/subnet design, private endpoints, DNS resolution, NSG rules, and Front Door Premium configuration.Provision and maintain Azure platform services: App Services, Azure SQL, Azure OpenAI, Azure Container Registry (ACR), Key Vault, Entra ID, and Storage Accounts (ADLS Gen2). Cloud & Platform Management (Azure) – 25%Manage Azure Kubernetes Service (AKS) clusters, including node pools, scaling, spot instances, and workload connectivity to dependent services (databases, storage, AI services).Manage identity and access: Entra ID app registrations, managed identities, RBAC, and integration with external IdPs (Okta).Administer database platforms from an infrastructure perspective: Azure SQL Serverless, PostgreSQL Flexible Server, Cosmos DB — including connectivity, Entra auth, firewall rules, and private endpoints.Ensure robust access controls and platform reliability across dev, demo, and production environments. CI/CD & Software Delivery – 20%Build, optimize, and maintain CI/CD pipelines using GitHub Actions for container builds, infrastructure deployments, and application releases.Manage container image lifecycle: build, scan, push to ACR, and deploy to AKS or App Services.Implement environment promotion workflows with appropriate gating, secrets management (Key Vault), and rollback strategies.Design and operate GitHub-hosted private runners where required, including network integration with Azure VNets. Monitoring, Security & Assurance – 15%Implement and operate observability using Datadog and Azure Application Insights. Monitor performance, resolve issues proactively, and optimize cost and reliability.Respond to security findings: triage, containment, IAM scoping, container image CVE remediation, and endpoint hardening.Handle L2/L3 incident escalations, including root-cause analysis, user journey tracing, and log analysis.Enforce solution compliance across products: network isolation, least-privilege access, secrets hygiene, and deployment guardrails. Leadership & Collaboration – 10%Partner with architects, product engineers, and security teams to align on infrastructure standards and platform roadmaps.Promote DevOps culture, automation-first thinking, and continuous improvement across the NGSS engineering organization.Contribute to technical discovery, POCs, and innovation work streams to validate new tools, technologies, and architectural patterns.Support team recruiting activities: resume screening, technical interviews, and candidate evaluation.ABOUT YOUEducation & ExperienceBachelor’s or Master’s degree in Computer Science, Engineering, or a related technical field.4–7 years of experience in DevOps, infrastructure engineering, or cloud platform engineering roles.Proven track record of designing and operating cloud infrastructure in production environments.Demonstrated experience working with cross-functional engineering teams in fast-paced product organizations.Professional Skills & MindsetExcellent communication and collaboration skills, with the ability to translate complex technical topics for diverse stakeholders.Proactive, analytical, and systematic — strong problem-solving skills with the ability to trace issues across multiple layers (DNS, networking, identity, application).Results-driven with a bias for automation and continuous improvement.Familiarity with Agile methodologies and a commitment to team enablement.Technical ExpertiseHands-on experience with Terraform and Terraform Cloud (or equivalent) — workspace management, state, modules, and remote backends.Strong proficiency in Azure services, including AKS, Networking (VNets, subnets, private endpoints, NSGs, DNS zones), App Services, Key Vault, Container Registry, and Storage Accounts.Experience with containerization technologies (Docker, Kubernetes) and container image lifecycle management.Expertise in roles, permissions, and IAM — particularly Microsoft Entra ID and Okta.Advanced skills in CI/CD automation using GitHub Actions, Azure DevOps, and related DevOps toolchains.Proficient in Linux administration and automation scripting (Bash, PowerShell, Python) for reusable workflows.Experience with monitoring platforms, including Datadog and Azure Application Insights.Familiarity with Azure private networking: private endpoints (blob, DFS, SQL, PostgreSQL), Private DNS Zones, and VNet integration for App Services and AKS.Competent in database deployment and management from an infrastructure perspective — Azure SQL Serverless, PostgreSQL Flexible Server, and Cosmos DB.Foundation in security remediation: container CVE patching, IAM scoping, NSG/firewall tightening, and WAF/Front Door rule management. Preferred QualificationsProfessional certifications such as Azure DevOps Engineer Expert, Azure Administrator, Terraform Associate, or CKA (or equivalent).Experience managing multi-environment governance, cost optimization, and compliance frameworks in cloud environments.Familiarity with Azure OpenAI, Cognitive Search, Databricks, and the integration of AI services into enterprise platforms.Experience with workflow orchestration tools (Airflow, or similar DAG/pipeline systems).Snowflake administration or connectivity from a DevOps lens. Go back Apply Share this job: LinkedIn X EmailRemotefull timeSenior
