Business Area:
ITSeniority Level:
Mid-Senior levelJob Description:
At Cloudera, we empower people to transform complex data into clear and actionable insights. With as much data under management as the hyperscalers, we're the preferred data partner for the top companies in almost every industry. Powered by the relentless innovation of the open source community, Cloudera advances digital transformation for the world’s largest enterprises.
Job Description
About the Team & Role
We are building an enterprise-grade, Everything-as-Code (EaC) Operating Platform that replaces manual IT operations with an automated, zero-trust software factory. As a DevSecOps Platform Engineer, you will be a core builder of our security, networking, and platform control planes.
Operating in an environment where all infrastructure, access policies, and network routing exist strictly as version-controlled text artifacts inside Git repositories, you will architect our multi-cloud Kubernetes foundations (AWS EKS / Azure AKS), enforce keyless workload identity, build zero-trust service mesh perimeters, and write active Policy-as-Code (OPA/Rego) pipelines.
As a DevSecOps Platform Engineer, you will:
- Two-Tier IaC Platform Primitives: Design, provision, and maintain modular Terraform primitives and GitOps patterns for multi-cloud Kubernetes clusters (EKS/AKS), software-defined networks, and pod identity layers.
- Service Mesh & Edge Control Planes: Operate Istio/Envoy service mesh topologies across multi-gateway perimeters (Public Ingress, B2B Ingress, Egress).
- Active Policy-as-Code Gating: Author and maintain Open Policy Agent (OPA / Rego) policies to enforce pre-flight deployment checks, Commit-as-Code format verification, and dynamic Just-in-Time (JIT) time-bound access escalation gates.
- Out-of-Band Telemetry Exhaust: Configure OpenTelemetry (OTel) collectors and Envoy sidecar proxies to emit uniform out-of-band JSON telemetry logs, stamping W3C traceparent headers and system primary keys (UPID, USID, correlation_id, process_id) across all network hops.
- GitOps Scaffolding & Linter Governance: Manage localized pull-based continuous delivery engines (ArgoCD) and construct automated structural linters to enforce the 10-Pillar Application Spoke Repository Standard across all engineering teams.
We are excited if you have (Required Experience):
- Kubernetes & Container Security: 5+ years of deep experience operating production Kubernetes (Amazon EKS, Azure AKS) and container security frameworks.
- Education: Bachelor’s degree in Computer Science, Engineering, Information Systems, or a related field or equivalent experience.
- Service Mesh & API Gateways: Advanced hands-on experience configuring Istio / Envoy service meshes, mTLS, custom ingress/egress routing, and edge API gateways.
- Policy-as-Code (Rego/OPA): Practical expertise writing custom Open Policy Agent (OPA) rules in Rego for pipeline gating, admission controllers, or access governance.
- Infrastructure-as-Code & GitOps: High proficiency with Terraform (modular structure design) and pull-based GitOps delivery tools (ArgoCD or Flux).
- Keyless Identity & Secrets Management: Hands-on experience with OIDC identity federation, HashiCorp Vault, and short-lived secret workflows.
- Distributed Observability: Strong understanding of OpenTelemetry (OTel) instrumentation, W3C trace context propagation, and log aggregation pipelines.
You may also have:
- Familiarity with CI/CD linter construction for regular expression validation (Commit-as-Code).
- Background working within Hub-and-Spoke repository models and developer portal integrations.
What you can expect from us:
Generous PTO Policy
Support work life balance with Unplugged Days
Flexible WFH Policy
Mental & Physical Wellness programs
Phone and Internet Reimbursement program
Access to Continued Career Development
Comprehensive Benefits and Competitive Packages
Paid Volunteer Time
Employee Resource Groups
EEO/VEVRAA
#LI-EO1
#LI-HYBRID
Skills Required
- 5+ years of deep experience operating production Kubernetes, including Amazon EKS and Azure AKS
- Experience with container security frameworks
- Bachelor's degree in Computer Science, Engineering, Information Systems, or a related field, or equivalent experience
- Advanced hands-on experience with Istio, Envoy, mTLS, custom ingress and egress routing, and edge API gateways
- Practical expertise writing Open Policy Agent rules in Rego for pipeline gating, admission controllers, or access governance
- High proficiency with Terraform and pull-based GitOps tools such as ArgoCD or Flux
- Hands-on experience with OIDC identity federation, HashiCorp Vault, and short-lived secret workflows
- Strong understanding of OpenTelemetry instrumentation, W3C trace context propagation, and log aggregation pipelines
- Familiarity with CI/CD linter construction and regular expression validation
- Experience with Hub-and-Spoke repository models and developer portal integrations
Cloudera Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Cloudera and has not been reviewed or approved by Cloudera.
-
Fair & Transparent Compensation — Pay practices are presented as equity-audited with a recognized Fair Pay Workplace certification and ongoing internal reviews. Compensation is often characterized as competitive for similar-sized peers, with visible market-aligned ranges for key roles.
-
Healthcare Strength — Benefit descriptions emphasize comprehensive medical, dental, and vision coverage, alongside life and disability insurance, an EAP, wellness programming, and U.S. gym reimbursement. Health coverage is described as strong in practice.
-
Leave & Time Off Breadth — Policies include generous PTO and holidays plus recurring companywide Unplugged Days that create extended weekends. Parental and medical leave are also highlighted as part of the core package.
Cloudera Insights
What We Do
At Cloudera, we empower people to transform complex data into clear and actionable insights. With as much data under management as the hyperscalers, we're the preferred data partner for the top companies in almost every industry. Powered by the relentless innovation of the open source community, Cloudera advances digital transformation for the world’s largest enterprises.
Why Work With Us
Impact at Scale: The infrastructure we build solves massive problems for top global banks, telecommunications giants, and healthcare providers. Cutting-Edge Tech: Work directly at the intersection of Open Source, Machine Learning, and Generative AI. Unmatched Flexibility: Enjoy a remote-friendly, hybrid culture that respects your time—including






