Get more replies from employers
Send a job-specific resume in minutes.
SYNKCODE FZCO in Dubai seeks a Senior Network, Security & Platform Architect/Engineer to design and manage robust Kubernetes networking, ensure high availability, and minimize latency across enterprise platforms.
You will implement granular security policies (CNI, Network Policies, Istio/Linkerd), manage Ingress, Vault-based secrets, and integrated firewalls and WAFs, while guiding DMZs, VLANs, and virtualized RHEL/KVM environments.
Design implement and manage robust network architectures within Kubernetes clusters ensuring high availability and low latency
Develop and enforce granular network security policies using Kubernetes Network Policies Calico or other CNI-specific security features
Configure and maintain Ingress controllers and service meshes e g Istio Linkerd for secure and efficient traffic management
Implement and manage secrets management solutions e g HashiCorp Vault Kubernetes Secrets to protect sensitive data
Bachelor's or Master's degree in Computer Science, Information Technology, or a related field.
5+ years of experience in network engineering and cybersecurity, with at least 2 years focused on Kubernetes.
Proven expertise in Kubernetes networking concepts (CNI, Services, Ingress, Network Policies).
Hands-on experience with security tools and practices like firewalls, IDS/IPS, WAFs, and vulnerability scanning.
Develop high-level and low-level network designs for segmented enterprise platforms.
Design inbound and outbound DMZs, trusted application zones, and management, operations, backup, and datanetworks.
Define VLANs, subnets, gateways, route tables, firewall boundaries, NAT, DNS, and IP-address allocations.
Apply default-deny segmentation and permit only approved source, destination, protocol, and port combinations.
Prepare architecture diagrams, traffic flows, communication matrices, allocation registers, and implementation records.
Design and administer RHEL-based KVM environments, Open vSwitch or Linux bridges, and VLAN-backed virtualinterfaces.
Create isolated hypervisor-only networks and map VM interfaces to approved bridges, VLANs, and port groups.
Implement virtual firewall and Layer 3 routing services while separating management from application traffic.
Design separate public-facing and private Kubernetes worker groups and enforce appropriate workload placement.
Implement default-deny NetworkPolicies, namespace isolation, controlled service/DNS exposure, and explicit ingress andegress.
Protect control-plane and node-management interfaces and prevent workloads from bypassing approved gateways andfirewalls.
Design and operate APISIX gateways for inbound, internal, and outbound API traffic.
Configure authentication, authorization, mTLS, request validation, rate limits, allowlists, routing policies, tracing, and auditlogs.
Configure NGINX reverse and egress proxies with approved upstreams, methods, paths, headers, and externaldestinations.
Integrate gateways and proxies with firewalls, Kubernetes services, DNS, NAT, certificates, monitoring, and centralizedlogging.
Page 1Senior Network, Security & Platform Architect/Engine