Über diese Senior Platform Engineer (Top Secret/SCI with agreement to obtain CI Poly Clearance Required) Stelle bei North Point Technology
North Point Technology is looking to hire a Senior Platform Engineer with deep expertise in on-premises Kubernetes infrastructure to support a mission-critical enterprise container platform operating in a fully air-gapped, non-cloud environment. This is a short-term contract assignment of approximately seven months. An active Top Secret clearance with SCI eligibility is required upon hire, and the selected candidate must be willing and able to obtain a polygraph within the customer's timeline.
Responsibilities:
The Senior Platform Engineer will design, deploy, and maintain enterprise-scale Kubernetes clusters built entirely from bare metal in secure, air-gapped data centers. Responsibilities span the full infrastructure stack: advanced Linux administration including systemd, kernel tuning, and SSH key architecture; manual installation and configuration of container runtimes (containerd, CRI-O); OS-level security hardening with AppArmor and SELinux; and management of cgroups v2 and container isolation mechanisms. The engineer will design and implement software-defined storage solutions, build distributed storage clusters from raw drives, deploy Container Storage Interface (CSI) drivers for dynamic volume provisioning, and monitor storage performance and capacity. Cluster lifecycle duties include bootstrapping production Kubernetes clusters from scratch using kubeadm or Kubespray, designing multi-master high-availability control plane architectures, configuring internal load balancers for API server redundancy, and managing etcd operations including backups, snapshots, restoration, and defragmentation. Security responsibilities include implementing RBAC policies, network policies, pod security standards, admission controllers, API server auditing, certificate lifecycle management, and vulnerability remediation. The role also involves developing Ansible playbooks and Bash/Python scripts for cluster provisioning, implementing GitOps workflows with ArgoCD, maintaining infrastructure-as-code repositories, building CI/CD pipelines for infrastructure validation, managing Kaniko-based container image builds in air-gapped environments, and troubleshooting cluster components using k9s, kubectl, and crictl.
Required Skills/Experience:
- On-premises Kubernetes cluster deployment and management in production environments (non-cloud, air-gapped)
- Bootstrapping Kubernetes clusters using Kubespray, kubeadm, or equivalent tools
- Enterprise Linux system administration including systemd service management and kernel tuning
- Container runtime installation and configuration: containerd and CRI-O
- cgroups v2, Linux namespaces, and container isolation management at the OS level
- OS-level security hardening with AppArmor and SELinux
- Software-defined storage design and implementation; CSI driver deployment for dynamic persistent volume provisioning
- High-availability Kubernetes control plane architecture with multi-master nodes and internal load balancers
- etcd cluster operations: backups, snapshots, restoration, and defragmentation
- Kubernetes security: RBAC, network policies, pod security standards, admission controllers, and API server auditing
- Certificate lifecycle management for Kubernetes cluster components and service mesh
- Ansible automation and Ansible playbook development for infrastructure provisioning
- GitOps workflows and ArgoCD for declarative, continuous deployment
- Infrastructure-as-code repository management for repeatable deployments
- CI/CD pipeline construction for infrastructure testing and validation
- Air-gapped and offline deployment strategies including Kaniko-based container image builds
- Cluster administration and debugging using k9s, kubectl, and crictl
- Troubleshooting static pods: etcd, kube-apiserver, kube-controller-manager, kube-scheduler
- Scripting in Bash and/or Python for cluster automation
Preferred Skills/Experience:
- Identity and authorization standards: X.509, SAML, OAuth2, OIDC, LDAP
- ICAM solution architecture using Oracle or other enterprise-grade identity platforms
Qualifications:
- Bachelor's degree in a STEM field
- Master's degree in a STEM field (preferred)
- Certified Kubernetes Security Specialist (CKS) certification
- Active Top Secret security clearance
- SCI eligibility
- Willingness and ability to obtain a CI polygraph within the customer's timeline
- U.S. citizenship required
North Point Technology is THE BEST place to work for curious-minded engineers motivated to support our country’s most crucial missions! We focus on long term projects, leveraging the latest technology in support of innovative solutions to solve our customer’s most difficult problems.
At North Point Technology, EMPLOYEES come first! We value our employees by providing excellent compensation, benefits, and a flexible work-life balance. We strive for a close-knit and open atmosphere where the owners are always directly available to our team members.
Come join us! Apply with North Point Technology today!
For positions requiring a federal security clearance, your clearance level must be clearly identified on your resume.