> Markdown version of [/jobs/ext/3076606-devsecops-platform-engineer](https://www.wearedevelopers.com/jobs/ext/3076606-devsecops-platform-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # DevSecOps Platform Engineer - **Company:** Cloudera - **Location:** Barcelona, Spain (Remote available) - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Application Programming Interfaces (APIs), Information Systems, Continuous Delivery, Continuous Integration, JSON, Key Management, Open Source Technology, OpenID, Regular Expressions, Policy as Code, Istio, Kubernetes, Information Technology, Hashicorp, Azure AKS, Api Gateway, Terraform, Devsecops - **Published:** September 25, 2026 - **Apply:** https://www.recruit.net/job/devsecops-platform-engineer-jobs/FCF927D5AA8E79EC ## About the Role correlation_id, process_id) across all network hops.GitOps Scaffolding & Linter Governance: Manage localized pull-based continuous delivery engines (ArgoCD) and construct automated structural linters to enforce the 10-Pillar Application Spoke Repository Standard across all engineering teams.We are excited if you have (Required Experience):Kubernetes & Container Security: 5+ years of deep experience operating production Kubernetes (Amazon EKS, Azure AKS) and container security frameworks.Education: Bachelor's degree in Computer Science, Engineering, Information Systems, or a related field or equivalent experience.Service Mesh & API Gateways: Advanced hands-on experience configuring Istio / Envoy service meshes, mTLS, custom ingress/egress routing, and edge API gateways.Policy-as-Code (Rego/OPA): Practical expertise writing custom Open Policy Agent (OPA) rules in Rego for pipeline gating, admission controllers, or access governance.Infrastructure-as-Code & GitOps: High proficiency with Terraform (modular structure design) and pull-based GitOps delivery tools (ArgoCD or Flux).Keyless Identity & Secrets Management: Hands-on experience with OIDC identity federation, HashiCorp Vault, and short-lived secret workflows.Distributed Observability: Strong understanding of OpenTelemetry (OTel) instrumentation, W3C trace context propagation, and log aggregation pipelines.You may also have:Familiarity with CI/CD linter construction for regular expression validation (Commit-as-Code).Background working within Hub-and-Spoke repository models and developer portal integrations.What you can expect from us:Generous PTO Policy Support work life balance with Unplugged DaysFlexible WFH Policy Mental & Physical Wellness programs Phone and Internet Reimbursement program Access to Continued Career Development Comprehensive Benefits and Competitive Packages Paid Volunteer TimeEmployee Resource GroupsEEO/VEVRAA#LI-EO1#LI-HYBRIDSummaryLocation: Hungary-Remote; Poland-Remote; Spain-Other-Remote; Czech Republic > Remote; Spain-Barcelona-Remote; Spain-Madrid-RemoteType: Full time ## Description AKS), enforce keyless workload identity, build zero-trust service mesh perimeters, and write active Policy-as-Code (OPA/Rego) pipelines.As a DevSecOps Platform Engineer, you will:Two-Tier IaC Platform Primitives: Design, provision, and maintain modular Terraform primitives and GitOps patterns for multi-cloud Kubernetes clusters (EKS/AKS), software-defined networks, and pod identity layers.Service Mesh & Edge Control Planes: Operate Istio/Envoy service mesh topologies across multi-gateway perimeters (Public Ingress, B2B Ingress, Egress).Active Policy-as-Code Gating: Author and maintain Open Policy Agent (OPA / Rego) policies to enforce pre-flight deployment checks, Commit-as-Code format verification, and dynamic Just-in-Time (JIT) time-bound access escalation gates.Out-of-Band Telemetry Exhaust: Configure OpenTelemetry (OTel) collectors and Envoy sidecar proxies to emit uniform out-of-band JSON telemetry logs, stamping W3C traceparent headers and system primary keys (UPID, USID