Kubernetes Platform Engineer

Bay Systems Consulting Inc.

Berkeley (CA)

On-site

USD 150,000 - 210,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Bay Systems Consulting Inc. in Berkeley, CA, is seeking a Kubernetes Platform Engineer to join the Platform Engineering team as a hands‑on contributor.

The role emphasizes daily operations of on‑prem Kubernetes clusters (K3s/RKE2) with cloud support on GCP and AWS, plus Cilium networking and multi‑tenant security. The candidate will manage cluster lifecycles, implement security baselines, and enable development teams to deploy workloads efficiently.

Qualifications

  • Typically requires a minimum of 8 years of related experience with a Bachelor’s degree
  • Demonstrated experience administering Kubernetes on on‑premises infrastructure (K3s, RKE2, or similar)
  • Experience with cloud‑managed Kubernetes (GKE and/or EKS)
  • Strong understanding of Linux networking fundamentals: iptables/nftables, routing tables, DNS, TCP/IP stack
  • Experience with GitOps methodologies and tools such as ArgoCD or Flux
  • Proficiency in scripting and automation: Bash, Python, Go
  • Cilium CNI or equivalent production experience
  • Ability to work collaboratively in a team environment and communicate technical concepts clearly
  • GCP and/or AWS cloud platform experience

Responsibilities

  • Manage the full lifecycle of Kubernetes clusters (on‑premises K3s/RKE2, GKE, and EKS), including upgrades, security patching, scaling, and capacity planning
  • Troubleshoot cluster‑level issues including control plane problems, node failures, and resource constraints
  • Implement and maintain cluster security hardening based on CIS benchmarks and organizational security policies
  • Manage etcd cluster health, backup procedures, and disaster recovery capabilities
  • Monitor cluster performance and optimize resource utilization across multi‑tenant workloads
  • Coordinate with datacenter operations team for physical infrastructure changes and maintenance windows
  • Implement, configure, and maintain Cilium CNI across on‑premises and cloud Kubernetes environments
  • Design and enforce network policies to achieve secure multi‑tenant isolation
  • Troubleshoot complex pod networking issues including DNS resolution, service discovery, and connectivity problems
  • Configure and maintain BGP peering with physical network infrastructure for on‑premises integration
  • Work with network engineering team on firewall rules, VLANs, IPv6 networking, and network architecture
  • Contribute to building a next‑generation internal developer platform inspired by tools like Backstage
  • Work with the security team to define secure image baselines and automate the patching pipeline for container images
  • Assist development teams with deploying, configuring, and troubleshooting Kubernetes workloads
  • Review application deployment manifests and provide guidance on best practices and optimization
  • Develop and maintain platform documentation, runbooks, and self‑service guides
  • Engage with development teams to understand platform needs and tailor the cluster experience to meet evolving requirements

Skills

Kubernetes administration
On-premises Kubernetes (K3s/RKE2)
Cloud Kubernetes (GKE/EKS)
Linux networking fundamentals
GitOps (ArgoCD/Flux)
Scripting (Bash, Python, Go)
Cilium CNI

Education

Bachelor’s degree
Master’s degree

Tools

Terraform
Ansible
Backstage

Job description

If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.

Full Time Berkeley, California, Berkeley, CA, US

1 year contract - Extension/Conversion possibility with job performance

We are seeking a Kubernetes Platform Engineer to join the Platform Engineering team as a hands‑on individual contributor. This role focuses on day‑to‑day operations and administration of Kubernetes clusters, primarily on‑premises (K3s/RKE2) with additional support for cloud environments on Google Cloud Platform (GCP) and Amazon Web Services (AWS). You will manage cluster lifecycle operations, implement and maintain Cilium‑based networking, troubleshoot complex platform issues, and enable development teams to successfully deploy and operate their workloads. This position balances infrastructure operations with developer enablement, requiring both deep technical expertise and strong collaboration skills.

The Team

The Platform Engineering team is a small team within ESnet's Systems and Software department that is dedicated to streamlining the software development lifecycle by establishing standardized processes for building, configuring, and deploying applications. The team supports the engineering, implementation, and maintenance of ESnet's platform systems and services including GitLab, Ansible, and Kubernetes environments, with responsibility for both on‑premises and cloud‑based services deployed across Google Cloud Platform (GCP) and Amazon Web Services (AWS).

