Principal Kubernetes Platform Engineer
Job Description
REQUIREMENTS
- Kubernetes — deep knowledge of node groups, OIDC provider, Pod Identity/IRSA, cluster autoscaler, and EKS upgrade operations
- Helm — multi-environment chart authoring, value layering strategies, Helmfile or ArgoCD-based GitOps delivery; experience converting AKS/Azure chart patterns to AWS EKS equivalents
- Security — IRSA design, KMS CMK policies, Secrets Manager, External Secrets Operator, Pod Security Standards, Network Policies, and PCI DSS compliance; experience operating under regulatory security standards
- Networking — VPC design, private subnets, ALB ingress controller, ACM certificate management, Route 53, External-DNS, PrivateLink for internal AWS service endpoints, and security group design
- Container Platform — ECR image registry management, image scanning, multi-stage Dockerfile practices, non-root container enforcement, read-only root filesystem, and supply chain security
- CI/CD & GitOps — Jenkins pipeline authoring, Bitbucket/GitHub pull request workflows, ArgoCD or Flux, feature branch strategies, and pre-push security gate enforcement
- Observability — CloudWatch Container Insights, AWS Distro for OpenTelemetry (ADOT), Prometheus, Grafana, and distributed tracing on EKS
Preferred
- AWS CDK (TypeScript) — authoring CDK L3 constructs and infrastructure-as-code best practices for EKS, MSK, RDS, DynamoDB, S3, and Secrets Manager
- Kafka / Streaming — operating Kafka on Kubernetes, topic management, consumer group operations, and TLS/SASL authentication
- Database Operations — exposure to PostgreSQL (RDS/Aurora), DynamoDB, and Redis Enterprise in a Kubernetes or managed AWS environment
- Application Background — familiarity with polyglot microservice environments (Rust, Go, Java/Flink, C++); ability to read and advise on Dockerfiles, gRPC/protobuf service contracts, and multi-language build pipelines
- ML Platform Awareness — basic familiarity with SageMaker, Bedrock, or MLflow workloads running on EKS is a plus
RESPONSIBILITES
- Own and operate the AWS EKS cluster, upgrades, node groups, managed add-ons, cluster logging, and capacity planning
- Author, maintain, and review Helm charts for application services, infrastructure (Kafka, Redis, PostgreSQL), and observability layers
- Design and implement IAM/IRSA roles, KMS key policies, and Secrets Manager integration per workload, following least-privilege principles
- Enforce platform security standards, Pod Security Standards, Network Policies, container hardening, and PCI DSS 3.2.1 compliance gates in CI pipelines
- Manage ECR image registry, scanning policies, base image governance, and lifecycle rules
- Build and maintain AWS CDK infrastructure constructs for EKS, MSK, S3, RDS, DynamoDB, Secrets Manager, VPC, and supporting services
- Define and operate ingress patterns, AWS ALB, ACM certificates, Route 53 DNS, and External Secrets Operator for secrets delivery
- Lead platform security reviews and ensure all infrastructure changes are validated against organisational compliance standards before deployment
- Collaborate with application engineering teams across Rust, Go, Java, and C++ services to onboard workloads, review resource configurations, and resolve platform-level issues
- Drive GitOps delivery practices via ArgoCD, CI/CD pipeline integration, and feature branch release workflows
- Define and document platform standards, runbooks, and onboarding guides for the engineering team
- Act as the platform SME, mentoring engineers, leading design discussions, and making architectural decisions for the AWS platform layer
Are you interested in this position?
Apply by clicking on the “Apply Now” button below!
#CrossChannelJobs #JobSearch
#CareerOpportunities #HiringNow
#Employment #JobOpenings
#JobSeekers