DevSecOps Platform Engineer

Cloudera

Kalisz

On-site

PLN 180,000 - 260,000

Full time

8 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Generous PTO
Flexible WFH
Wellness program
Reimbursement for phone/internet
Career development
Benefits package

Job summary

Cloudera is seeking a DevSecOps Platform Engineer to build an enterprise-grade, Everything-as-Code operating platform. Design and maintain multi-cloud Kubernetes foundations (AWS EKS / Azure AKS), enforce keyless workload identity, and implement zero-trust service mesh perimeters.

You will work with IaC primitives, GitOps (ArgoCD/Flux), Open Policy Agent (Rego), and telemetry pipelines to shape policy-gated deployment and secure infrastructure across environments.

Qualifications

  • Bachelor’s degree in Computer Science, Engineering, Information Systems, or a related field or equivalent experience.
  • 5+ years of deep experience operating production Kubernetes (Amazon EKS, Azure AKS) and container security frameworks.
  • Advanced hands-on experience configuring Istio / Envoy service meshes, mTLS, and edge API gateways.
  • Practical expertise writing Open Policy Agent (OPA) rules in Rego for gating, admission controllers, or access governance.
  • High proficiency with Terraform (modular structure design) and pull-based GitOps tools (ArgoCD or Flux).
  • Hands-on experience with OIDC identity federation, HashiCorp Vault, and short-lived secret workflows.

Responsibilities

  • Two-Tier IaC Platform Primitives: Design, provision, and maintain modular Terraform primitives and GitOps patterns for multi-cloud Kubernetes clusters (EKS/AKS).
  • Service Mesh & Edge Control Planes: Operate Istio/Envoy service mesh topologies across multi-gateway perimeters (Public Ingress, B2B Ingress, Egress).
  • Policy-as-Code Gating: Author and maintain Open Policy Agent (OPA / Rego) policies to enforce pre-flight deployment checks and time-bound access gates.
  • Out-of-Band Telemetry Exhaust: Configure OpenTelemetry collectors and Envoy sidecar proxies to emit telemetry logs across network hops.
  • GitOps Scaffolding & Linter Governance: Manage ArgoCD and construct automated linters to enforce repository standards across teams.

Skills

Kubernetes
Terraform
GitOps
Service Mesh
OPA/ Rego
IaC
OpenTelemetry

Education

Bachelor’s degree in CS/Engineering

Tools

Terraform
ArgoCD
Flux
Istio
Envoy
OPA
Rego
Vault
OIDC

Job description

Business Area:

IT


Seniority Level:

Mid-Senior level


Job Description:

At Cloudera, we empower people to transform complex data into clear and actionable insights. With as much data under management as the hyperscalers, we\'re the preferred data partner for the top companies in almost every industry. Powered by the relentless innovation of the open source community, Cloudera advances digital transformation for the world\’s largest enterprises.


About the Team & Role

We are building an enterprise-grade, Everything-as-Code (EaC) Operating Platform that replaces manual IT operations with an automated, zero-trust software factory. As a DevSecOps Platform Engineer, you will be a core builder of our security, networking, and platform control planes.


Operating in an environment where all infrastructure, access policies, and network routing exist strictly as version-controlled text artifacts inside Git repositories, you will architect our multi-cloud Kubernetes foundations (AWS EKS / Azure AKS), enforce keyless workload identity, build zero-trust service mesh perimeters, and write active Policy-as-Code (OPA/Rego) pipelines.


As a DevSecOps Platform Engineer, you will:


  • Two-Tier IaC Platform Primitives: Design, provision, and maintain modular Terraform primitives and GitOps patterns for multi-cloud Kubernetes clusters (EKS/AKS), software-defined networks, and pod identity layers.

  • Service Mesh & Edge Control Planes: Operate Istio/Envoy service mesh topologies across multi-gateway perimeters (Public Ingress, B2B Ingress, Egress).

  • Active Policy-as-Code Gating: Author and maintain Open Policy Agent (OPA / Rego) policies to enforce pre-flight deployment checks, Commit-as-Code format verification, and dynamic Just-in-Time (JIT) time-bound access escalation gates.

