Senior Platform Engineer/Kubernetes SME
Role details
Job location
Tech stack
Job description
- Own the design, build, and operations of a modular, API-first platform that abstracts infrastructure from simulation software
- Lead multi-cluster Kubernetes, service mesh, security hardening, and observability to support hundreds of users and tens of thousands of entities across connected and air-gapped environments
- Design and operate multi-cluster Kubernetes environments (control/data/CI/observability planes) with strong isolation and zero-trust defaults
- Implement service mesh (e.g., Istio) for mTLS, traffic control, and fine-grained AuthorizationPolicy; manage ingress (Gateway/VirtualService) and east-west policies
- Author and maintain platform CRDs and controllers/operators to reconcile developer intent into runtime objects (namespaces/cells, Deployments/Jobs, Services, policies, gateways)
- Integrate network policy (eBPF/Cilium), secrets management, RBAC/ABAC, and policy-driven automation across environments
- Stand up observability (metrics/logs/traces) and SLO monitoring; drive reliability (HA, backup/restore, DR)
- Support air-gap packaging/delivery and secure software supply chain (images, SBOMs, provenance)
- Active Top Secret clearance with SCI eligibility
Requirements
- 12+ years of Software Engineering experience with 5-8+ years in platform/SRE roles operating production Kubernetes at scale; strong multi-cluster and GitOps (Argo CD/Flux) experience
- Hands-on with Istio/Envoy, Cilium (NetworkPolicy, eBPF), Ingress/Gateway API, and cluster networking (DNS, L7/L4)
- Controller/operator development using Go (Kubebuilder/Operator SDK) or TypeScript-based frameworks; CRD design/versioning
- Observability: Prometheus, OpenTelemetry, Fluent Bit/OpenSearch; incident response and performance tuning
- Security: mTLS, OIDC, JWT, OPA/Gatekeeper/Kyverno (or equivalent), image signing, SBOM, CVE remediations, * Experience in air-gapped or classified environments; package and deploy with tools that support disconnected sites
- Exposure to Kubernetes Gateway/Envoy Gateway, egress control, and sidecar injection strategies
- Prior VV&A support for modeling & simulation platforms
- Ability to work across Unclassified ? Secret ? TS/SCI/SAP environments
Benefits & conditions
$187,700-$225,000
This range is for the Colorado Spring, CO area only.
$196,600-$218,400
This range is for the Lexington Park, MD, Maui, HI, & Carlsbad, CA areas only.
The offered rate will be based on the selected candidate's working location, knowledge, skills, abilities and/or experience, clearance level, contract affordability and in consideration of internal parity.
Additional Compensation
KBR may offer bonuses, commissions, or other forms of compensation to certain job titles or levels, per internal policy or contractual designation. Additional compensation may be in the form of sign on bonus, relocation benefits, short term incentives, long term incentives, or discretionary payments for exceptional performance.
Ready to Make a Difference?
If you're excited about making a significant impact in the field of space defense and working on projects that matter, we encourage you to apply and join our team at KBR. Let's shape the future together.
KBR Benefits
KBR offers a selection of competitive lifestyle benefits which could include 401K plan with company match, medical, dental, vision, life insurance, AD&D, flexible spending account, disability, paid time off, or flexible work schedule. We support career advancement through professional training and development.
Belong, Connect and Grow at KBRAt KBR, we are passionate about our people and our Zero Harm culture. These inform all that we do and are at the heart of our commitment to, and ongoing journey toward being a People First company. That commitment is central to our team of team's philosophy and fosters an environment where everyone can Belong, Connect and Grow. We Deliver - Together.