Senior Cloud Platform Architect - AWS
Opplane - San Francisco Bay Area
Hiring: Senior Cloud Platform Architect - AWS Company: Opplane Location: San Francisco Bay Area Job Posted Time: 2026-09-17 10:02:09 Employment Type: Contract / Remote Target Skills & Keywords : API Gateway, AWS, EKS, Git, GitLab CI, GitOps, Grafana, HTTP/2, Helm, Honeycomb, IAM, IaC, Istio, Java, Kinesis, Kubernetes, OpenTelemetry, Protobuf, REST, S3, SOC 2, Service Mesh, Splunk, Spring Boot, Terraform, VPC, gRPC About the job Experience: •12+ years in software, infrastructure, or platform engineering, including 5+ years of hands-on production Kubernetes on AWS — EKS architecture, operations, networking, upgrades, scaling, and incident troubleshooting. Required Skills: •EKS platform. A repeatable, multi-AZ EKS Auto Mode foundation and golden path — VPC CNI, Karpenter, KEDA, reusable Terraform/Helm/Kustomize modules — implemented, documented, and operable by SRE. •GitOps delivery. Flux as the sole production path: continuous reconciliation, signed digest-pinned images, GitLab CI and Artifactory integration, Flagger SLO-gated canaries, no ClickOps. •Service mesh. Istio Ambient — istiod, istio-cni, ztunnel, opt-in waypoints, SPIFFE workload identity, strict mTLS, AuthorizationPolicy, default-deny NetworkPolicy — with measured latency and overhead. •API gateway and containerization. A single governed north-south ingress (Tyk Self-Managed, Operator-driven from Git): authentication, rate limits, routing, REST-to-gRPC transcoding, and migration of existing APIs onto the platform. •Security and audit. Pod Security Standards, Kyverno admission policy, EKS Pod Identity, Secrets Manager/CSI, KMS, cert-manager, image signing and SBOMs — plus a durable billing/audit capture path (Kinesis, Firehose, S3 Object Lock) with an approved, load-tested reliability contract. •Contracts and operations. gRPC/Protobuf as the east-west standard with buf breaking-change checks; SLOs, error budgets, and OpenTelemetry-based metrics, logs, and traces built into the platform. •Technical leadership. Architecture decision records, threat models, and standards; coaching platform, SRE, and application engineers; representing Opplane in client architecture reviews. Qualifications: •A proven track record of standing up EKS platforms end to end and containerizing existing API workloads onto them at enterprise scale. •Strong IaC and Kubernetes configuration skills (Terraform, Helm, Kustomize) and reusable platform-module design, with defensible architecture decisions and cross-team leadership in a regulated environment. •Production service mesh ownership — Istio architecture, policy, rollout, performance, troubleshooting; Ambient mode especially relevant. •Deep GitOps experience with continuous reconciliation, drift management, and environment promotion; able to implement the target model in Flux. •Practical Kubernetes and AWS security: PSS, policy as code, NetworkPolicy, IAM, Pod Identity, KMS, certificate management, image signing, SBOMs. •API gateway and regulated audit/event-ingestion design; able to own a self-managed gateway (direct Tyk experience strongly preferred). •Solid functional working knowledge of gRPC, HTTP/2, and Protobuf, plus enough Java 21 / Spring Boot familiarity to review the reference runtime pattern. •Observability depth across metrics, logs, traces, SLOs, and rollout analysis with OpenTelemetry; performance validation at tens of thousands of TPS. •Tyk Operator/Pump and custom Go or gRPC plugins •Kinesis/Firehose/S3 Object Lock compliance-grade event capture Compensation: •Flexible work environment (work from home / hybrid options) Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!