The specialists that run the thing, prove it survives, and break it on purpose before an outage does.
infra-engineer
Terraform and AWS, Docker images and Kubernetes manifests, GitHub Actions CI with supply-chain hardening (OIDC, SHA pinning), ArgoCD delivery, Vault secrets, and multi-region failover architecture. Encodes and tests the Sentinel policies that gate every plan.
Skills
- tf-module-authoring
- k8s-production-manifests
- gitops-cicd-pipeline
- sentinel-policy-authoring
- vault-secrets-management
sre-engineer
Prometheus metrics and alert rules, Grafana dashboards as code, Traefik ingress, OpenTelemetry pipelines, and logs through CloudWatch, Elastic, or Loki. Replaces static thresholds with multi-window burn-rate alerts, and works incidents from evidence rather than hunches.
Skills
- service-observability-bundle
- slo-burn-rate-alerts
- incident-investigation
- traefik-service-exposure
network-engineer
VPC and subnet topology, routing and egress, load balancer selection and configuration, security groups, Route 53, and Kubernetes NetworkPolicies. Owns "A can't reach B" — debugged layer by layer with recorded evidence, not by widening a security group until it works.
Skills
- vpc-topology-design
- connectivity-triage
- k8s-network-policies
- alb-nlb-exposure
ops-engineer
Where an alert actually lands: PagerDuty services, escalation policies and humane on-call rotations as Terraform, Slack and email routing, dedup and grouping — and incident communications while something is on fire. Proves each path with a synthetic alert.
Paging real humans, like sending real email, needs explicit approval.
Skills
- alert-routing-setup
- oncall-escalation-design
- incident-comms-runbook
chaos-engineer
Turns resilience claims into falsifiable AWS FIS experiments — numeric hypothesis, measured baseline, CloudWatch stop conditions, an abort path — then measures real RTO and RPO against what the architecture promises. Runs game days with named human roles.
Experiments are designed by default; running one against any environment needs recorded approval.
Skills
- fis-experiment-design
- game-day-runbook
- dr-validation
security-engineer
Audits code and infrastructure against the OWASP Top 10 (2025), API and LLM/Agentic lists included. Triages CVEs by KEV and EPSS rather than CVSS alone, reviews AI-agent systems for prompt injection, excessive agency, and MCP supply-chain risk, and defines the requirements behind the Sentinel policies infra-engineer encodes.
Skills
- security-audit
- dependency-cve-triage
- agent-security-review
- sentinel-policy-requirements