Major Responsibilities
Cluster Operations & Administration
  • Manage the full lifecycle of Kubernetes clusters (on‑premises K3s/RKE2, GKE, and EKS), including upgrades, security patching, scaling, and capacity planning
  • Troubleshoot cluster‑level issues including control plane problems, node failures, and resource constraints
  • Implement and maintain cluster security hardening based on CIS benchmarks and organizational security policies
  • Manage etcd cluster health, backup procedures, and disaster recovery capabilities
  • Monitor cluster performance and optimize resource utilization across multi‑tenant workloads
  • Coordinate with datacenter operations team for physical infrastructure changes and maintenance windows
  • Implement, configure, and maintain Cilium CNI across on‑premises and cloud Kubernetes environments
  • Design and enforce network policies to achieve secure multi‑tenant isolation
  • Troubleshoot complex pod networking issues including DNS resolution, service discovery, and connectivity problems
  • Configure and maintain BGP peering with physical network infrastructure for on‑premises integration
  • Work with network engineering team on firewall rules, VLANs, IPv6 networking, and network architecture
Internal Developer Platform & Enablement
  • Contribute to building a next‑generation internal developer platform inspired by tools like Backstage, focused on increasing development efficiency and security
  • Work with the security team to define secure image baselines and automate the patching pipeline for container images
  • Assist development teams with deploying, configuring, and troubleshooting Kubernetes workloads
  • Review application deployment manifests and provide guidance on best practices and optimization
  • Develop and maintain platform documentation, runbooks, and self‑service guides
  • Engage with development teams to understand platform needs and tailor the cluster experience to meet evolving requirements
Required Qualifications
  • Typically requires a minimum of 8 years of related experience with a Bachelor’s degree; or 6 years and a Master’s degree; or equivalent experience.
  • Demonstrated experience administering Kubernetes on on‑premises infrastructure (K3s, RKE2, or similar bare‑metal distributions)
  • Experience with cloud‑managed Kubernetes (GKE and/or EKS)
  • Strong understanding of Linux networking fundamentals: iptables/nftables, routing tables, DNS, TCP/IP stack, network troubleshooting
  • Experience with GitOps methodologies and tools such as ArgoCD or Flux
  • Proficiency in scripting and automation: Bash, Python, Go
  • Cilium CNI or equivalent production experience
  • Ability to work collaboratively in a team environment and communicate technical concepts clearly
  • Understanding of Kubernetes security best practices including Pod Security Standards, RBAC, and secrets management
  • GCP (Google Cloud Platform) and/or AWS (Amazon Web Services) cloud platform experience
Preferred Qualifications
  • Go programming experience for operator maintenance and platform tooling development
  • CKA (Certified Kubernetes Administrator) or CKS (Certified Kubernetes Security Specialist) certification
  • Background in BGP routing protocols and network engineering concepts
  • IPv6 networking experience
  • Infrastructure as Code experience with Terraform or Ansible
  • Experience with internal developer platform (IDP) tools such as Backstage or similar
  • Experience with service mesh technologies (Istio, Linkerd)
  • Excellent understanding of code review and familiarity with GitHub and GitLab workflows
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Kubernetes Platform Engineer
Kubernetes Platform Engineer

Ltd Global • Berkeley (CA)

On-site
USD 120,000 - 160,000
Kubernetes Platform Engineer
Kubernetes Platform Engineer

MartinFed • Oak Ridge (TN)

On-site
USD 90,000 - 130,000
Kubernetes Platform Engineer
Kubernetes Platform Engineer

Xcel Engineering • Oak Ridge (TN)

On-site
USD 120,000 - 190,000
Principal Security Engineer
Principal Security Engineer

Mass Digital Health • Boston (MA)

On-site
USD 120,000 - 150,000
Platform Engineer
Platform Engineer

APN Consulting, Inc. • Jersey City (NJ)

On-site
USD 130,000 - 160,000
Senior Platform / DevOps Engineer
Senior Platform / DevOps Engineer

Veriipro • Westlake (TX)

On-site
USD 130,000 - 160,000
Senior Platform Engineer
Senior Platform Engineer

Radiance Technologies, Inc. • Albuquerque (NM)

On-site
USD 110,000 - 140,000
AWS / Kubernetes Engineer
AWS / Kubernetes Engineer

Highbrow LLC • Berkeley Heights (NJ)

On-site
USD 100,000 - 130,000
Kubernetes Platform Engineer
Kubernetes Platform Engineer

Cadre5 • Knoxville (TN)

Hybrid
USD 100,000 - 130,000
Excellent medical insurance
401K match
15 days PTO
+1
Platform Engineer/ GitOps/Kubernetes
Platform Engineer/ GitOps/Kubernetes

Motion Recruitment • Philadelphia

On-site
USD 120,000 - 160,000
Medical, Dental, and Vision Insurance
401(k) with company match
Paid Time Off and Holidays
+1