posted 2 months ago
General Information Job Title Senior Engineer, DevOps Engineering Job ID 109086 Work Areas Technology & Engineering Employment Type Permanent Full-Time Location(s) Mexico City, Warsaw Description & Requirements WHAT MAKES US A GREAT PLACE TO WORKWe are proud to be consistently recognized as one of the world’s best places to work. We are currently the top ranked consulting firm on Glassdoor’s Best Places to Work list and have earned the #1 overall spot a record seven times. Extraordinary teams are at the heart of our business strategy, but these don’t happen by chance. They require intentional focus on bringing together a broad set of backgrounds, cultures, experiences, perspectives, and skills in a supportive and inclusive work environment. We hire people with exceptional talent and create an environment in which every individual can thrive professionally and personally. WHO YOU’LL WORK WITHCoro is Bain's persistent product development and engineering organization, building and operating the firm's proprietary digital solutions. Coro brings together technology, data, and services to create differentiated value for Bain's clients and case teams.This role sits within Coro's DevOps and Assurance team, part of the Next Generation Software Solutions (NGSS) department. The team enables secure, efficient, and reliable delivery of technology across Bain's global ecosystem, focusing on both technical operations and platform assurance so that every deployment meets the firm's standards for quality, security, and compliance. WHERE YOU’LL FIT WITHIN THE TEAM The Senior Engineer helps build and operate the infrastructure, deployment automation, and operational reliability behind Coro's platforms. Working alongside architects and backend engineers, this engineer provisions and operates Azure infrastructure, builds and maintains CI/CD pipelines, and helps ensure services are deployed consistently, monitored effectively, and can scale as the build plan expands.This is a delivery-focused role: the Senior Engineer executes well against established standards and patterns, takes ownership of the tasks assigned to them, and collaborates closely with the wider team. It is a critical foundational role in the early stages of the platform build, requiring strong technical fundamentals and the pragmatism to make infrastructure decisions that support a fast-moving product team. WHAT YOU’LL DO Infrastructure & Automation – 30%Design, provision, and manage cloud infrastructure using Terraform and Terraform Cloud. Automate deployments to ensure scalability, consistency, and security across environments.Architect and manage Azure networking: VNet/subnet design, private endpoints, DNS resolution, NSG rules, and Front Door Premium configuration.Provision and maintain Azure platform services: App Services, Azure SQL, Azure OpenAI, Container Registry (e.g. Azure Container Registry, Cloudsmith), Key Vault, Entra ID, and Storage Accounts (ADLS Gen2).Collaborate with Bain's central cloud and infrastructure teams to refine shared processes, tooling, and approaches to operational work.Cloud & Platform Management (Azure) – 25%Manage Azure Kubernetes Service (AKS) clusters, including node pools, scaling, spot instances, and workload connectivity to dependent services (databases, storage, AI services).Manage identity and access: Entra ID app registrations, managed identities, RBAC, and integration with external IdPs (Okta).Administer database platforms from an infrastructure perspective: Azure SQL Serverless, PostgreSQL Flexible Server, Cosmos DB, including connectivity, Entra auth, firewall rules, and private endpoints.Ensure robust access controls and platform reliability across dev, demo, and production environments.CI/CD & Software Delivery – 20%Build, optimize, and maintain CI/CD pipelines using GitHub Actions for container builds, infrastructure deployments, and application releases.Manage container image