Senior / Principal Kubernetes Platform Architect

Il y a 4 semaines

Luxembourg Cyberr Temps plein
Senior / Principal Kubernetes Platform Architect

Location:
Luxembourg Languages : English Responsibilities Design the overall architecture of a production-grade Kubernetes as a Service (KaaS) platform for multiple customers. Define the multi-tenancy, isolation, networking, storage, security and high-availability strategy. Design and automate the complete Kubernetes cluster lifecycle: provisioning, scaling, upgrades, recovery and decommissioning. Define the platform's Day-2 operations, monitoring, incident management, backup and Disaster Recovery processes. Design secure IAM, RBAC, encryption, PKI and Key Management architectures suitable for regulated customers. Define the Infrastructure as Code / GitOps approach and ensure the platform is reproducible and auditable. Evaluate build vs buy and recommend the most appropriate Kubernetes components and technologies. Contribute hands-on to the PoC, MVP and production implementation of the platform. Produce architecture documentation, operational runbooks and security recommendations. Transfer knowledge and train internal teams to operate and maintain the platform independently. Technical Requirements Expert-level Kubernetes experience in production, including control plane, etcd, HA, node management, upgrades and cluster recovery. Proven experience building or operating Kubernetes platforms for multiple customers/teams, ideally in CSP, MSP, telecom, hosting, sovereign cloud or regulated environments. Strong expertise in Cluster API or equivalent cluster lifecycle management; Rancher, Gardener, Kubermatic or OpenShift are a plus. Strong knowledge of multi-tenancy and isolation: RBAC, quotas, network policies, Pod Security, admission policies and dedicated workloads. Advanced Cilium / eBPF expertise: NetworkPolicy, Hubble, BGP, Gateway API, LoadBalancers and Cluster Mesh. Strong knowledge of datacenter networking: VLAN, VXLAN/EVPN, BGP, routing, firewalls, NAT and load balancing. Strong expertise in Kubernetes storage, ideally Ceph / Rook / Ceph CSI, as well as Longhorn or equivalent CSI solutions. Strong knowledge of encryption and Key Management: TLS/mTLS, WireGuard, IPsec, KMS, Vault, HSM, BYOK and encryption at rest. Strong Kubernetes security knowledge: CIS, OIDC, least privilege, Kyverno/OPA, image security, SBOM, signing and runtime security. Strong expertise in Terraform/OpenTofu, Ansible, Helm, Kustomize, GitOps, Argo CD/Flux and CI/CD. Experience with Prometheus, Grafana, Loki, OpenTelemetry, Hubble and production observability. Experience with Velero/Kasten, backup, RPO/RTO and Disaster Recovery. Knowledge of metering/chargeback solutions such as OpenCost or Kubecost is a plus. Experience with ISO 27001, DORA, CSSF/PSF, PCI-DSS or other regulated environments is highly valued. CKA/CKS certifications are a plus but hands-on production experience is mandatory. Interested in this opportunity? Feel free to apply or send us your updated CV to anne-catherine.son@cyberr.ai or morgane.zimmer@cyberr.ai