Kubernetes Engineer

Stefanini
Charlotte, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Automation of Tests Microsoft Azure Bash Shell Cloud Computing Disaster Recovery Domain Name System (DNS) Github Subnetting Python (Programming Language) Key Management Log Analysis
+20 more
Network Architecture Open Service Interface Definitions OpenID Role-Based Access Control Google Cloud Software Modules Load Balancing Istio Infrastructure as Code (IaC) Git Flow Kubernetes Deployment Automation Linkerd (Service Mesh) Azure AKS Azure Service Fabric Terraform Software Version Control Dynatrace AWS EKS Docker

Job description

We are seeking an experienced Kubernetes Engineer/Administrator. This role focuses on managing and scaling our enterprise-grade Azure Kubernetes Service (AKS) infrastructure. You will be responsible for designing, implementing, and maintaining production Kubernetes clusters that support critical enterprise workloads across multiple Azure regions.

Primary ResponsibilitiesAzure Kubernetes Service (AKS) ManagementDesign, deploy, and manage enterprise-scale AKS clusters across multiple Azure regionsImplement and maintain private AKS clusters with advanced networking configurationsConfigure and manage customer-managed encryption keys (CMK) for cluster disk encryptionImplement blue/green deployment strategies for zero-downtime cluster upgradesManage AKS cluster lifecycle including upgrades, node pool scaling, and disaster recoveryOptimize cluster performance, cost, and resource utilizationImplement AKS Fleet Manager for multi-cluster management and orchestrationConfigure AKS Automatic for simplified cluster operations and auto-scalingManage AKS Managed Namespaces for improved multi-tenancy and resource isolation

Security & ComplianceImplement and maintain private networking architectures with Azure Private EndpointsConfigure and manage Workload Identity (OIDC) and user-assigned managed identitiesIntegrate Azure Policy for governance, compliance, and security enforcementImplement Kubernetes RBAC and Azure RBAC integrationManage secrets integration with Azure Key Vault using CSI driversEnsure secure communication between AKS and Azure PaaS servicesImplement network policies and pod security standards

Service Mesh & Advanced NetworkingDeploy and manage Linkerd service mesh for secure service-to-service communicationImplement mTLS between services with automatic certificate rotationConfigure traffic splitting, load balancing, and observability with LinkerdTroubleshoot service mesh networking and performance issuesIntegrate service mesh metrics with Azure Monitor

Infrastructure as Code (IaC)Develop and maintain Terraform modules for AKS and supporting Azure infrastructureBuild reusable, production-ready Terraform patterns following Azure best practicesImplement infrastructure automation and GitOps workflowsManage Terraform state, version control, and module lifecycleCreate and maintain comprehensive documentation for infrastructure patterns

GitOps & CI/CDDesign and implement GitOps workflows using ArgoCD for application deploymentsBuild and maintain CI/CD pipelines using GitHub Actions for Kubernetes workloadsIntegrate AKS with Azure Container Registry (ACR) for container image managementImplement automated testing and validation for infrastructure and application changesManage deployment strategies (rolling updates, blue/green, canary)Maintain GitHub Actions workflows for infrastructure provisioning and testing

Azure Platform IntegrationIntegrate AKS with Azure services includingConfigure and maintain private endpoints for all Azure servicesImplement VNet integration and subnet delegation patternsDesign and implement service connectivity across Azure regions

Monitoring, Observability & OperationsImplement comprehensive monitoring and alerting with Azure MonitorConfigure Log Analytics workspaces and integrate with AKSBuild dashboards and alerts for cluster health, performance, and securityLeverage Linkerd metrics and distributed tracing for service observabilityTroubleshoot complex cluster, networking, and application issuesConduct capacity planning and cost optimizationParticipate in on-call rotation for production supportPerform post-incident analysis and implement preventive measures, Platform Engineering ExperienceBuilding internal developer platforms on KubernetesPolicy-as-code implementation (Azure Policy, OPA, Kyverno)Cost optimization and FinOps practices for KubernetesChaos engineering and reliability testingMulti-region disaster recovery patterns

Requirements

Required QualificationsTechnical Skills - Azure & Kubernetes5+ years of hands-on Kubernetes experience in production environments2+ years of Azure Kubernetes Service (AKS) experience requiredStrong Terraform expertise with proven ability to build reusable, production-ready modulesDeep understanding of Kubernetes architecture, networking, storage, and securityExperience with private AKS clusters and Azure Private Link/Private EndpointsProficiency with Azure networking: VNets, subnets, NSGs, private DNS zones, VNet peeringStrong understanding of Azure managed identities, Workload Identity, and RBACExperience with Azure Key Vault integration (CSI driver, disk encryption sets)Hands-on experience with customer-managed encryption keys in AzureExperience with Azure Container Registry including geo-replication and vulnerability scanningKnowledge of AKS advanced features (Fleet Manager, AKS Automatic, Managed Namespaces) isa plus

Infrastructure as Code & AutomationAdvanced Terraform skills with module development experienceGit version control and branching strategies (GitHub)GitOps tools: ArgoCDGitHub Actions for CI/CD pipelinesInfrastructure testing and validation practices

Platform & ToolsAzure CLI and Azure PowerShellkubectl, helm, kustomizeLinux system administrationScripting: Bash, Python, or PowerShellContainer technologies: Docker, containerdGitHub workflows and Actions

Soft SkillsStrong analytical and troubleshooting abilitiesExcellent documentation skills with focus on knowledge sharingCollaborative team player with mentoring capabilitiesEffective communication for both technical and business audiencesSelf-motivated with ability to manage complex projects

Preferred QualificationsAdvanced Kubernetes & Cloud SkillsCertified Kubernetes Administrator (CKA) or Certified Kubernetes Security Specialist (CKS)Experience with Linkerd service mesh - deployment, configuration, and troubleshootingExperience with AKS Fleet Manager for multi-cluster orchestrationFamiliarity with AKS Automatic and managed namespace patternsExperience with Kubernetes operators and Custom Resource Definitions (CRDs)Service mesh implementations (Linkerd preferred; Istio, Open Service Mesh)Advanced CNI configurations (Azure CNI, Calico, Cilium)Multi-cluster management and federationExperience with other cloud platforms (Google Cloud Platform GKE, AWS EKS) is a plus, Required QualificationsTechnical Skills - Azure & Kubernetes5+ years of hands-on Kubernetes experience in production environments2+ years of Azure Kubernetes Service (AKS) experience requiredStrong Terraform expertise with proven ability to build reusable, production-ready modulesDeep understanding of Kubernetes architecture, networking, storage, and securityExperience with private AKS clusters and Azure Private Link/Private EndpointsProficiency with Azure networking: VNets, subnets, NSGs, private DNS zones, VNet peeringStrong understanding of Azure managed identities, Workload Identity, and RBACExperience with Azure Key Vault integration (CSI driver, disk encryption sets)Hands-on experience with customer-managed encryption keys in AzureExperience with Azure Container Registry including geo-replication and vulnerability scanningKnowledge of AKS advanced features (Fleet Manager, AKS Automatic, Managed Namespaces) is a plus

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:16 min

Managing large deployments and staging environments

Alexander Bubeck · WWC 2023

2:53 min

Configuring dynamic proxy updates with Istio Pilot

Jan Mensch Jan Mensch · WWC Europe 2026

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · WWC 2025

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · WWC 2023

1:39 min

Introduction to Kubernetes security challenges and opportunities

Marc Nimmerrichter · WWC 2022

7:15 min

Installing Istio programmatically with bash scripts

Thomas Südbröcker · LIVE

Videos

See all

Related articles

See all