DevSecOps Platform Engineer

Cloudera

Barcelona

Presencial

EUR 70.000 - 120.000

Jornada completa

hace 28 horas
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

Una candidatura hecha para este puesto de trabajo — un currículum y una carta de presentación adaptados que responden directamente a la oferta.

Supera los filtros ATS

Ventajas ofrecidas por este puesto de trabajo

PTO
Unplugged Days
Flexible WFH Policy
Mental & Physical Wellness programs
Phone and Internet Reimbursement
Continued Career Development
Comprehensive Benefits and Competitive
Paid Volunteer Time
Employee Resource Groups

Descripción de la vacante

Cloudera is seeking a DevSecOps Platform Engineer to build an Everything-as-Code operating platform for multi-cloud Kubernetes clusters with a strong focus on security and zero-trust principles.

You will design Terraform primitives, manage ArgoCD pipelines, and implement policy-as-code using OPA/Rego. You will also implement OpenTelemetry telemetry and Istio/Envoy service meshes to secure and observe deployments.

Formación

  • 5+ years of production Kubernetes (EKS/AKS) and container security experience.
  • Bachelor's degree in CS/Engineering or equivalent experience.
  • Advanced hands-on Istio/Envoy service mesh, mTLS, edge gateways.
  • Practical Rego/OPA policy-writing experience for gatekeeping.
  • Terraform and GitOps tooling (ArgoCD or Flux) proficiency.
  • Hands-on with OIDC identity federation and short-lived secrets.
  • OpenTelemetry instrumentation and log/trace pipelines knowledge.

Responsabilidades

  • Design, provision, and maintain Terraform primitives and GitOps patterns for multi-cloud Kubernetes clusters (EKS/AKS).
  • Operate Istio/Envoy service mesh topologies across multi-gateway perimeters.
  • Author and maintain OPA/Rego policies to gate deployments and access.
  • Configure OpenTelemetry collectors and Envoy proxies for telemetry data.
  • Manage ArgoCD-based delivery and enforce repository standards via linters.

Conocimientos

Kubernetes & Container Security
Policy-as-Code (Rego/OPA)
Infrastructure-as-Code & GitOps
Keyless Identity & Secrets Management
Distributed Observability

Educación

Bachelor's degree in Computer Science, Engineering, Information Systems, or a related field or equivalent experience

Herramientas

Terraform
ArgoCD
Flux
Istio/Envoy
Open Policy Agent (OPA)
Rego
HashiCorp Vault
OIDC

Descripción del empleo

Job Description

At Cloudera, we empower people to transform complex data into clear and actionable insights. With as much data under management as the hyperscalers, we're the preferred data partner for the top companies in almost every industry. Powered by the relentless innovation of the open source community, Cloudera advances digital transformation for the world's largest enterprises.

Business Area

IT

Seniority Level

Mid-Senior level

About the Team & Role

We are building an enterprise-grade, Everything-as-Code (EaC) Operating Platform that replaces manual IT operations with an automated, zero-trust software factory. As a DevSecOps Platform Engineer, you will be a core builder of our security, networking, and platform control planes.

Operating in an environment where all infrastructure, access policies, and network routing exist strictly as version-controlled text artifacts inside Git repositories, you will architect our multi-cloud Kubernetes foundations (AWS EKS / Azure AKS), enforce keyless workload identity, build zero-trust service mesh perimeters, and write active Policy-as-Code (OPA/Rego) pipelines.

