RESPONSIBILITIES:
Kforce has a client that is seeking a Senior Kubernetes Engineer/Administrator-Azure AKS in Charlotte, NC.
Responsibilities:
Azure Kubernetes Service (AKS) Management:
* Design, deploy, and manage enterprise-scale AKS clusters across multiple Azure regions
* Implement and maintain private AKS clusters with advanced networking configurations
* Configure and manage customer-managed encryption keys (CMK) for cluster disk encryption
* Implement blue/green deployment strategies for zero-downtime cluster upgrades
* Manage AKS cluster lifecycle including upgrades, node pool scaling, and disaster recovery
* Optimize cluster performance, cost, and resource utilization
* Implement AKS Fleet Manager for multi-cluster management and orchestration
* Configure AKS Automatic for simplified cluster operations and auto-scaling
* Manage AKS Managed Namespaces for improved multi-tenancy and resource isolation
Security & Compliance:
* Implement and maintain private networking architectures with Azure Private Endpoints
* Configure and manage Workload Identity (OIDC) and user-assigned managed identities
* Integrate Azure Policy for governance, compliance, and security enforcement
* Implement Kubernetes RBAC and Azure RBAC integration
* Manage secrets integration with Azure Key Vault using CSI drivers
* Ensure secure communication between AKS and Azure PaaS services
* Implement network policies and pod security standards
REQUIREMENTS:
* Certified Kubernetes Administrator (CKA) or Certified Kubernetes Security Specialist (CKS)
* 5+ years of hands-on Kubernetes experience in production environments
* 2+ years of Azure Kubernetes Service (AKS) experience required
* Experience with private AKS clusters and Azure Private Link/Private Endpoints
* Experience with Azure Key Vault integration (CSI driver, disk encryption sets)
* Hands-on experience with customer-managed encryption keys in Azure
* Experience with Azure Container Registry including geo-replication and vulnerability scanning
* Experience with Linkerd service mesh - deployment, configuration, and troubleshooting
* Experience with AKS Fleet Manager for multi-cluster orchestration
* Experience with Kubernetes operators and Custom Resource Definitions (CRDs)
* Familiarity with AKS Automatic and managed namespace patterns
* Strong Terraform expertise with proven ability to build reusable, production-ready modules
* Deep understanding of Kubernetes architecture, networking, storage, and security
* Proficiency with Azure networking: VNets, subnets, NSGs, private DNS zones, VNet peering
* Strong understanding of Azure managed identities, Workload Identity, and RBAC
* Experience with other cloud platforms (Google Cloud Platform GKE, AWS EKS) is a plus
* Knowledge of AKS advanced features (Fleet Manager, AKS Automatic, Managed Namespaces) is a plus
Infrastructure as Code & Automation:
* Advanced Terraform skills with module development experience
* Git version control and branching strategies (GitHub)
* GitOps tools: ArgoCD
* GitHub Actions for CI/CD pipelines
* Infrastructure testing and validation practices
* Azure CLI and Azure PowerShell
* kubectl, helm, kustomize
* Linux system administration
* Scripting: Bash, Python, or PowerShell
* Container technologies: Docker, container
The pay range is the lowest to highest compensation we reasonably in good faith believe we would pay at posting for this role. We may ultimately pay more or less than this range. Employee pay is based on factors like relevant education, qualifications, certifications, experience, skills, seniority, location, performance, union contract and business needs. This range may be modified in the future.
We offer comprehensive benefits including medical/dental/vision insurance, HSA, FSA, 401(k), and life, disability & ADD insurance to eligible employees. Salaried personnel receive paid time off. Hourly employees are not eligible for paid time off unless required by law. Hourly employees on a Service Contract Act project are eligible for paid sick leave.
Note: Pay is not considered compensation until it is earned, vested and determinable. The amount and availability of any compensation remains in Kforce's sole discretion unless and until paid and may be modified in its discretion consistent with the law.
This job is not eligible for bonuses, incentives or commissions.
Kforce is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.
By clicking ?Apply Today? you agree to receive calls, AI-generated calls, text messages or emails from Kforce and its affiliates, and service providers. Note that if you choose to communicate with Kforce via text messaging the frequency may vary, and message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You will always have the right to cease communicating via text by using key words such as STOP.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
- Dice Id: kforcecx
- Position Id: ITEQG2187205
- Posted 1 day ago