Senior Cloud Platform Architect – AWS EKS, API Containerization

Posted Aug 26

This is a fully remote position, open to applicants in California.

📋 Description

• Lead the containerization efforts for a large-scale API ecosystem for a major financial services client.

• Transform an approved AWS EKS reference architecture into a secure and repeatable production environment.

• Develop and assess Terraform, Helm, Kustomize, Flux, and Istio policies.

• Implement a multi-AZ EKS Auto Mode foundation and golden path utilizing VPC CNI, Karpenter, KEDA, and reusable Terraform/Helm/Kustomize modules.

• Document the platform to ensure operability by the SRE team.

• Establish Flux as the exclusive production delivery channel featuring continuous reconciliation, signed digest-pinned images, GitLab CI and Artifactory integration, and Flagger SLO-gated canaries.

• Implement the Istio Ambient service mesh, incorporating istiod, istio-cni, ztunnel, opt-in waypoints, SPIFFE workload identity, strict mTLS, AuthorizationPolicy, and default-deny NetworkPolicy.

• Measure latency and overhead within the service mesh.

• Manage north-south ingress utilizing Tyk Self-Managed and its Operator, handling authentication, rate limits, routing, REST-to-gRPC transcoding, and API migration.

• Enforce security protocols including Pod Security Standards, Kyverno admission policies, EKS Pod Identity, Secrets Manager/CSI, KMS, cert-manager, image signing, and SBOMs.

• Create a robust billing and audit capture mechanism using Kinesis, Firehose, S3 Object Lock, and an approved load-tested reliability contract.

• Set gRPC/Protobuf as the standard for east-west communication with buf breaking-change checks.

• Integrate SLOs, error budgets, and OpenTelemetry-based metrics, logs, and traces into the platform.

• Develop architecture decision records, threat models, and standards.

• Mentor platform, SRE, and application engineers.

• Represent Opplane during client architecture reviews.


⛳️ Requirements

• 12+ years of experience in software, infrastructure, or platform engineering.

• 5+ years of hands-on experience with production Kubernetes on AWS, including EKS architecture, operations, networking, upgrades, scaling, and incident troubleshooting.

• Proven ability to establish EKS platforms from start to finish and containerize existing API workloads at an enterprise scale.

• Strong expertise in Terraform, Helm, and Kustomize.

• Experience in reusable platform-module design.

• Ability to make defensible architecture decisions and lead cross-team initiatives in a regulated environment.

• Ownership of production service mesh, including Istio architecture, policy, rollout, performance, and troubleshooting; experience with Ambient mode is particularly relevant.

• Extensive GitOps experience with continuous reconciliation, drift management, and environment promotion; capability to implement Flux.

• Practical knowledge of Kubernetes and AWS security, including PSS, policy as code, NetworkPolicy, IAM, Pod Identity, KMS, certificate management, image signing, and SBOMs.

• Experience in API gateway and regulated audit/event-ingestion design; ability to manage a self-managed gateway.

• Familiarity with gRPC, HTTP/2, and Protobuf.

• Sufficient knowledge of Java 21 and Spring Boot to review the reference runtime pattern.

• Expertise in observability across metrics, logs, traces, SLOs, and rollout analysis using OpenTelemetry.

• Proven performance validation at tens of thousands of TPS.

• Requires overlapping hours with US Pacific time.

• Participation in an escalation rotation during the build-out phase is required.

• Background screening by the client is mandatory.

• Preference for candidates based in California.

• Direct experience with Tyk is highly preferred.

• AWS Solutions Architect Professional and CKA/CKS certifications are advantageous.


🏝️ Benefits

• Permanent full-time employment.

• Remote work opportunities within the US.

• Preference for California-based individuals for occasional client-site workshops and readiness reviews.

• US Pacific hours overlap.

• Work within a global and multicultural team.

• Experience a fast-paced, impact-driven startup environment.

• Enjoy ownership over the work produced.

• Be part of a collaborative, open, curious, and supportive culture.

People also viewed

Devoteam8 hours ago

Node.js Developer

TN flagTunisia OnlyFull-timeBackend Engineer
ApplyView job
ioet8 hours ago

Senior Backend Engineer – Google Ads

Latin AmericaFull-timeBackend Engineer
ApplyView job
Sigma Software Group9 hours ago

Senior Java Developer

DE flagGermany, +1 more countryFull-timeBackend Engineer
ApplyView job
Humana9 hours ago

Lead Full-Stack Engineer – Backend Focus

US flagDistrict of Columbia, +8 more statesFull-timeBackend Engineer$155.2k – $213.4k/year
ApplyView job
Tether.to9 hours ago

Backend Engineer – Wallets

AE flagUnited Arab Emirates (UAE) OnlyFull-timeBackend Engineer
ApplyView job
CI&T9 hours ago

Master .NET Specialist

BR flagBrazil OnlyFull-timeBackend Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers