Istio Mesh Engineer


TechClub Inc.
Dice Job Match Score™
🤯 Applying directly to the forehead...
Job Details
Skills
- Istio
- YAML
Summary
Role: Istio Mesh Engineer
Location: Dallas, TX /Remote
Job Description:
· Design, deploy, and operate Istio service mesh on AKS (ingress/egress gateways, traffic shifting, retries/timeouts, circuit breaking).
· Enforce zero-trust service-to-service security with MTLS, Authorization Policy, PeerAuthentication, and RequestAuthentication.
· Drive kubenet → Azure CNI transition (including Azure CNI Overlay), with IP planning, subnetting, IPAM, and routing/NSG alignment.
· Implement and validate Kubernetes Network Policies (Cilium/Calico) to restrict east-west traffic and control egress.
· Kubernetes/Platform, strong Istio (prod ops), Gateway API migrations, and aware of Azure networking (VNets, UDR, NSG, NAT, Private Link).
· Establish compliant egress architectures (NAT Gateway, Istio egress gateway, Private Link) and DNS patterns (CoreDNS + Private DNS Zones).
· Build GitOps workflows (Argo CD/Flux) for mesh, Gateway API, and policy manifests; manage lifecycle via Helm/Kustomize.
· Define lac with Terraform/Bicep for AKS, networking, identity, and Key Vault; integrate with Azure DevOps/GitHub Actions pipelines.
· Configure PKI/certificates for mesh (Istio CA, cert-manager with Azure Key Vault), TLS termination, and automated rotation.
· Stand up observability: PrometheGrafana, OpenTelemetry/Jaeger, Azure Monitor/Log Analytics; publish SLOs, alerts, and runbooks.
· Gatekeeper/Kyverno), and DR drills. Perform security hardening (CIS benchmarks), policy enforcement (OPA
· Partner with app teams to refactor ingress to Gateway/HTTPRoute, implement canary/blue-green (Argo Rollouts/Flagger), and document patterns.
· Tooling & languages: YAML/bash plus Go or Python; hands-on with Azure AD/Entra, Azure Workload Identity, Key Vault, and eBPF/Cilium.
Roles & Responsibilities
· Design, deploy, and operate Istio service mesh on AKS (ingress/egress gateways, traffic shifting, retries/timeouts, circuit breaking).
· Enforce zero-trust service-to-service security with MTLS, Authorization zationPolicy. Policy, Peer Authentication, and Request Authentication.
· Drive kubenet → Azure CNI transition (including Azure CNI Overlay), with IP planning, subnetting, IPAM, and routing/NSG alignment.
· Implement and validate Kubernetes Network Policies (Cilium/Calico) to restrict east-west traffic and control egress.
· Establish compliant egress architectures (NAT Gateway, Istio egress gateway, Private Link) and DNS patterns (CoreDNS + Private DNS Zones).
· Build GitOps workflows (Argo CD/Flux) for mesh, Gateway API, and policy manifests; manage lifecycle via Helm/Kustomize.
· Define lac with Terraform/Bicep for AKS, networking, identity, and Key Vault; integrate with Azure DevOps/GitHub Actions pipelines.
· Configure PKI/certificates for mesh (Istio CA, cert-manager with Azure Key Vault), TLS termination, and automated rotation.
· Stand up observability: PrometheGrafana, OpenTelemetry/Jaeger, Azure Monitor/Log Analytics; publish SLOs, alerts, and runbooks.
· Perform security hardening (CIS benchmarks), policy enforcement (OPA Gatekeeper/Kyverno), and DR drills.
· Partner with app teams to refactor ingress to Gateway/HTTPRoute, implement canary/blue-green (Argo Rollouts/Flagger), and document patterns.
· Tooling & languages: YAML/bash plus Go or Python; hands-on with Azure AD/Entra, Azure Workload Identity, Key Vault, and eBPF/Cilium.
- Dice Id: 90979514
- Position Id: 8922673
- Posted 1 day ago
Company Info
TechClub Inc. renders avant-garde IT solutions to corporations. We provide exhaustive managed IT services that make us the perfect technology partners for our customers. TechClub Inc. is committed to designing critical information and maintaining a professional standard. We use cutting-edge digital approaches and maintain an open mindset to constantly innovate. Our objective is to guarantee customer satisfaction with our services. We are committed to providing post-implementation support and delivering expert IT solutions to over 50+ customers worldwide to improve and optimize operations.
TechClub Inc. was founded in 2014 and is based in Lincolnshire. We are a Google partner company, offering cost-effective, innovative, and sustainable web solutions with the slogan: “Imagination, Meets Implementation”. Our focused working strategy has made a considerable impact in the industry.
Mission
Our uncompromised, technology-agnostic guidance and implementation services are always delivered by senior IT leaders; we never razzle-dazzle and we never leave you with a solution we wouldn’t gladly support for the long run. Our commitment to customer results is unpaired in the industry – delivering unique attention and value to every client, every minute.
Vision
Our vision is to be a top player in the global market by accentuating constant innovation and delivering cost-efficient and typical IT solutions to our clients through technology leadership, creativity, and a devoted workforce.

Similar Jobs
It looks like there aren't any Similar Jobs for this job yet.
Search all similar jobs