About The Position

North Point Technology is looking to hire a Senior Platform Engineer with deep expertise in on-premises Kubernetes infrastructure to support a mission-critical enterprise container platform operating in a fully air-gapped, non-cloud environment. This is a short-term contract assignment of approximately seven months. An active Top Secret clearance with SCI eligibility is required upon hire, and the selected candidate must be willing and able to obtain a polygraph within the customer's timeline.

Requirements

  • On-premises Kubernetes cluster deployment and management in production environments (non-cloud, air-gapped)
  • Bootstrapping Kubernetes clusters using Kubespray, kubeadm, or equivalent tools
  • Enterprise Linux system administration including systemd service management and kernel tuning
  • Container runtime installation and configuration: containerd and CRI-O
  • cgroups v2, Linux namespaces, and container isolation management at the OS level
  • OS-level security hardening with AppArmor and SELinux
  • Software-defined storage design and implementation; CSI driver deployment for dynamic persistent volume provisioning
  • High-availability Kubernetes control plane architecture with multi-master nodes and internal load balancers
  • etcd cluster operations: backups, snapshots, restoration, and defragmentation
  • Kubernetes security: RBAC, network policies, pod security standards, admission controllers, and API server auditing
  • Certificate lifecycle management for Kubernetes cluster components and service mesh
  • Ansible automation and Ansible playbook development for infrastructure provisioning
  • GitOps workflows and ArgoCD for declarative, continuous deployment
  • Infrastructure-as-code repository management for repeatable deployments
  • CI/CD pipeline construction for infrastructure testing and validation
  • Air-gapped and offline deployment strategies including Kaniko-based container image builds
  • Cluster administration and debugging using k9s, kubectl, and crictl
  • Troubleshooting static pods: etcd, kube-apiserver, kube-controller-manager, kube-scheduler
  • Scripting in Bash and/or Python for cluster automation
  • Active Top Secret security clearance SCI eligibility
  • Willingness and ability to obtain a CI polygraph within the customer's timeline
  • U.S. citizenship required

Nice To Haves

  • Identity and authorization standards: X.509, SAML, OAuth2, OIDC, LDAP
  • ICAM solution architecture using Oracle or other enterprise-grade identity platforms
  • Master's degree in a STEM field
  • Certified Kubernetes Security Specialist (CKS) certification

Responsibilities

  • Design, deploy, and maintain enterprise-scale Kubernetes clusters built entirely from bare metal in secure, air-gapped data centers.
  • Perform advanced Linux administration including systemd, kernel tuning, and SSH key architecture.
  • Manually install and configure container runtimes (containerd, CRI-O).
  • Implement OS-level security hardening with AppArmor and SELinux.
  • Manage cgroups v2 and container isolation mechanisms.
  • Design and implement software-defined storage solutions.
  • Build distributed storage clusters from raw drives.
  • Deploy Container Storage Interface (CSI) drivers for dynamic volume provisioning.
  • Monitor storage performance and capacity.
  • Bootstrap production Kubernetes clusters from scratch using kubeadm or Kubespray.
  • Design multi-master high-availability control plane architectures.
  • Configure internal load balancers for API server redundancy.
  • Manage etcd operations including backups, snapshots, restoration, and defragmentation.
  • Implement RBAC policies, network policies, pod security standards, admission controllers, API server auditing, certificate lifecycle management, and vulnerability remediation.
  • Develop Ansible playbooks and Bash/Python scripts for cluster provisioning.
  • Implement GitOps workflows with ArgoCD.
  • Maintain infrastructure-as-code repositories.
  • Build CI/CD pipelines for infrastructure validation.
  • Manage Kaniko-based container image builds in air-gapped environments.
  • Troubleshoot cluster components using k9s, kubectl, and crictl.

Benefits

  • excellent compensation
  • benefits
  • flexible work-life balance
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service