As a DevSecOps Platform Engineer, you will:
  • Two-Tier IaC Platform Primitives: Design, provision, and maintain modular Terraform primitives and GitOps patterns for multi-cloud Kubernetes clusters (EKS/AKS), software-defined networks, and pod identity layers.
  • Service Mesh & Edge Control Planes: Operate Istio/Envoy service mesh topologies across multi-gateway perimeters (Public Ingress, B2B Ingress, Egress).
  • Active Policy-as-Code Gating: Author and maintain Open Policy Agent (OPA / Rego) policies to enforce pre-flight deployment checks, Commit-as-Code format verification, and dynamic Just-in-Time (JIT) time-bound access escalation gates.
  • Out-of-Band Telemetry Exhaust: Configure OpenTelemetry (OTel) collectors and Envoy sidecar proxies to emit uniform out-of-band JSON telemetry logs, stamping W3C traceparent headers and system primary keys (UPID, USID, correlation_id, process_id) across all network hops.
  • GitOps Scaffolding & Linter Governance: Manage localized pull-based continuous delivery engines (ArgoCD) and construct automated structural linters to enforce the 10-Pillar Application Spoke Repository Standard across all engineering teams.
We are excited if you have (Required Experience)
  • Kubernetes & Container Security: 5+ years of deep experience operating production Kubernetes (Amazon EKS, Azure AKS) and container security frameworks.
  • Education: Bachelor's degree in Computer Science, Engineering, Information Systems, or a related field or equivalent experience.
  • Service Mesh & API Gateways: Advanced hands-on experience configuring Istio / Envoy service meshes, mTLS, custom ingress/egress routing, and edge API gateways.
  • Policy-as-Code (Rego/OPA): Practical expertise writing custom Open Policy Agent (OPA) rules in Rego for pipeline gating, admission controllers, or access governance.
  • Infrastructure-as-Code & GitOps: High proficiency with Terraform (modular structure design) and pull-based GitOps delivery tools (ArgoCD or Flux).
  • Keyless Identity & Secrets Management: Hands-on experience with OIDC identity federation, HashiCorp Vault, and short-lived secret workflows.
  • Distributed Observability: Strong understanding of OpenTelemetry (OTel) instrumentation, W3C trace context propagation, and log aggregation pipelines.
You may also have
  • Familiarity with CI/CD linter construction for regular expression validation (Commit-as-Code).
  • Background working within Hub-and-Spoke repository models and developer portal integrations.
What you can expect from us
  • Generous PTO Policy
  • Support work life balance with Unplugged Days
  • Flexible WFH Policy
  • Mental & Physical Wellness programs
  • Phone and Internet Reimbursement program
  • Access to Continued Career Development
  • Comprehensive Benefits and Competitive Packages
  • Paid Volunteer Time
  • Employee Resource Groups
EEO/VEVRAA
Consigue la evaluación confidencial y gratuita de tu currículum.

o arrastra y suelta tu archivo aquí

Similar jobs

Puestos de trabajo similares que vale la pena comparar

DevSecOps Platform Engineer
DevSecOps Platform Engineer

Cloudera • Madrid

Híbrido
EUR 90.000 - 120.000
Generous PTO Policy
Unplugged Days
Flexible WFH Policy
+6
Sr. Staff Platform Operations Engineer
Sr. Staff Platform Operations Engineer

Cloudera • Madrid

Híbrido
EUR 90.000 - 125.000
Generous PTO Policy
Unplugged Days
Flexible WFH Policy
+6
Lead Data Mesh Engineer
Lead Data Mesh Engineer

Cloudera • Madrid

Presencial
EUR 90.000 - 130.000
Generous PTO Policy
Unplugged Days
Flexible WFH Policy
+4
Senior DevOps Engineer ID68699
Senior DevOps Engineer ID68699

AgileEngine • Madrid

Híbrido
EUR 60.000 - 85.000
Professional growth
Competitive compensation
Exciting projects
+1
DevSecOps Platform Engineer — IaC & Zero-Trust Automation
DevSecOps Platform Engineer — IaC & Zero-Trust Automation

Cloudera • Madrid

Híbrido
EUR 90.000 - 120.000
Generous PTO Policy
Unplugged Days
Flexible WFH Policy
+6
DevOps Engineer (Senior) ID46624
DevOps Engineer (Senior) ID46624

AgileEngine • Madrid

Presencial
EUR 40.000 - 60.000
Professional growth including mentorship
Competitive USD-based compensation
Exciting projects with Fortune 500 companies
+1
Zero-Trust DevSecOps Platform Engineer — Remote
Zero-Trust DevSecOps Platform Engineer — Remote

Cloudera • Barcelona

Presencial
EUR 70.000 - 120.000
PTO
Unplugged Days
Flexible WFH Policy
+6
Forward Deployed AI Engineer (Senior/Principal Level) - based in Czechia/Poland/Spain
Forward Deployed AI Engineer (Senior/Principal Level) - based in Czechia/Poland/Spain

Cloudera • Barcelona

Híbrido
EUR 90.000 - 130.000
Generous PTO Policy
Flexible WFH Policy
Mental & Physical Wellness programs
+5
Platform Engineer
Platform Engineer

Holcim Supplementary Pension Fund • Madrid

Presencial
EUR 75.000 - 100.000
Platform Engineer
Platform Engineer

Ilkari • Málaga

Presencial
EUR 55.000 - 75.000
Life and health insurance
Gym reimbursement
Learning Pocket budget
+4