Senior Cloud Platform Architect - AWS EKS & API Containerization
Oplane
- Location
- US
- Workplace
- Remote
- Employment
- Full Time
- Salary
- —
Posted 23d ago
Senior Cloud Platform Architect - AWS EKS & API Containeriza
- Values
- Team
- Jobs
- Offices
- Jobs
- >
- Senior Cloud Platform Architect - AWS EKS & API Containerization
Senior Cloud Platform Architect - AWS EKS & API Containerization
- Permanent
- Full-time
- Remote
About the Role
We are looking for a senior, hands-on architect to lead the containerization of a large-scale API estate for an enterprise financial services client and turn an approved AWS EKS reference architecture into a secure, repeatable production platform.
This is an architect-who-builds role
you will write and review Terraform, Helm, Kustomize, Flux, and Istio policy, and stay close enough to the code, pipelines, and operational data to prove the platform works. Application images stay stateless and portable; the platform owns transport security, identity, routing, secrets, telemetry, admission policy, and rate limiting.
Key Responsibilities
- EKS platform. A repeatable, multi-AZ EKS Auto Mode foundation and golden path — VPC CNI, Karpenter, KEDA, reusable Terraform/Helm/Kustomize modules — implemented, documented, and operable by SRE.
- GitOps delivery.
Flux as the sole production path
continuous reconciliation, signed digest-pinned images, GitLab CI and Artifactory integration, Flagger SLO-gated canaries, no ClickOps.
- Service mesh. Istio Ambient — istiod, istio-cni, ztunnel, opt-in waypoints, SPIFFE workload identity, strict mTLS, AuthorizationPolicy, default-deny NetworkPolicy — with measured latency and overhead.
- API gateway and containerization. A single governed north-south ingress (Tyk Self-Managed, Operator-driven from Git): authentication, rate limits, routing, REST-to-gRPC transcoding, and migration of existing APIs onto the platform.
- Security and audit. Pod Security Standards, Kyverno admission policy, EKS Pod Identity, Secrets Manager/CSI, KMS, cert-manager, image signing and SBOMs — plus a durable billing/audit capture path (Kinesis, Firehose, S3 Object Lock) with an approved, load-tested reliability contract.
- Contracts and operations. gRPC/Protobuf as the east-west standard with buf breaking-change checks; SLOs, error budgets, and OpenTelemetry-based metrics, logs, and traces built into the platform.
- Technical leadership. Architecture decision records, threat models, and standards; coaching platform, SRE, and application engineers; representing Opplane in client architecture reviews.
Requirements
- 12+ years in software, infrastructure, or platform engineering, including 5+ years of hands-on production Kubernetes on AWS — EKS architecture, operations, networking, upgrades, scaling, and incident troubleshooting.
- A proven track record of standing up EKS platforms end to end and containerizing existing API workloads onto them at enterprise scale.
- Strong IaC and Kubernetes configuration skills (Terraform, Helm, Kustomize) and reusable platform-module design, with defensible architecture decisions and cross-team leadership in a regulated environment.
- Production service mesh ownership — Istio architecture, policy, rollout, performance, troubleshooting; Ambient mode especially relevant.
- Deep GitOps experience with continuous reconciliation, drift management, and environment promotion; able to implement the target model in Flux.
Practical Kubernetes and AWS security
PSS, policy as code, NetworkPolicy, IAM, Pod Identity, KMS, certificate management, image signing, SBOMs.
- API gateway and regulated audit/event-ingestion design; able to own a self-managed gateway (direct Tyk experience strongly preferred).
- Working knowledge of gRPC, HTTP/2, and Protobuf, plus enough Java 21 / Spring Boot familiarity to review the reference runtime pattern.
- Observability depth across metrics, logs, traces, SLOs, and rollout analysis with OpenTelemetry; performance validation at tens of thousands of TPS.
Nice to Have
- Tyk Operator/Pump and custom Go or gRPC plugins
- Flux image automation
- Flagger progressive delivery
- Kinesis/Firehose/S3 Object Lock compliance-grade event capture
- Graviton, Kubecost/OpenCost and cloud-cost optimization
- Fluent Bit, AMP, Splunk, Honeycomb, Grafana
- PCI-scoped, SOC 2, or fintech platform engineering
- AWS Solutions Architect Professional, CKA/CKS
Other Requirements
Remote within the US, California preferred for occasional client-site workshops and readiness reviews. Requires US Pacific hours overlap, an escalation rotation during build-out, and client background screening. Opplane Inc. is an equal opportunity employer.
About Opplane
Opplane delivers advanced data and platform solutions for financial services, telecommunications, and reg-tech, accelerating their digital transformation. Our leadership team is made up of Silicon Valley serial entrepreneurs and executives with deep experience at PayPal, Xerox PARC, Amazon, Wells Fargo, and SoFi. We are a small, fast-moving, multicultural team that values ownership over formality.
🌍 Global & Multicultural – Diverse perspectives, global collaboration (US, Portugal, India and Singapore offices)
⚡ Startup Energy – Fast-moving, impact-driven environment
💪 Ownership Mindset – Engineers own what they build
🤝 Collaborative & Friendly – Open, curious, and supportive culture
- Permanent
- Full-time
- Remote
Apply now
Apply now
Privacy policy
| Cookie settings
| Powered by Factorial
Build my own jobs page
FACTORIAL uses cookies to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners who may combine it with other information that you've provided to them or that they've collected from your use of their services.
Read more about our Cookies' Policy →
Privacy policy
Manage cookies Reject cookies Accept cookies
This website uses cookies
FACTORIAL uses cookies to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners who may combine it with other information that you've provided to them or that they've collected from your use of their services.
Read more about our Cookies' Policy →
Manage cookies
Necessary
Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Statistics
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Marketing
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.
Preferences
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
Reject cookies Allow selection
Skills
- AWS
- EKS
- Terraform
- Helm
- Kustomize
- Flux
- Istio
- Kubernetes
- VPC CNI
- Karpenter
- KEDA
- GitLab CI
- Artifactory
- Flagger
- Tyk
- gRPC
- HTTP/2
- Protobuf
- Java 21
- Spring Boot
- OpenTelemetry
- PSS
- NetworkPolicy
- IAM
- Pod Identity
- KMS
- cert-manager
- SBOMs
- Kinesis
- Firehose
- S3 Object Lock
- Go
- Graviton
- Kubecost
- OpenCost
- Fluent Bit
- AMP
- Splunk
- Honeycomb
- Grafana
- Kyverno
- Secrets Manager
- CSI
- buf