About The Position

We are looking for an Architect / Tech Lead who will be responsible for the technical direction of our Managed Service. You will design how our products run as a multi-tenant SaaS operation, from deployment to databases to application-level monitoring, and set the engineering standards that the team will follow. Our Application unit operates Managed Service products on the platform we run. openDesk is our first product, with more to follow; you will shape the architecture so that it remains sustainable across products. You are a senior individual contributor with technical leadership responsibility, but without disciplinary personnel management: you lead through architecture, reviews, ADRs, and mentoring, not through directives. You know the openDesk stack in depth (Nubus/Keycloak as IAM, OX App Suite, Nextcloud, Collabora, Jitsi, Element/Synapse, OpenProject, XWiki) and know how to deploy and operate these components reliably. We operate openDesk with tenant separation across multiple Kubernetes clusters: each customer receives their own namespaces for application, configuration, mail, and databases. You understand the boundary to the Platform team: clusters, network, and shared components like cert-manager, external-dns, external-secrets, Flux, kube-prometheus-stack, Thanos, Loki, and OpenBao are provided by the Platform team. You are responsible for the application layer on top, including the operators you run (CNPG, MariaDB-Operator, Keycloak-Operator), the databases, the application-specific secrets, and app-specific alerting. You also own the technical side of the ISO 27001 compliance of the service based on BSI IT-Grundschutz. On-call duty is part of the team. In an organization with 360-degree feedback, you will embody an open feedback culture.

Requirements

  • Several years of experience in the architecture and operation of complex, Kubernetes-based application landscapes as SaaS/Managed Service.
  • In-depth knowledge of the openDesk stack or comparable collaboration components (IAM/Keycloak/Nubus, Groupware, Nextcloud, Videoconferencing, Wiki/PM tools).
  • Confident use of Helm and Helmfile (multi-chart deployments, Helm-Diff, Values/Environments) as well as CI-driven rollout (e.g., GitLab CI) and GitOps (Flux).
  • Experience with database operation in Kubernetes via operators, ideally CNPG/CloudNativePG (PostgreSQL) and/or MariaDB-Operator, including backup/restore and PITR.
  • Experience with secret management (ExternalSecrets, Vault/OpenBao) and application-level monitoring/alerting (Prometheus ecosystem, Thanos, Loki).
  • Experience in IT Service Management according to ITIL: process design (Incident, Problem, Change, Release) and integration of CI/CD into ITSM processes.
  • Technical responsibility for information security according to ISO 27001 based on BSI IT-Grundschutz.
  • Sound Linux knowledge and willingness to participate in on-call duty.
  • German and English at business level (C1/C2) in spoken and written form.
  • Technical leadership without disciplinary responsibility: provide direction, convince, mentor.
  • Very good analytical and conceptual skills; you justify trade-offs comprehensibly.
  • Strong communication skills towards engineers, service owners, and the platform team.
  • Hands-on mentality: you can conceptualize and intervene yourself in an emergency.
  • Willingness to embody and solicit 360-degree feedback.

Nice To Haves

  • Specific productive experience with openDesk and its deployment repository (Helmfile structure, release/patch process).
  • Experience with multi-tenant SaaS operation (tenant isolation via namespaces, scaling, multi-customer migrations).
  • Knowledge of openDesk supporting services (Redis/Memcached, Object Storage, Mail/Postfix infrastructure, ClamAV/ICAP, Coturn).
  • Experience with multi-cluster operation and tenant separation.
  • Certifications (e.g., CKA/CKS, ITIL, ISO 27001 Lead Implementer/Auditor, BSI IT-Grundschutz Practitioner).
  • Experience in moderation, conflict resolution, and de-escalation.
  • Experience in training and knowledge transfer (trainings, workshops).

Responsibilities

  • You are responsible for the technical direction of the Managed Service: You design the target and deployment architecture for the multi-tenant openDesk SaaS operation across multiple clusters.
  • You set engineering standards and document decisions as ADRs; you conduct design and code reviews.
  • You design the Helmfile-based openDesk deployment (35+ Helm charts, Helm-Diff, Environments/Values) and its delivery via GitLab CI; supporting services are rolled out via GitOps where possible.
  • You are responsible for the database concept based on the operators you run (CNPG for PostgreSQL, MariaDB-Operator) including backup/restore and PITR.
  • You are responsible for application secret management via ExternalSecrets against OpenBao.
  • You define the application-level monitoring and alerting concept (openDesk-specific metrics, SLI/SLO for the service) based on the kube-prometheus-stack, Thanos, and Loki provided by the Platform team.
  • You own the technical side of ISO 27001 compliance based on BSI IT-Grundschutz: Security Context of openDesk, technical controls, evidence.
  • You design the IT Service Management processes of the service according to ITIL (Incident, Problem, Change, Release) and anchor them technically, including the integration of CI/CD into Change Management.
  • You define clear interfaces to the Platform team and make build-vs-buy decisions for the service.
  • You mentor the DevOps, Rollout, and Support Engineers and participate in on-call duty.

Benefits

  • Remote-First as a lived model
  • Flexible working hours with personal responsibility
  • Exciting projects instead of routine tickets
  • Further education, certifications & knowledge exchange
  • Modern equipment & work environment
  • Attractive conditions (fair fixed salary, annual profit sharing, option for company car)
  • Transparent feedback culture & development
  • Health, leisure & security (30 days vacation, group accident insurance)
  • Team culture & shared experiences
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service