24 sep
|
Cloudera
|
Madrid
Job Description
At Cloudera, we empower people to transform complex data into clear and actionable insights. With as much data under management as the hyperscalers, we're the preferred data partner for the top companies in almost every industry. Powered by the relentless innovation of the open source community, Cloudera advances digital transformation for the world’s largest enterprises.
Business Area
IT
Seniority Level
Mid-Senior level
Job Description
At Cloudera, we empower people to transform complex data into clear and actionable insights. With as much data under management as the hyperscalers, we're the preferred data partner for the top companies in almost every industry. Powered by the relentless innovation of the open source community, Cloudera advances digital transformation for the world’s largest enterprises.
Job Description
About the Team & Role
We are building an enterprise-grade, Everything-as-Code (EaC) Operating Platform that replaces manual IT operations with an automated, zero-trust software factory. As a DevSecOps Platform Engineer , you will be a core builder of our security, networking, and platform control planes. Operating in an environment where all infrastructure, access policies, and network routing exist strictly as version-controlled text artifacts inside Git repositories, you will architect our multi-cloud Kubernetes foundations (AWS EKS / Azure AKS), enforce keyless workload identity, build zero-trust service mesh perimeters, and write active Policy-as-Code (OPA/Rego) pipelines.
As a DevSecOps Platform Engineer, you will:
- Two-Tier IaC Platform Primitives: Design, provision,
and maintain modular Terraform primitives and GitOps patterns for multi-cloud Kubernetes clusters (EKS/AKS), software-defined networks, and pod identity layers.
- Service Mesh & Edge Control Planes: Operate Istio/Envoy service mesh topologies across multi-gateway perimeters (Public Ingress, B2B Ingress, Egress).
- Active Policy-as-Code Gating: Author and maintain Open Policy Agent (OPA / Rego) policies to enforce pre-flight deployment checks, Commit-as-Code format verification, and dynamic Just-in-Time (JIT) time-bound access escalation gates.
- Out-of-Band Telemetry Exhaust: Configure OpenTelemetry (OTel) collectors and Envoy sidecar proxies to emit uniform out-of-band JSON telemetry logs, stamping W3C traceparent headers and system primary keys (UPID, USID, correlation_id, process_id) across all network hops.
- GitOps Scaffolding & Linter Governance: Manage localized pull-based continuous delivery engines (ArgoCD) and construct automated structural linters to enforce the 10-Pillar Application Spoke Repository Standard across all engineering teams.
You may also have:
- Familiarity with CI/CD linter construction for regular expression validation (Commit-as-Code).
- Background working within Hub-and-Spoke repository models and developer portal integrations.
What you can expect from us:
- Generous PTO Policy
- Support work life balance with Unplugged Days
- Adaptable WFH Policy
- Mental & Physical Wellness programs
- Phone and Internet Reimbursement program
- Access to Continued Career Development
- Comprehensive Benefits and Competitive Packages
- Paid Volunteer Time
- Employee Resource Groups
EEO/VEVRAA
#J-18808-Ljbffr
📌 DevSecOps Platform Engineer (Madrid)
🏢 Cloudera
📍 Madrid