
Principal Kubernetes Platform Engineer
Mastercard1 day ago
Base Salary
$170k - $323k/yr
Responsibilities
- Own and operate AWS EKS clusters, including upgrades, node groups, managed add-ons, logging, and capacity planning.
- Author and maintain Helm charts for application services, infrastructure, and observability layers.
- Implement IAM/IRSA, KMS policies, Secrets Manager integration, Pod Security Standards, Network Policies, container hardening, and PCI DSS compliance gates.
- Manage ECR registries, image scanning, base image governance, lifecycle rules, and container supply-chain security.
- Build AWS CDK infrastructure constructs for EKS, MSK, S3, RDS, DynamoDB, Secrets Manager, VPC, and supporting services.
- Define ingress and networking patterns using ALB, ACM, Route 53, External Secrets Operator, External-DNS, PrivateLink, and security groups.
- Drive GitOps delivery through ArgoCD, CI/CD integrations, pull-request workflows, and feature-branch release processes.
- Operate and improve observability using CloudWatch Container Insights, ADOT, Prometheus, Grafana, and distributed tracing.
- Onboard application workloads, resolve platform-level issues, document standards and runbooks, mentor engineers, and lead architecture discussions.
Requirements
- Deep Kubernetes and EKS experience, including node groups, OIDC, Pod Identity/IRSA, cluster autoscaling, and upgrade operations.
- Experience authoring multi-environment Helm charts and using Helmfile or ArgoCD-based GitOps delivery.
- Experience with AWS security controls including IRSA, KMS, Secrets Manager, External Secrets Operator, Pod Security Standards, Network Policies, and PCI DSS compliance.
- Experience with AWS networking, VPCs, private subnets, ALB ingress, ACM, Route 53, External-DNS, PrivateLink, and security groups.
- Experience managing ECR, image scanning, multi-stage Dockerfiles, non-root containers, read-only root filesystems, and supply-chain security.
- Experience authoring Jenkins pipelines and using Bitbucket or GitHub pull-request workflows, ArgoCD or Flux, and security gates.
- Experience with CloudWatch Container Insights, ADOT, Prometheus, Grafana, and distributed tracing on EKS.
- Preferred: AWS CDK with TypeScript, Kafka on Kubernetes, PostgreSQL or Aurora, DynamoDB, Redis Enterprise, Rust, Go, Java or Flink, C++, Dockerfiles, gRPC/protobuf, and multi-language build pipelines.
- Preferred: familiarity with SageMaker, Bedrock, or MLflow workloads running on EKS.
Benefits
- Full-time employee benefits generally include medical, prescription drug, dental, vision, disability, and life insurance.
- Benefits include flexible spending and health savings accounts, paid leave, 401(k) matching, deferred compensation for eligible roles, fitness reimbursement or on-site fitness facilities, tuition reimbursement, and paid holidays.
- Benefits include 16 weeks of new parent leave, up to 20 days of bereavement leave, 80 hours of Paid Sick and Safe Time, 25 vacation days, and 5 personal days, prorated by hire date.
- The posting covers Arlington, Virginia and remote positions in Georgia, Illinois, Michigan, Missouri, New Jersey, New York, North Carolina, Texas, and Virginia.
- This posting is not for a current vacancy and is intended to collect resumes for future opportunities.
Tech Stack
Amazon DynamoDBApache FlinkApache KafkaAWSC++DockerGoGrafanagRPCHelmJavaJenkinsKubernetesMLflowPostgreSQLPrometheusRedisRustTypeScript
Categories
About Mastercard
Mastercard builds and operates a global payments network used by banks, merchants, fintechs, and governments, offering card processing, real-time payments, tokenization, and fraud/risk services. It generates revenue from transaction processing and assessment/service fees across more than 200 countries and territories. Founded in 1966 and headquartered in Purchase, New York, Mastercard is a public company listed on the NYSE (ticker: MA).