FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Principal Kubernetes Platform Engineer
Mastercard. Own and operate AWS EKS clusters, including upgrades, node groups, managed add-ons, logging, and capacity planning .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in managing AWS EKS clusters, including security compliance, IAM roles, and infrastructure as code using AWS CDK. Proficient in authoring Helm charts, implementing GitOps practices, and collaborating with application teams to ensure platform reliability and security.
Highest-signal resume keywords
AWS EKS ManagementHelm Chart AuthoringKubernetes Security ComplianceGitOps Delivery with ArgoCDAWS CDK Infrastructure Development
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
KubernetesHelmAWS CDKIAM/IRSA RolesKMS Key PoliciesDockerPostgreSQLKafkaRedisPCI DSS Compliance
Soft Skills
MentoringCollaborationLeadership
Tools & Technologies
AWSArgoCDGitHubJenkinsCloudWatchPrometheusGrafanaSageMakerBedrockMLflow
Industry Keywords
Pod Security StandardsNetwork PoliciesECR ManagementSupply Chain SecurityRegulatory Security Standards
Tech Stack
Tools & technologiesAWSAzureDNSDynamoDBFluxGrafanaGRPCJavaJenkinsKafkaKubernetesNode.jsPostgresPrometheusRedisRustTypeScriptC++Go
About the role
Key responsibilities & impact- Own and operate AWS EKS clusters, including upgrades, node groups, managed add-ons, logging, and capacity planning
- Author, maintain, and review Helm charts for application services, Kafka, Redis, PostgreSQL, and observability layers
- Design and implement IAM/IRSA roles, KMS key policies, and Secrets Manager integrations using least-privilege principles
- Enforce platform security standards, Pod Security Standards, Network Policies, container hardening, and PCI DSS 3.2.1 compliance gates
- Manage ECR image registry, scanning policies, base image governance, and lifecycle rules
- Build and maintain AWS CDK infrastructure constructs for EKS, MSK, S3, RDS, DynamoDB, Secrets Manager, VPC, and supporting services
- Define and operate ingress patterns, AWS ALB, ACM certificates, Route 53 DNS, and External Secrets Operator
- Lead platform security reviews and validate infrastructure changes against compliance standards
- Collaborate with Rust, Go, Java, and C++ application teams to onboard workloads and resolve platform issues
- Drive GitOps delivery with ArgoCD, CI/CD integration, and feature branch release workflows
- Define platform standards, runbooks, and onboarding guides
- Serve as platform SME, mentor engineers, lead design discussions, and make AWS platform architecture decisions
- Design, code, prototype, and validate core Decision Management Platform capabilities using AI-assisted development tools
Requirements
What you’ll need- Deep knowledge of Kubernetes node groups, OIDC provider, Pod Identity/IRSA, cluster autoscaler, and EKS upgrade operations
- Experience authoring multi-environment Helm charts, value layering strategies, and Helmfile or ArgoCD-based GitOps delivery
- Experience converting AKS/Azure chart patterns to AWS EKS equivalents
- Experience with IRSA design, KMS CMK policies, Secrets Manager, External Secrets Operator, Pod Security Standards, Network Policies, and PCI DSS compliance
- Experience operating under regulatory security standards
- Experience with VPC design, private subnets, ALB ingress controller, ACM certificates, Route 53, External-DNS, PrivateLink, and security groups
- Experience with ECR management, image scanning, multi-stage Dockerfiles, non-root containers, read-only root filesystems, and supply chain security
- Experience authoring Jenkins pipelines, Bitbucket/GitHub pull request workflows, ArgoCD or Flux, feature branch strategies, and pre-push security gates
- Experience with CloudWatch Container Insights, ADOT, Prometheus, Grafana, and distributed tracing on EKS
- Preferred: AWS CDK TypeScript and CDK L3 constructs
- Preferred: Kafka on Kubernetes, topic and consumer group operations, and TLS/SASL authentication
- Preferred: PostgreSQL/RDS/Aurora, DynamoDB, and Redis Enterprise
- Familiarity with Rust, Go, Java/Flink, C++, Dockerfiles, gRPC/protobuf, and multi-language build pipelines preferred
- Basic familiarity with SageMaker, Bedrock, or MLflow workloads on EKS is a plus
- Must comply with Mastercard security policies, protect information confidentiality and integrity, report suspected violations, and complete mandatory security training
Benefits
Comp & perks- Annual bonus or commissions may be available depending on the role
- Medical, prescription drug, dental, vision, disability, and life insurance
- Flexible spending account and health savings account
- 16 weeks of new parent leave
- Up to 20 days of bereavement leave
- 80 hours of Paid Sick and Safe Time
- 25 days of vacation time
- 5 personal days
- 10 annual paid U.S. observed holidays
- 401k with a best-in-class company match
- Deferred compensation for eligible roles
- Fitness reimbursement or on-site fitness facilities
- Tuition reimbursement eligibility