Principal Kubernetes Platform Engineer
AI in this role
Our Purpose
Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we’re helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
Title and Summary
Principal Kubernetes Platform EngineerAbout MastercardMastercard is a global technology company in the payments industry. Our mission is to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart, and accessible.
Using secure data and networks, partnerships, and passion, our innovations and solutions help individuals, financial institutions, governments, and businesses realize their greatest potential. With connections across more than 210 countries and territories, we are building a sustainable world that unlocks priceless possibilities for all.
Overview
As a Principal Engineer within the Decision Stream program, you will combine enterprise-scale technical leadership with hands-on engineering for the next-generation Decision Management Platform. This is not a strategy-only role. You will actively design, code, prototype, and validate core platform capabilities, using modern AI-assisted development tools as part of day-to-day software engineering to move faster, improve quality, and help teams adopt better ways of building.
Key areas of focus include leveraging disruptive technologies in real-time AI inferencing and decisioning to improve product effectiveness, increase business delivery, strengthen technical resilience, and lower cost of ownership. You will work closely with technology executives, senior leaders, and engineers to shape the overall AI & DPE technology strategy.
Role
• Own and operate the AWS EKS cluster, upgrades, node groups, managed add-ons, cluster logging, and capacity planning
• Author, maintain, and review Helm charts for application services, infrastructure (Kafka, Redis, PostgreSQL), and observability layers
• Design and implement IAM/IRSA roles, KMS key policies, and Secrets Manager integration per workload, following least-privilege principles
• Enforce platform security standards, Pod Security Standards, Network Policies, container hardening, and PCI DSS 3.2.1 compliance gates in CI pipelines
• Manage ECR image registry, scanning policies, base image governance, and lifecycle rules
• Build and maintain AWS CDK infrastructure constructs for EKS, MSK, S3, RDS, DynamoDB, Secrets Manager, VPC, and supporting services
• Define and operate ingress patterns, AWS ALB, ACM certificates, Route 53 DNS, and External Secrets Operator for secrets delivery
• Lead platform security reviews and ensure all infrastructure changes are validated against organisational compliance standards before deployment
• Collaborate with application engineering teams across Rust, Go, Java, and C++ services to onboard workloads, review resource configurations, and resolve platform-level issues
• Drive GitOps delivery practices via ArgoCD, CI/CD pipeline integration, and feature branch release workflows
• Define and document platform standards, runbooks, and onboarding guides for the engineering team
• Act as the platform SME, mentoring engineers, leading design discussions, and making architectural decisions for the AWS platform layer
All About You
• Kubernetes — deep knowledge of node groups, OIDC provider, Pod Identity/IRSA, cluster autoscaler, and EKS upgrade operations
• Helm — multi-environment chart authoring, value layering strategies, Helmfile or ArgoCD-based GitOps delivery; experience converting AKS/Azure chart patterns to AWS EKS equivalents
• Security — IRSA design, KMS CMK policies, Secrets Manager, External Secrets Operator, Pod Security Standards, Network Policies, and PCI DSS compliance; experience operating under regulatory security standards
• Networking — VPC design, private subnets, ALB ingress controller, ACM certificate management, Route 53, External-DNS, PrivateLink for internal AWS service endpoints, and security group design
• Container Platform — ECR image registry management, image scanning, multi-stage Dockerfile practices, non-root container enforcement, read-only root filesystem, and supply chain security
• CI/CD & GitOps — Jenkins pipeline authoring, Bitbucket/GitHub pull request workflows, ArgoCD or Flux, feature branch strategies, and pre-push security gate enforcement
• Observability — CloudWatch Container Insights, AWS Distro for OpenTelemetry (ADOT), Prometheus, Grafana, and distributed tracing on EKS
Preferred Qualifications
• AWS CDK (TypeScript) — authoring CDK L3 constructs and infrastructure-as-code best practices for EKS, MSK, RDS, DynamoDB, S3, and Secrets Manager
• Kafka / Streaming — operating Kafka on Kubernetes, topic management, consumer group operations, and TLS/SASL authentication
• Database Operations — exposure to PostgreSQL (RDS/Aurora), DynamoDB, and Redis Enterprise in a Kubernetes or managed AWS environment
• Application Background — familiarity with polyglot microservice environments (Rust, Go, Java/Flink, C++); ability to read and advise on Dockerfiles, gRPC/protobuf service contracts, and multi-language build pipelines
• ML Platform Awareness — basic familiarity with SageMaker, Bedrock, or MLflow workloads running on EKS is a plusMastercard is a merit-based, inclusive, equal opportunity employer that considers applicants without regard to gender, gender identity, sexual orientation, race, ethnicity, disabled or veteran status, or any other characteristic protected by law. We hire the most qualified candidate for the role. In the US or Canada, if you require accommodations or assistance to complete the online application process or during the recruitment process, please contact reasonable_accommodation@mastercard.com and identify the type of accommodation or assistance you are requesting. Do not include any medical or health information in this email. The Reasonable Accommodations team will respond to your email promptly.
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
Abide by Mastercard’s security policies and practices;
Ensure the confidentiality and integrity of the information being accessed;
Report any suspected information security violation or breach, and
Complete all periodic mandatory security trainings in accordance with Mastercard’s guidelines.
Pay Ranges
Arlington, Virginia: $195,000 - $323,000 USDRemote - Georgia: $170,000 - $281,000 USDRemote - Illinois: $170,000 - $281,000 USDRemote - Michigan: $170,000 - $281,000 USDRemote - Missouri: $170,000 - $281,000 USDRemote - New Jersey: $170,000 - $281,000 USDRemote - New York: $170,000 - $281,000 USDRemote - North Carolina: $170,000 - $281,000 USDRemote - Texas: $170,000 - $281,000 USDRemote - Virginia: $170,000 - $281,000 USDJob Posting Window
Posting windows may change based on the volume of applications received and business necessity. Candidates are encouraged to apply expeditiously.How we rate this
Principal Kubernetes Platform Engineer at Mastercard rates 31 out of 100 for how much of the daily work is AI. That makes it Little AI (AI Level 1 of 4). The level is about AI in the job, not seniority.
Little AI. AI is not part of the work.
- ●●●● Builds AI80 to 100
- ●●●○ Works on AI60 to 79
- ●●○○ Uses AI40 to 59
- ●○○○ Little AI0 to 39
Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.
Prepare for this job
A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.
Skills and AI tools this role asks for
Questions you could be asked
- What's a project where you used Bedrock hands-on?
- Walk me through how you've used Mlflow in your day-to-day work.
- What are the limits of Sagemaker that you've run into, and how did you work around them?
Adapt your resume
- List these exact terms on your resume: Bedrock, Mlflow, and Sagemaker. An applicant tracking system matches the wording, not the idea.
- Attach one line of real, concrete experience to at least one of them — a tool named with nothing behind it rarely survives a human read.
Want an expert to read your CV for this job?
Free. Send your CV and the role you want next. We reply by email within 2 to 4 business days.
Get a free CV reviewGet new AI jobs by email
One email a week with the new AI jobs, each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.
Free. One email a week. Unsubscribe in one click.
Similar roles
Software Engineering roles that involve little AI, at other companies.
What kind of AI work fits you?
Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.
Find my next step