102854 – Sr. Kubernetes Platform Engineer

Summary

We’re seeking a Senior Kubernetes Platform Engineer to own the design, security, and day-2 operations of our Azure Kubernetes Service (AKS) platform. This is a deep Kubernetes role focused on cluster administration, networking, ingress/egress control, service mesh, automation via GitOps, and observability for production containerized workloads. The role is hands-on and central to ensuring clusters and services are secure, resilient, and ready for production traffic.

Responsibilities

  • Design, build, and operate AKS clusters including bootstrapping, configuration, upgrades, and node/pod lifecycle management.
  • Manage Kubernetes networking, ingress and egress traffic control, HTTPS ingress controllers, and TLS certificate management for per-service routing.
  • Implement and operate service mesh technologies such as Istio and Envoy to enable secure, observable service-to-service communication.
  • Implement authentication and authorization for user and machine access, design and maintain RBAC policies, and enforce pod-level security controls.
  • Configure and operate scaling mechanisms including Horizontal Pod Autoscaler, Cluster Autoscaler, and Azure Container Instance integration for burst scenarios.
  • Manage containerized workloads (Pods, Deployments, Services, ConfigMaps, selectors) and support application teams in deploying to AKS.
  • Build and maintain CI/CD and GitOps workflows using Terraform, Flux, Helm, and Kustomize to provision infrastructure and deploy applications across environments.
  • Manage secrets, certificates, managed identities, and service principals; enforce container image security standards for images from Azure Container Registry.
  • Integrate and maintain observability tooling and routing of application, cluster, and diagnostic logs into Azure Event Hub/Storage and monitor runtime with Dynatrace and/or Prometheus.
  • Scan, monitor, and remediate vulnerabilities across images, hosts, registries, and runtime; provide operational support and incident response for cluster issues.
  • Expand the internal Platform-as-a-Service offering by creating reusable deployment templates and automation to reduce time to market for application teams.
  • Provide hands-on guidance, best-practice designs, and operational support to application teams to ensure clean, secure, and reliable operation on AKS.

Requirements

  • 5+ years administering production Kubernetes, with 3+ years on Azure Kubernetes Service (AKS).
  • Complete working understanding of the Kubernetes networking model.
  • Experience with AKS bootstrapping, build, configuration, upgrades, and operational support across clusters, nodes, and pods.
  • Experience with manual and automated scaling: Horizontal Pod Autoscaler, Cluster Autoscaler, and Azure Container Instance (ACI) integration.
  • Experience implementing authentication and authorization for user and machine access to clusters and designing RBAC.
  • Experience enforcing pod-level security controls and node-to-node encryption.
  • Hands-on management of containerized workloads: Pods, Deployments, Services, ConfigMaps, and selectors.
  • Prior experience standing up Linux and/or Windows clusters from the Azure CLI.
  • Deep experience with Kubernetes ingress and egress traffic control, HTTPS ingress controllers, and TLS certificate management.
  • Production service mesh experience with Istio and Envoy.
  • Strong Azure networking fundamentals as they apply to AKS cluster connectivity.
  • 5+ years building and running microservices and containerized systems with event-driven architectures and focus on scalability and security.
  • 2+ years building CD automation via Terraform and Flux following GitOps practices; experience with Helm and Kustomize.
  • Experience with Infrastructure as Code, preferably Terraform.
  • Experience building and managing GitHub build and release pipelines across Dev, Stage, and Production environments.
  • Production experience with Dynatrace and/or Prometheus.
  • Experience routing AKS application, event, cluster, user activity, and diagnostic logs into Azure Event Hub/Storage for monitoring.
  • Experience building reusable deployment templates that enable application teams to deploy or provision AKS environments consistently.

Nice to Have

  • Familiarity with security and compliance frameworks such as NIST, FedRAMP, CSA, or ISO container/cloud standards.
  • Experience with governance and scanning tooling such as Wiz, Arnica, or SonarQube.
  • Familiarity with Kusto (KQL) for log querying.
  • Experience with Azure serverless.
  • Experience with Azure SQL Server, MongoDB, or PostgreSQL.
  • Experience with Crossplane.Experience with REST APIs and Swagger/OpenAPI.
Job Type: Remote
Allowed Country: Argentina Brazil Colombia Costa Rica Peru

Solicitar este puesto

Maximum allowed file size is 50 MB. Allowed type(s): .pdf