All roles with salary

Staff Infrastructure Engineer

TRM Labs USAUSD 205,000–245,000 / yearLead

Key requirements

  • Python
  • Go
  • Aws
  • Gcp
  • Kubernetes
  • Ci/Cd
  • Audit
  • Compliance
Build a Safer World. TRM Labs provides AI-powered intelligence solutions that help public and private sector agencies investigate and disrupt crime. TRM's platforms enable investigators to trace illicit activity, build cases, and construct operating pictures of threat networks. Leading agencies and businesses worldwide rely on TRM to make the world safer and more secure. In one line Our team builds the platform that every TRM product, every internal AI agent, and every investigation our customers run depends on. We are not maintaining a system someone else finished - we are building its next generation, on the bleeding edge, for workloads where reliability and security are not negotiable. We're looking for an engineer who has taken infrastructure from zero to one and can operate it in production. Why this work matters TRM's platform lets financial institutions and governments trace illicit finance, disrupt crypto- and AI-enabled crime, and run some of the highest-stakes investigations in the world. Our infrastructure is what lets investigators and banks trust the data underneath them . When we get it right, a case moves and a threat gets stopped. When infrastructure is weak, everything above it is slow, fragile, or unsafe. That's the job: make the foundation something the mission can be built on. What you'll actually work on This is real, current work - not a hypothetical roadmap: Multi-region, multi-cloud Kubernetes across US GCP, EU GCP, and AWS GovCloud - making "stand up another site" a self-serve configuration instead of a bespoke project. A genuinely self-serve internal PaaS. ~60+ engineers already deploy on it, the large majority with no infra person in the loop. You extend the paved road - golden paths, guardrails, and interfaces engineers actually enjoy using. Agent-native infrastructure. Secure sandboxes where AI agents build and ship, and encoding our operational knowledge into skills so the platform increasingly runs and heals itself. Zero-trust secrets with Vault. Short-lived, dynamic credentials replacing every long-lived secret in the system - closing the blast radius on leaked passwords, one database at a time. Reliability engineering that means it. SLOs and error budgets, real observability, and disaster recovery with validated cross-region restore and sub-hour RTO. Databases as a first-class platform concern. Postgres on Kubernetes, migrations, replication, and redundancy for services that can't blink. Compliance as code. SOC2 and FedRAMP posture built into the platform so security is the default, not a scramble before an audit. What you'll own You'll own an Area of Responsibility end to end - a slice of the platform that is genuinely yours. You'll define what "great" looks like for it and build the glide path to get there rather than waiting for one; obsess over the metrics that tell you whether it's actually working; and fix root causes so a class of problems disappears instead of working the ticket queue faster. You own the outcome, not just your layer of it. Who you are This is a builder's role , and the bar is high: You've taken infrastructure from zero to one - designed and shipped a platform capability that other engineers came to depend on, not just operated one that already existed. You write real software (Go, Python, or similar). You build tooling, automation, and services - you don't only wire up other people's tools. You're deep in GCP and/or AWS - compute, IAM, VPC, networking, storage, load balancing - and comfortable operating across clouds. You've run Kubernetes in production (GKE/EKS) and are up to date with the state of the art for IaC. You can debug low-level problems without hand-holding - a networking issue, a saturated node, a slow query, a failing deploy - and get to the actual cause. You're fluent across the modern platform toolchain: GitOps (Argo/Flux), containers, CI/CD, observability built on SLOs

See your match score for this role.

Xecodai maps the interview stages and shows what is preventing a 95% match.

Analyse this role