Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Mastercard

Principal Kubernetes Platform Engineer

Mastercard

. Own and operate AWS EKS clusters, including upgrades, node groups, managed add-ons, logging, and capacity planning .

Posted 10/3/2026full-timeUnited StatesLead💰 $195,000 - $323,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in managing AWS EKS clusters, including security compliance, IAM roles, and infrastructure as code using AWS CDK. Proficient in authoring Helm charts, implementing GitOps practices, and collaborating with application teams to ensure platform reliability and security.

Highest-signal resume keywords
AWS EKS ManagementHelm Chart AuthoringKubernetes Security ComplianceGitOps Delivery with ArgoCDAWS CDK Infrastructure Development

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
KubernetesHelmAWS CDKIAM/IRSA RolesKMS Key PoliciesDockerPostgreSQLKafkaRedisPCI DSS Compliance
Soft Skills
MentoringCollaborationLeadership
Tools & Technologies
AWSArgoCDGitHubJenkinsCloudWatchPrometheusGrafanaSageMakerBedrockMLflow
Industry Keywords
Pod Security StandardsNetwork PoliciesECR ManagementSupply Chain SecurityRegulatory Security Standards

Tech Stack

Tools & technologies
AWSAzureDNSDynamoDBFluxGrafanaGRPCJavaJenkinsKafkaKubernetesNode.jsPostgresPrometheusRedisRustTypeScriptC++Go

About the role

Key responsibilities & impact
  • Own and operate AWS EKS clusters, including upgrades, node groups, managed add-ons, logging, and capacity planning
  • Author, maintain, and review Helm charts for application services, Kafka, Redis, PostgreSQL, and observability layers
  • Design and implement IAM/IRSA roles, KMS key policies, and Secrets Manager integrations using least-privilege principles
  • Enforce platform security standards, Pod Security Standards, Network Policies, container hardening, and PCI DSS 3.2.1 compliance gates
  • Manage ECR image registry, scanning policies, base image governance, and lifecycle rules
  • Build and maintain AWS CDK infrastructure constructs for EKS, MSK, S3, RDS, DynamoDB, Secrets Manager, VPC, and supporting services
  • Define and operate ingress patterns, AWS ALB, ACM certificates, Route 53 DNS, and External Secrets Operator
  • Lead platform security reviews and validate infrastructure changes against compliance standards
  • Collaborate with Rust, Go, Java, and C++ application teams to onboard workloads and resolve platform issues
  • Drive GitOps delivery with ArgoCD, CI/CD integration, and feature branch release workflows
  • Define platform standards, runbooks, and onboarding guides
  • Serve as platform SME, mentor engineers, lead design discussions, and make AWS platform architecture decisions
  • Design, code, prototype, and validate core Decision Management Platform capabilities using AI-assisted development tools

Requirements

What you’ll need
  • Deep knowledge of Kubernetes node groups, OIDC provider, Pod Identity/IRSA, cluster autoscaler, and EKS upgrade operations
  • Experience authoring multi-environment Helm charts, value layering strategies, and Helmfile or ArgoCD-based GitOps delivery
  • Experience converting AKS/Azure chart patterns to AWS EKS equivalents
  • Experience with IRSA design, KMS CMK policies, Secrets Manager, External Secrets Operator, Pod Security Standards, Network Policies, and PCI DSS compliance
  • Experience operating under regulatory security standards
  • Experience with VPC design, private subnets, ALB ingress controller, ACM certificates, Route 53, External-DNS, PrivateLink, and security groups
  • Experience with ECR management, image scanning, multi-stage Dockerfiles, non-root containers, read-only root filesystems, and supply chain security
  • Experience authoring Jenkins pipelines, Bitbucket/GitHub pull request workflows, ArgoCD or Flux, feature branch strategies, and pre-push security gates
  • Experience with CloudWatch Container Insights, ADOT, Prometheus, Grafana, and distributed tracing on EKS
  • Preferred: AWS CDK TypeScript and CDK L3 constructs
  • Preferred: Kafka on Kubernetes, topic and consumer group operations, and TLS/SASL authentication
  • Preferred: PostgreSQL/RDS/Aurora, DynamoDB, and Redis Enterprise
  • Familiarity with Rust, Go, Java/Flink, C++, Dockerfiles, gRPC/protobuf, and multi-language build pipelines preferred
  • Basic familiarity with SageMaker, Bedrock, or MLflow workloads on EKS is a plus
  • Must comply with Mastercard security policies, protect information confidentiality and integrity, report suspected violations, and complete mandatory security training

Benefits

Comp & perks
  • Annual bonus or commissions may be available depending on the role
  • Medical, prescription drug, dental, vision, disability, and life insurance
  • Flexible spending account and health savings account
  • 16 weeks of new parent leave
  • Up to 20 days of bereavement leave
  • 80 hours of Paid Sick and Safe Time
  • 25 days of vacation time
  • 5 personal days
  • 10 annual paid U.S. observed holidays
  • 401k with a best-in-class company match
  • Deferred compensation for eligible roles
  • Fitness reimbursement or on-site fitness facilities
  • Tuition reimbursement eligibility