Role: ARO Platform Engineering
Duration: 12 Months
Location: Remote
Job Description:
We are seeking an experienced Azure Red Hat OpenShift (ARO) Platform Engineering Consultant to design, implement, and operationalize an enterprise container platform. The consultant will establish the ARO landing zone, Terraform automation framework, GitHub Actions CI/CD standards, security guardrails, RBAC model, and developer self-service capabilities.
This role will partner with Cloud Engineering, DevOps, Security, IAM, and Application teams to create a standardized platform that enables secure and scalable application onboarding while enforcing enterprise governance and compliance requirements.
Roles & Responsibilities
ARO Platform Architecture
Responsibilities
- Design and implement Azure Red Hat OpenShift (ARO) clusters for production and non-production environments.
- Define cluster topology, networking, ingress, egress, and connectivity standards.
- Establish namespace/project provisioning standards.
- Define platform architecture patterns for application onboarding.
- Create reusable reference architectures and design standards.
- Establish disaster recovery and multi-region design patterns.
- Lead technical design reviews and architecture decisions.
Terraform Platform Automation
Responsibilities
- Develop reusable Terraform modules for:
- ARO Clusters
- Namespaces / Projects
- Azure RBAC
- Entra Groups
- Workload Identity
- Key Vault Integration
- Azure Container Registry
- Datadog Monitoring
- Network Connectivity
- Implement Infrastructure as Code standards and governance.
- Manage Terraform state, module versioning, and release processes.
- Establish policy-as-code controls and security baselines.
- Support fully automated environment provisioning.
GitHub & GitHub Actions Enablement
Responsibilities
Design GitHub Enterprise organizational structure.
Define repository standards and governance practices.
Build reusable GitHub Actions workflow templates.
Establish CI/CD deployment standards for ARO-hosted applications.
Implement:
- Branch protections
- Pull request controls
- Security scanning
- Code quality gates
- Artifact signing
- Deployment approvals
- Create self-service onboarding processes for application teams.
- Lead migration from legacy deployment pipelines to GitHub Actions.
Identity, Roles & Privileges
Responsibilities
- Design enterprise RBAC model for ARO.
- Integrate Microsoft Entra ID authentication with OpenShift.
- Define least-privilege access standards.
- Implement Privileged Identity Management (PIM) for elevated access.
- Define role assignments and approval workflows.
- Establish service-account governance and workload identities.
- Support audit and compliance requirements.
- Define and Maintain Platform Roles
Platform Administrator
- Full cluster administration
- Node management
- Operator lifecycle management
- Platform upgrade authority
- PIM-controlled privileged access
- Platform Operations
Monitoring and support
- Platform troubleshooting
- Incident response
- Capacity management
- Application Operations
Namespace administration
- Deployment approvals
- Application support
- Secret rotation management
- Developer
Build and deploy applications
- Manage application resources within assigned namespaces
- View logs and metrics
- Security Administrator
- Security policy management
- Vulnerability oversight
- Compliance reporting
- Audit reviews
- CI/CD Service Accounts
Automated deployment execution
- Infrastructure provisioning
- Pipeline operations
- Read-Only Support
- Operational visibility
- Troubleshooting access
- Monitoring dashboards only
Security & Compliance
Responsibilities
- Implement enterprise security baselines.
- Integrate Azure Key Vault using CSI drivers and workload identity.
- Establish secrets-management standards.
- Design separation-of-duties controls.
- Support regulatory and audit requirements.
- Implement infrastructure scanning and compliance checks within pipelines.
- Work with IAM and Security teams on governance controls.
- 6. Observability & Operations
Responsibilities
- Implement Datadog monitoring standards.
- Define dashboards, alerts, and service-level objectives (SLOs).
- Create operational runbooks.
- Establish platform support and escalation procedures.
- Define capacity planning standards.
- Implement platform health monitoring and reporting.
Developer Platform Enablement
Responsibilities
- Create onboarding processes for application teams.
- Develop deployment patterns and templates.
- Publish engineering standards and documentation.
- Provide platform training and knowledge transfer.
- Support application migration efforts into ARO.
- Drive adoption of self-service platform capabilities.
Required Qualifications:
- 8+ years in Cloud Infrastructure, Platform Engineering, or DevOps.
- 3+ years of Azure Red Hat OpenShift (ARO) or OpenShift experience.
- Expert Terraform development and module design experience.
- Strong GitHub Enterprise and GitHub Actions experience.
Experience with:
- Azure Networking
- Entra ID
- Azure RBAC
- Managed Identity
- Key Vault
- Azure Container Registry
- API Management
- Strong understanding of platform security and least-privilege design.
- Experience implementing enterprise DevSecOps practices.