Level

Cloudera

DevSecOps Platform Engineer

AI in this role

Design and maintain a zero-trust multi-cloud Kubernetes platform using Infrastructure-as-Code and GitOps practices.

kubernetesterraformargocdistioenvoyopaopentelemetrygit
devsecopsinfrastructure-as-codeci-cdcontainer-securitynetworking

Business Area:

IT

Seniority Level:

Mid-Senior level

Job Description: 

At Cloudera, we empower people to transform complex data into clear and actionable insights. With as much data under management as the hyperscalers, we're the preferred data partner for the top companies in almost every industry.  Powered by the relentless innovation of the open source community, Cloudera advances digital transformation for the world’s largest enterprises.


Job Description

About the Team & Role

We are building an enterprise-grade, Everything-as-Code (EaC) Operating Platform that replaces manual IT operations with an automated, zero-trust software factory. As a DevSecOps Platform Engineer, you will be a core builder of our security, networking, and platform control planes.


Operating in an environment where all infrastructure, access policies, and network routing exist strictly as version-controlled text artifacts inside Git repositories, you will architect our multi-cloud Kubernetes foundations (AWS EKS / Azure AKS), enforce keyless workload identity, build zero-trust service mesh perimeters, and write active Policy-as-Code (OPA/Rego) pipelines.


As a DevSecOps Platform Engineer, you will:


  • Two-Tier IaC Platform Primitives: Design, provision, and maintain modular Terraform primitives and GitOps patterns for multi-cloud Kubernetes clusters (EKS/AKS), software-defined networks, and pod identity layers.
  • Service Mesh & Edge Control Planes: Operate Istio/Envoy service mesh topologies across multi-gateway perimeters (Public Ingress, B2B Ingress, Egress).
  • Active Policy-as-Code Gating: Author and maintain Open Policy Agent (OPA / Rego) policies to enforce pre-flight deployment checks, Commit-as-Code format verification, and dynamic Just-in-Time (JIT) time-bound access escalation gates.
  • Out-of-Band Telemetry Exhaust: Configure OpenTelemetry (OTel) collectors and Envoy sidecar proxies to emit uniform out-of-band JSON telemetry logs, stamping W3C traceparent headers and system primary keys (UPID, USID, correlation_id, process_id) across all network hops.
  • GitOps Scaffolding & Linter Governance: Manage localized pull-based continuous delivery engines (ArgoCD) and construct automated structural linters to enforce the 10-Pillar Application Spoke Repository Standard across all engineering teams.


We are excited if you have (Required Experience):

  • Kubernetes & Container Security: 5+ years of deep experience operating production Kubernetes (Amazon EKS, Azure AKS) and container security frameworks.
  • Education: Bachelor’s degree in Computer Science, Engineering, Information Systems, or a related field or equivalent experience.
  • Service Mesh & API Gateways: Advanced hands-on experience configuring Istio / Envoy service meshes, mTLS, custom ingress/egress routing, and edge API gateways.
  • Policy-as-Code (Rego/OPA): Practical expertise writing custom Open Policy Agent (OPA) rules in Rego for pipeline gating, admission controllers, or access governance.
  • Infrastructure-as-Code & GitOps: High proficiency with Terraform (modular structure design) and pull-based GitOps delivery tools (ArgoCD or Flux).
  • Keyless Identity & Secrets Management: Hands-on experience with OIDC identity federation, HashiCorp Vault, and short-lived secret workflows.
  • Distributed Observability: Strong understanding of OpenTelemetry (OTel) instrumentation, W3C trace context propagation, and log aggregation pipelines.


You may also have:

  • Familiarity with CI/CD linter construction for regular expression validation (Commit-as-Code).
  • Background working within Hub-and-Spoke repository models and developer portal integrations.

What you can expect from us:

  • Generous PTO Policy 

  • Support work life balance with Unplugged Days

  • Flexible WFH Policy 

  • Mental & Physical Wellness programs 

  • Phone and Internet Reimbursement program 

  • Access to Continued Career Development 

  • Comprehensive Benefits and Competitive Packages 

  • Paid Volunteer Time

  • Employee Resource Groups

EEO/VEVRAA


#LI-EO1

#LI-HYBRID

How we rate this

DevSecOps Platform Engineer at Cloudera rates 0 out of 100 for how much of the daily work is AI. That makes it Little AI (AI Level 1 of 4). The level is about AI in the job, not seniority.

Classification

Little AI. AI is not part of the work.

  1. ●●●● Builds AI80 to 100
  2. ●●●○ Works on AI60 to 79
  3. ●●○○ Uses AI40 to 59
  4. ●○○○ Little AI0 to 39

Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.

Prepare for this job

A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.

Skills and AI tools this role asks for

DevsecopsInfrastructure As CodeCi CdContainer SecurityNetworkingKubernetesTerraformArgocd

Questions you could be asked

  1. Tell me about a project where devsecops was part of your work. What did you do?
  2. Tell me about a project where infrastructure as code was part of your work. What did you do?
  3. Tell me about a project where ci cd was part of your work. What did you do?
  4. Tell me about a project where container security was part of your work. What did you do?
  5. Tell me about a project where networking was part of your work. What did you do?

Adapt your resume

  • List these exact terms on your resume: Devsecops, Infrastructure As Code, Ci Cd, Container Security, and Networking. An applicant tracking system matches the wording, not the idea.
  • Attach one line of real, concrete experience to at least one of them — a tool named with nothing behind it rarely survives a human read.

Want an expert to read your CV for this job?

Free. Send your CV and the role you want next. We reply by email within 2 to 4 business days.

Get a free CV review

Get new remote cybersecurity jobs by email

One email a week with the new remote cybersecurity jobs, each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.

Free. One email a week. Unsubscribe in one click.

Similar roles

Software Engineering roles that involve little AI, at other companies.

What kind of AI work fits you?

Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.

Find my next step

More jobs at Cloudera

More cybersecurity jobs

Related searches

Same AI level