MUST HAVE
• 13+ years in software, infrastructure, or platform engineering, including 5+ years of hands-on production Kubernetes on AWS — EKS architecture, operations, networking, upgrades, scaling, and incident troubleshooting.
• A proven track record of standing up EKS platforms end to end and containerizing existing API workloads onto them at enterprise scale.
• Strong IaC and Kubernetes configuration skills (Terraform, Helm, Kustomize) and reusable platform-module design, with defensible architecture decisions and cross-team leadership in a regulated environment.
• Production service mesh ownership — Istio architecture, policy, rollout, performance, troubleshooting; Ambient mode especially relevant.
• Deep GitOps experience with continuous reconciliation, drift management, and environment promotion; able to implement the target model in Flux.
• Practical Kubernetes and AWS security: PSS, policy as code, NetworkPolicy, IAM, Pod Identity, KMS, certificate management, image signing, SBOMs.
• API gateway and regulated audit/event-ingestion design; able to own a self-managed gateway (direct Tyk experience strongly preferred).
• Working knowledge of gRPC, HTTP/2, and Protobuf, plus enough Java 21 / Spring Boot familiarity to review the reference runtime pattern.
• Observability depth across metrics, logs, traces, SLOs, and rollout analysis with OpenTelemetry; performance validation at tens of thousands of TPS.