Track Lead - Azure DevOps, Terraform

HCLTech
Amsterdam, Netherlands
1 day ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Amazon S3 Apache HTTP Server Microsoft Azure Software as a Service Control Objectives for Information and Related Technology (COBIT) Linux Elasticsearch File Transfer Identity and Access Management Python (Programming Language) OpenShift Role-Based Access Control
+14 more
Remote Access Technology Ansible Prometheus Zero Trust Network Access Service Development Studio SQL Databases Data Logging Grafana Control Structures Git Kubernetes Infrastructure Automation Frameworks Apache Kafka Terraform

Job description

We are building a productized secure access platform that provides engineers across a global enterprise with interactive remote access (SSH/RDP via Apache Guacamole) and secure file transfer (S3 presigned URLs). The platform runs as a SaaS-style shared service on OpenShift with two environment-separated instances (Production and Non-Production), enforcing strict tenant isolation so each consuming team only accesses their own resources. As a Senior Platform Engineer, you will own the technical design, implementation, and operations of this platform. You will work at the intersection of security engineering, container orchestration, and infrastructure automation - building a service governed by an enterprise-approved reference architecture with direct security office oversight., Design and operate the interactive access service based on Apache Guacamole, containerized on OpenShift, translating HTTPS to native protocols (SSH, RDP, SQL, VNC) Build and maintain the file transfer service using S3 presigned URLs with time-bound expiry and tenant-scoped bucket/path access controls Engineer tenant isolation within shared SaaS-style deployments, ensuring each consuming team only accesses their own targets through predefined connections and network-level controls Design credential lifecycle automation: retrieval/seeding at session start, reset/removal at session stop, integrated with Privileged Access Management and credential stores Build session recording and logging pipelines shipping audit data to tenant-specified log repositories (Kafka, S3, Git) Implement metering and billing event generation for per-tenant consumption tracking Develop CI/CD pipelines for automated platform lifecycle management: provisioning, start, stop, decommissioning (immutable infrastructure / cattle model) Collaborate with security teams to refine detection scenarios every sprint and maintain audited control reporting (Seven IT Risk Controls, COBIT framework) Define and monitor SLIs/SLOs: start latency, session success rate, recording complete

Requirements

3+ years hands-on experience with Kubernetes/OpenShift in production (deployment, networking, RBAC, persistent storage, operators) Proficiency in Go and Python for platform service development, automation, and tooling Strong Linux systems engineering (SSH, networking, security hardening, systemd) Container orchestration and CI/CD pipeline design (Helm, ArgoCD, Tekton, or equivalent) S3-compatible object storage (MinIO or AWS S3): presigned URLs, bucket policies, IAM integration Azure DevOps for backlog management, CI/CD pipelines, and release workflows Infrastructure as Code: Terraform, Ansible, or equivalent Understanding of security principles: zero-trust, defence-in-depth, protocol insulation, MFA, credential management Experience with IAM systems, directory services integration, and conditional access policies Familiarity with logging and monitoring stacks (Kafka, Elasticsearch, Prometheus/Grafana)

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer · Coffee With Developers

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

10:40 min

Visualizing Prometheus open metrics using custom Grafana dashboards

Stijn Polfliet · LIVE

4:30 min

Transitioning from software engineering into a DevOps trajectory

Davide Imola Davide Imola · LIVE

56 sec

Favorite git commands and the importance of patch commits

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

9:06 min

Questions on career paths and continuous delivery orchestration platforms

Zan Markan Zan Markan · LIVE

Videos

See all

Related articles

See all