  • Out-of-Band Telemetry Exhaust: Configure OpenTelemetry (OTel) collectors and Envoy sidecar proxies to emit uniform out-of-band JSON telemetry logs, stamping W3C traceparent headers and system primary keys (UPID, USID, correlation_id, process_id) across all network hops.

  • GitOps Scaffolding & Linter Governance: Manage localized pull-based continuous delivery engines (ArgoCD) and construct automated structural linters to enforce the 10-Pillar Application Spoke Repository Standard across all engineering teams.


We are excited if you have (Required Experience):


  • Kubernetes & Container Security: 5+ years of deep experience operating production Kubernetes (Amazon EKS, Azure AKS) and container security frameworks.

  • Education: Bachelor’s degree in Computer Science, Engineering, Information Systems, or a related field or equivalent experience.

  • Service Mesh & API Gateways: Advanced hands‑on experience configuring Istio / Envoy service meshes, mTLS, custom ingress/egress routing, and edge API gateways.

  • Policy-as-Code (Rego/OPA): Practical expertise writing custom Open Policy Agent (OPA) rules in Rego for pipeline gating, admission controllers, or access governance.

  • Infrastructure-as-Code & GitOps: High proficiency with Terraform (modular structure design) and pull-based GitOps delivery tools (ArgoCD or Flux).

  • Keyless Identity & Secrets Management: Hands‑on experience with OIDC identity federation, HashiCorp Vault, and short‑lived secret workflows.

  • Distributed Observability: Strong understanding of OpenTelemetry (OTel) instrumentation, W3C trace context propagation, and log aggregation pipelines.


You may also have:


  • Familiarity with CI/CD linter construction for regular expression validation (Commit-as-Code).

  • Background working within Hub-and-Spoke repository models and developer portal integrations.


What you can expect from us:


  • Generous PTO Policy

  • Support work life balance with Unplugged Days

  • Flexible WFH Policy

  • Mental & Physical Wellness programs

  • Phone and Internet Reimbursement program

  • Access to Continued Career Development

  • Comprehensive Benefits and Competitive Packages

  • Paid Volunteer Time

  • Employee Resource Groups


EEO/VEVRAA

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Staff Software Engineer, Anywhere Cloud (Rust & Kubernetes)
Staff Software Engineer, Anywhere Cloud (Rust & Kubernetes)

Cloudera • Kalisz

Hybrid
PLN 320,000 - 600,000
Generous PTO
Unplugged Days
Flexible WFH Policy
+5
DevSecOps Platform Engineer: Multi-Cloud K8s & IaC
DevSecOps Platform Engineer: Multi-Cloud K8s & IaC

Cloudera • Kalisz

On-site
PLN 180,000 - 260,000
Generous PTO
Flexible WFH
Wellness program
+3
Lead Data Mesh Engineer
Lead Data Mesh Engineer

Cloudera • Kalisz

Hybrid
PLN 200,000 - 360,000
Generous PTO Policy
Unplugged Days
Flexible WFH Policy
+6
DevOps Engineer
DevOps Engineer

Joy Studios • Warszawa

On-site
PLN 260,000 - 360,000
Staff Engineer I, DevOps Engineering
Staff Engineer I, DevOps Engineering

Bain & Company • Warszawa

On-site
PLN 260,000 - 360,000
Senior Devops engineer
Senior Devops engineer

Alcor • Kraków

On-site
PLN 260,000 - 360,000
Senior Engineer - DevOps
Senior Engineer - DevOps

Hard Rock Digital • Województwo pomorskie

On-site
PLN 180,000 - 280,000
Senior/Lead DevOps Engineer
Senior/Lead DevOps Engineer

Sigma Software • Warszawa

On-site
PLN 240,000 - 300,000
Senior Site Reliability Engineer / Kubernetes (Remote)
Senior Site Reliability Engineer / Kubernetes (Remote)

Pragmatike • Poland

Remote
PLN 392,000 - 566,000
DevOps Engineer
DevOps Engineer

Sigma Software • Województwo małopolskie

On-site
PLN 180,000 - 240,000