lifecycle: build, scan, push to a container registry (e.g. Azure Container Registry, Cloudsmith), and deploy to AKS or App Services.Implement environment promotion workflows with appropriate gating, secrets management (Key Vault), and rollback strategies.Design and operate GitHub-hosted private runners where required, including network integration with Azure VNets.Monitoring, Security & Assurance – 15%Implement and operate observability using the team's monitoring stack (e.g. Datadog, Azure Application Insights). Monitor performance, resolve issues proactively, and optimize cost and reliability.Respond to security findings: triage, containment, IAM scoping, container image CVE remediation, and endpoint hardening.Handle L2/L3 incident escalations, including root-cause analysis, user journey tracing, and log analysis.Enforce solution compliance across products: network isolation, least-privilege access, secrets hygiene, and deployment guardrails.Maintain local development environments and deployment documentation so engineers across the distributed team can onboard quickly and operate with minimal infrastructure friction.Leadership & Collaboration – 10%Partner with architects, product engineers, and security teams to align on infrastructure standards and platform roadmaps.Promote DevOps culture, automation-first thinking, and continuous improvement across the NGSS engineering organization.Contribute to technical discovery, POCs, and innovation workstreams to validate new tools, technologies, and architectural patterns.Support team recruiting activities: resume screening, technical interviews, and candidate evaluation. ABOUT YOUEducation & ExperienceBachelor's or Master's degree in Computer Science, Engineering, or a related technical field.4–6 years of experience in DevOps, infrastructure engineering, or cloud platform engineering roles.Proven track record of designing and operating cloud infrastructure in production environments.Demonstrated experience working with cross-functional engineering teams in fast-paced product organizations.Professional Skills & MindsetExcellent communication and collaboration skills, with the ability to translate complex technical topics for diverse stakeholders.Proactive, analytical, and systematic, with strong problem-solving skills and the ability to trace issues across multiple layers (DNS, networking, identity, application).Results-driven with a bias for automation and continuous improvement.Familiarity with Agile methodologies and a commitment to team enablement.Technical ExpertiseHands-on experience with Terraform and Terraform Cloud (or equivalent): workspace management, state, modules, and remote backends.Strong proficiency in Azure services, including AKS, Networking (VNets, subnets, private endpoints, NSGs, DNS zones), App Services, Key Vault, Container Registry, and Storage Accounts.Experience with containerization technologies (Docker, Kubernetes) and container image lifecycle management.Expertise in roles, permissions, and IAM, particularly Microsoft Entra ID and Okta.Advanced skills in CI/CD automation using GitHub Actions, Azure DevOps, and related DevOps toolchains.Proficient in Linux administration and automation scripting (Bash, PowerShell, Python) for reusable workflows.Experience with monitoring and observability platforms (e.g. Datadog, Azure Application Insights).Familiarity with Azure private networking: private endpoints (blob, DFS, SQL, PostgreSQL), Private DNS Zones, and VNet integration for App Services and AKS.Competent in database deployment and management from an infrastructure perspective, Azure SQL Serverless, PostgreSQL Flexible Server, and Cosmos DB.Foundation in security remediation: container CVE patching, IAM scoping, NSG/firewall tightening, and WAF/Front Door rule management.Preferred QualificationsProfessional certifications such as Azure DevOps Engineer Expert, Azure Administrator, Terraform Associate, or CKA (or equivalent).Experience managing multi-environment governance, cost optimization, and compliance frameworks in cloud environments.Familiarity with Azure OpenAI, Cognitive Search, Databricks, and the integration of AI services into enterprise platforms.Experience with workflow orchestration tools (Airflow, or similar DAG/pipeline systems).Snowflake administration or connectivity from a DevOps lens.Experience with AI/ML observability tools such as LangSmith or Arize.Familiarity with AI coding assistants such as Cursor, Claude Code, or Codex to speed up development. Go back Apply Share this job: LinkedIn X EmailRemotefull timeSenior
posted yesterday