Summary
✨ AI‑Generated
Engineer a secure, multi-tenant platform that provides interactive access, controlled file transfer, credential lifecycle automation, session recording, audit logging, and usage metering. You will build containerized services, enforce tenant isolation, integrate with privileged-access systems and storage platforms, and develop CI/CD automation for the complete platform lifecycle. The role combines DevOps, cloud infrastructure, security, and platform engineering.
Highlights
Build and operate sophisticated cloud-native platform services involving secure access, file transfer, tenant isolation, credential automation, audit logging, metering, and CI/CD. The role offers broad technical ownership across infrastructure automation, security, reliability, and platform lifecycle management.
Description
Job Description
Design and operate the interactive access service based on Apache Guacamole, containerized on OpenShift, translating HTTPS to native protocols (SSH, RDP, SQL, VNC)Build and maintain the file transfer service using S3 presigned URLs with time-bound expiry and tenant-scoped bucket/path access controlsEngineer tenant isolation within shared SaaS-style deployments, ensuring each consuming team only accesses their own targets through predefined connections and network-level controlsDesign credential lifecycle automation: retrieval/seeding at session start, reset/removal at session stop, integrated with Privileged Access Management and credential storesBuild session recording and logging pipelines shipping audit data to tenant-specified log repositories (Kafka, S3, Git)Implement metering and billing event generation for per-tenant consumption trackingDevelop CI/CD pipelines for automated platform lifecycle management: provisioning, start, stop, decommissioning (immutable infrastructure / cattle model)Collaborate with security teams to refine detection scenarios every sprint and maintain audited control reporting (Seven IT Risk Controls, COBIT framework)Define and monitor SLIs/SLOs: start latency, session success rate, recording completeness, tenant isolation violations, credential reset compliance
Required Skills & Experience
3+ years hands-on experience with Kubernetes/OpenShift in production (deployment, networking, RBAC, persistent storage, operators)Proficiency in Go and Python for platform service development, automation, and toolingStrong Linux systems engineering (SSH, networking, security hardening, systemd)Container orchestration and CI/CD pipeline design (Helm, ArgoCD, Tekton, or equivalent)S3-compatible object storage (MinIO or AWS S3): presigned URLs, bucket policies, IAM integrationAzure DevOps for backlog management, CI/CD pipelines, and release workflowsInfrastructure as Code: Terraform, Ansible, or equivalentUnderstanding of security principles: zero-trust, defence-in-depth, protocol insulation, MFA, credential managementExperience with IAM systems, directory services integration, and conditional access policiesFamiliarity with logging and monitoring stacks (Kafka, Elasticsearch, Prometheus/Grafana)
Nice to Have
VMware Cloud Foundation (VCF) experience or familiarity with VCF-based infrastructureExperience with Privileged Access Management tooling (CyberArk, HashiCorp Vault)Experience with Apache Guacamole or similar remote access gateway technologiesRDP and Windows Server administration knowledgeExperience in regulated financial services environments (DORA, NIS2, or equivalent regulatory frameworks)Understanding of network segmentation and firewall rule managementSOC2 Type 2 reporting or equivalent security assurance frameworksExperience designing metering/billing event pipelines for internal platform products