Embedded DevOps EngineerFull-time
PiNTeam · Garching
- Optimized GitLab CI/CD pipelines — Docker Bake, JUnit XML test reporting, and merge-request templates — cutting build ramp-up time.
- Established GitLab governance across multiple teams — golden merge-request and repository rules, automated mandatory-reviewer assignment, and a Premium-vs-Free cost-optimization analysis — and authored the supporting guidelines.
- Designed and shipped modular, pip- and .exe-distributable Python CLI tooling (PyInstaller, Nuitka, pip-tools, uv) published to an internal Nexus, maintaining supported Python versions via dependency analysis.
- Built and scaled DHCP infrastructure with Kea DHCP containers, BIND9, and KEA DDNS over bonded VLANs, including static IP reservations and per-VLAN scaling.
- Deployed a Dockerized RDP Gateway (rdpgw) integrated with Microsoft Entra ID (OIDC) for MFA-secured remote access.
- Configured NGINX (HTTP-to-HTTPS redirection, routing) and self-hosted noVNC with WebSocket access restricted to setup owners.
- Owned Windows endpoint provisioning end-to-end — PowerShell automation, package installation, Windows/WSL integration, Microsoft Intune management, and unattended installation with Autopilot enrollment (Unattend.xml).
- Extended internal infrastructure libraries and APIs (browser namespace, vm_switch_setup endpoint, SPICE/proxy configuration, VM IP/hostname mapping) and added Selenium-based authentication across Chrome, Edge, and Firefox.
- Built a status page and admin dashboard to monitor and control hardware setups (including remote power control), and authored the company-wide AI usage policy.