Description
## About the Role
HCLTech is seeking a **DevOps Engineer** to design, build, and operate secure, scalable platform services in a remote role based in the Netherlands.
The position focuses on Kubernetes/OpenShift, cloud-native infrastructure, CI/CD, platform automation, tenant isolation, credential lifecycle management, session recording, logging, monitoring, and secure access services.
You will work across platform engineering and security teams to develop production-grade services, automate infrastructure lifecycle management, maintain audited security controls, and define service-level indicators and objectives for reliability, security, and performance.
## Key Responsibilities
* Design and operate an interactive access service based on **Apache Guacamole**, containerized on **OpenShift**.
* Support translation of HTTPS traffic to native protocols including **SSH, RDP, SQL, and VNC**.
* Build and maintain file transfer services using **S3 presigned URLs** with time-bound expiry and tenant-scoped bucket and path access controls.
* Engineer tenant isolation within shared SaaS-style deployments.
* Ensure consuming teams can access only their predefined targets through appropriate connections and network-level controls.
* Design credential lifecycle automation, including credential retrieval or seeding at session start and reset or removal at session stop.
* Integrate credential workflows with **Privileged Access Management (PAM)** and credential stores.
* Build session recording and logging pipelines that deliver audit data to tenant-specified repositories such as **Kafka, S3, and Git**.
* Implement metering and billing event generation for per-tenant consumption tracking.
* Develop **CI/CD pipelines** for automated platform lifecycle management, including provisioning, starting, stopping, and decommissioning.
* Apply immutable infrastructure principles and a **cattle-model** approach to platform lifecycle management.
* Collaborate with security teams to refine detection scenarios each sprint.
* Maintain audited control reporting aligned with **Seven IT Risk Controls** and the **COBIT framework**.
* Define and monitor **SLIs/SLOs** covering start latency, session success rate, recording completeness, tenant isolation violations, and credential reset compliance.
## Required Qualifications
* **3+ years of hands-on production experience with Kubernetes/OpenShift**, including:
* Deployment
* Networking
* RBAC
* Persistent storage
* Operators
* Proficiency in **Go and Python** for platform service development, automation, and tooling.
* Strong **Linux systems engineering** experience, including SSH, networking, security hardening, and systemd.
* Experience with container orchestration and **CI/CD pipeline design**, including Helm, ArgoCD, Tekton, or equivalent technologies.
* Experience with **S3-compatible object storage**, such as MinIO or AWS S3, including presigned URLs, bucket policies, and IAM integration.
* Experience with **Azure DevOps** for backlog management, CI/CD pipelines, and release workflows.
* Infrastructure as Code experience with **Terraform, Ansible, or equivalent**.
* Understanding of security principles including:
* Zero Trust
* Defense in depth
* Protocol insulation
* MFA
* Credential management
* Experience with **IAM systems** and directory services integration.
* Understanding of **conditional access policies**.
* Familiarity with logging and monitoring technologies such as **Kafka, Elasticsearch, Prometheus, and Grafana**.
* Candidates must be **eligible to work in the Netherlands**.
* Fluency in **Dutch and English**.
## Preferred Qualifications
* VMware Cloud Foundation (**VCF**) experience or familiarity with VCF-based infrastructure.
* Experience with **Privileged Access Management** tools such as CyberArk or HashiCorp Vault.
* Experience with **Apache Guacamole** or similar remote access gateway technologies.
* **RDP** and Windows Server administration knowledge.
* Experience in regulated financial services environments.
* Familiarity with regulatory frameworks such as **DORA** or **NIS2**, or equivalent.
* Understanding of network segmentation and firewall rule management.
* **SOC 2 Type 2** reporting experience or equivalent security assurance frameworks.
* Experience designing metering and billing event pipelines for internal platform products.
## Skills & Competencies
* DevOps Engineering
* Kubernetes
* OpenShift
* Go
* Python
* Linux
* Cloud-Native Platforms
* Container Orchestration
* CI/CD
* Helm
* ArgoCD
* Tekton
* Azure DevOps
* Terraform
* Ansible
* AWS S3
* MinIO
* IAM
* RBAC
* Zero Trust Security
* Defense in Depth
* MFA
* Credential Management
* Privileged Access Management
* Apache Guacamole
* SSH
* RDP
* SQL
* VNC
* Kafka
* Elasticsearch
* Prometheus
* Grafana
* Infrastructure as Code
* Network Security
* Tenant Isolation
* Session Recording
* Platform Automation
* SLI/SLO Monitoring
* Metering and Billing Pipelines
* Security and Compliance
## Education & Experience
* The source listing does not specify a required educational degree.
* **3+ years of hands-on Kubernetes/OpenShift production experience** is required.
* Relevant production experience in platform engineering, DevOps, cloud infrastructure, automation, security, and CI/CD is applicable based on the stated requirements.
## Work Arrangement & Schedule
* **Remote**
* Listed location: **Amsterdam, Noord-Holland, Netherlands (Remote)**
* Candidates must be eligible to work in the Netherlands.
* Fluent Dutch and English are required.
* Specific working hours, shift requirements, travel requirements, and weekend requirements are not specified.
## Compensation & Benefits
* Compensation amount is not specified; the listing identifies **EUR** as the currency.
* Competitive compensation and benefits.
* Up to **20 days of vacation per year**.
* Term life insurance.
* Business travel insurance.
* Statutory benefits applicable in the Netherlands.
* Opportunities for professional development, upskilling, and involvement in exciting projects.
* Employee benefits are governed by internal policy and applicable local laws.
## Additional Information
HCLTech is described in the source listing as a global technology company operating across digital, engineering, cloud, and AI services and products.
The role involves collaboration with security teams, audited security controls, tenant isolation, credential management, logging, and compliance-focused platform engineering.
The source also describes a supportive, diverse, and global team environment and opportunities to contribute to company and social initiatives.