Job Summary
We are looking for a highly skilled Kubernetes Platform Engineer to design, operate, and optimize cloud-native infrastructure supporting mission-critical AI and enterprise workloads. The role involves managing Kubernetes platforms (EKS, AKS, GKE, or OpenShift), implementing Infrastructure as Code, building secure CI/CD pipelines, and ensuring the reliability, scalability, and security of cloud environments.
The ideal candidate will have deep hands-on expertise in Kubernetes, Docker, Helm, Terraform, cloud platforms (AWS/Azure/GCP), automation, and DevOps practices. You will be responsible for platform operations, cloud networking, workload identity, secrets management, storage, monitoring, and operational support for stateful services such as PostgreSQL, OpenSearch, and Keycloak.
Key Responsibilities
- Operate and maintain managed Kubernetes clusters (EKS/AKS/GKE/OpenShift) and the AIForce workloads on them — node pools, scheduling, autoscaling, upgrades.
- Own the Helm-based deployment model - manage multi-chart releases with layered value overrides across environments. Keep charts and container image versions (pinned by digest) consistent and auditable.
- Manage workload identity and secrets: cloud IAM and workload identity via OIDC (IRSA / Azure Workload Identity / GKE Workload Identity), the External Secrets Operator integrated with a cloud secret store (AWS Secrets Manager / Azure Key Vault / GCP Secret Manager) and HashiCorp Vault/OpenBao.
- Configure and troubleshoot Kubernetes networking: the CNI (pod IP / network-interface capacity planning), ingress controllers / reverse proxy, cloud load balancers, DNS and TLS termination.
- Manage persistent storage on Kubernetes: block and file storage via CSI drivers, StorageClasses and PVCs (RWO/RWX).
- Implement Infrastructure as Code with Terraform for cloud resources (Kubernetes supporting infra, managed databases, search, file storage, identity).
- Build and maintain CI/CD pipelines for container build, image scanning/signing and Helm-based deployment.
- Enforce Kubernetes security: RBAC, securityContext hardening, Pod Security Admission (and/or policy engines), image provenance and least-privilege access.
- Set up monitoring, logging, and alerting (Grafana + Prometheus and/or the platform's telemetry stack). Ensure availability, backup/DR and performance.
- Support the platform's stateful backends operationally: managed PostgreSQL, OpenSearch and Keycloak (SSO/OIDC).
- Troubleshoot deployment, networking, identity and data-connectivity issues across environments.
- Continuously improve reliability, automation and operational excellence.
Skill Requirements
Containers & Orchestration
- Docker (image build, optimization, registries)
- Kubernetes - deep, hands-on on at least one managed distribution (EKS/AKS/GKE/OpenShift), workloads, scheduling, RBAC, upgrades, debugging
- Helm - authoring/operating charts with multi-file value overrides
Cloud
- Strong hands-on experience with at least one major cloud (AWS, Azure or GCP) with a solid grasp of cloud IAM, networking/VPC, load balancing, DNS, block/file storage, managed databases, secret store, KMS etc
Kubernetes platform depth
- Networking: CNI, pod-IP/network capacity, ingress controllers/reverse proxy, load balancing, DNS, TLS
- Storage: CSI drivers, StorageClasses, PVCs
- Secrets: External Secrets Operator + a cloud secret store (and/or Vault/OpenBao)
- Security: RBAC, securityContext, Pod Security Admission
Infrastructure as Code
- Terraform (primary)
CI/CD
- One or more of GitHub Actions / GitLab CI / Jenkins / Azure DevOps, integrated with container build + Helm deploy
Scripting & OS
- Bash and Python (automation, YAML/JSON manipulation)
- Linux administration
Source Control
- Git (GitHub/GitLab/Bitbucket)
Other Requirements
- Multi-cloud experience across two or more of AWS/Azure/GCP and OpenShift
- Service mesh (Istio/Linkerd) and mTLS / in-cluster encryption
- Policy engines - Kyverno or OPA Gatekeeper. NetworkPolicies, pod-level security groups / network isolation
- KEDA / advanced autoscaling; cluster autoscaler / Karpenter (or equivalents)
- Keycloak / OIDC administration, API gateways
- DevSecOps — image scanning/signing, supply-chain security, vulnerability management
- FinOps / cloud cost optimization