> Markdown version of [/jobs/ext/2102563-platform-engineer](https://www.wearedevelopers.com/jobs/ext/2102563-platform-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Platform Engineer - **Company:** Businessdevelop - **Location:** Paisley, UK - **Experience:** Expert - **Salary:** £110,500.0 - £117,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Code Review, Data Structures, Distributed Systems, Domain Name System (DNS), Identity and Access Management, PostgreSQL, OAuth, Online Transaction Processing, OpenID, Akamai, Security Assertion Markup Language (SAML), Session Management, Session Manager SubSystems, Security Information and Event Management, TypeScript, WebSocket, ReactJS, Kubernetes Helm Charts, Firewalls (Computer Science), Kubernetes, Information Technology, Low Latency, Cloudflare, Apache Kafka, Bitbucket, Functional Programming, Akamai ION, Api Gateway, Splunk, Grpc, Dynatrace - **Published:** August 18, 2026 - **Apply:** https://www.apply4u.co.uk/jobs/x/44235574/ ## About the Role BS/MS degree in Computer Science, related technical field, or equivalent with 8+ years of industry experience5+ years hands-on experience with Envoy Proxy (xDS/ADS, ext_authz, HTTP/2, gRPC, WebSocket) and/or Kong API Gateway (plugin development, DB-less mode, Admin API)Strong Go development skills - control-plane services, gRPC APIs, Kubernetes controllers (client-go), concurrency patternsProduction Kubernetes experience (EKS and/or on-prem clusters) - Helm charts, HPA, PodDisruptionBudgets, NetworkPolicy, namespace isolation, ArgoCD GitOpsDeep understanding of OAuth 2.0 / OIDC / PKCE flows, DPoP sender-constrained tokens, mTLS, and session management patternsExperience with OPA (Open Policy Agent) policy authoring in Rego and sidecar deployment patternsHands-on with OpenTelemetry (traces, metrics, logs), Dynatrace, and Splunk SIEM integrationWorking knowledge of CDN/WAF platforms (Akamai Ion, Kona, Cloudflare) and WAF-as-code automationExperience with PostgreSQL (HA, connection pooling, PITR) and Kafka (MSK, Schema Registry, DLQ patterns)Familiarity with DNS steering (GeoDNS, Akamai GTM, health-check routing) and TLS certificate lifecycle (cert-manager, HSM/KMS)Strong CS fundamentals - networking (L3-L7), distributed systems, data structures & algorithmsExperience building high-volume, low-latency, resilient infrastructure services Nice to have:TypeScript/React experience for operator dashboard developmentAWS infrastructure experience (EKS, MSK, Lambda, Direct Connect, Network Firewall)Bitbucket Pipelines CI/CD and GitOps delivery workflowsExperience with CAEP (Continuous Access Evaluation Protocol) or similar session revocation mechanismsBackground in identity platforms (ForgeRock, SAML federation, token exchange patterns) ## Description Day-to-day responsibilities:Design, build and operate Envoy and Kong gateway infrastructure serving production traffic across multiple lines of businessDevelop Go-based control-plane services - Ingress Registry, xDS controllers, Session Manager, Context PropagatorImplement and maintain OPA policy bundles for coarse-grained authorization at the gateway layerBuild and extend OpenTelemetry instrumentation pipelines (OTel Collector, Dynatrace OTLP ingest, Splunk SIEM forwarding)Manage GitOps-driven deployments via ArgoCD and Helm across multi-cluster Kubernetes environmentsAutomate WAF rule management across Akamai and Cloudflare using WAF-as-code patternsContribute to the platform operator console (TypeScript/React) for route management, drift detection, and session visibilityCollaborate with LOB teams to onboard routes and migrate traffic from legacy ingress infrastructureParticipate in incident response, runbook development, and production readiness reviewsChampion software engineering best practices - code review, testing, documentation, and observability-first design ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Exploring the Power of gRPC-Gateway for Writing RESTful Services](https://www.wearedevelopers.com/videos/2072-exploring-the-power-of-grpc-gateway-for-writing-restful-services) - [How I saved 200K/yr in direct costs writing 0 code lines in K8s](https://www.wearedevelopers.com/videos/1055-how-i-saved-200k-yr-in-direct-costs-writing-0-code-lines-in-k8s) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Boosting OpenSearch Performance: gRPC Search in Action](https://www.wearedevelopers.com/videos/1964-boosting-opensearch-performance-grpc-search-in-action) ## Related Articles - [Envoy Proxy: Documentary Overview](https://www.wearedevelopers.com/magazine/235-envoy-proxy-documentary-overview) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 131 - AI'm not sure about OSS](https://www.wearedevelopers.com/magazine/472-dev-digest-131-ai-m-not-sure-about-oss) - [Dev Digest 139 - Soft and hard queries](https://www.wearedevelopers.com/magazine/487-dev-digest-139-soft-and-hard-queries)