Kubernetes Engineer (Istio Specialist) – EKS & OKE
Experience: 7–9 Years
Primary Skills: Kubernetes, Istio, AWS EKS, Oracle OKE, Terraform, Helm, GitOps, Service Mesh
Role Overview
We are seeking an experienced Kubernetes Engineer with strong Istio expertise to design, implement, and optimize cloud-native microservices platforms across Amazon EKS and Oracle OKE.
The role focuses on Kubernetes platform engineering, service mesh architecture, cloud networking, security, automation, and observability. The ideal candidate will have hands-on experience operating Istio in production environments and building secure, resilient, and scalable Kubernetes platforms across multi-cluster and multi-cloud environments.
Key Responsibilities
Kubernetes Platform Engineering
Deploy, configure, manage, and scale Kubernetes clusters on AWS EKS and Oracle OKE.
Automate Kubernetes cluster provisioning and lifecycle management using Terraform, Helm, GitLab, Argo CD, Flux, or similar tools.
Optimize cluster performance, workload scheduling, autoscaling, node pools, resource utilization, and overall platform reliability.
Implement GitOps-based approaches for Kubernetes configuration and application deployments.
Istio Service Mesh
Design, deploy, configure, and manage Istio service mesh in production Kubernetes environments.
Implement Istio across multi-cluster and multi-cloud architectures.
Configure advanced traffic-management capabilities including canary releases, blue/green deployments, traffic splitting, fault injection, retries, timeouts, and circuit breaking.
Implement mTLS, zero-trust networking, authorization policies, and service-to-service security.
Configure and manage Istio ingress and egress gateways.
Troubleshoot and optimize Envoy sidecars and proxy configurations.
Develop and maintain Istio resources such as VirtualServices, DestinationRules, Gateways, and AuthorizationPolicies.
Cloud-Native Networking & Security
Design and implement Kubernetes networking, service discovery, network policies, ingress/egress, and secure communication patterns.
Work with AWS and OCI networking services, including VPCs, subnets, load balancers, security groups/security lists, and NSGs.
Integrate Istio with identity and authentication technologies such as OIDC, OAuth2, SPIFFE, and SPIRE.
Implement secure service-to-service communication and zero-trust architecture across Kubernetes workloads.
Support Kubernetes CNI and cloud networking integrations.
Observability & Reliability
Build comprehensive monitoring and observability solutions using Prometheus, Grafana, Kiali, Jaeger/Zipkin, AWS CloudWatch, and OCI Monitoring.
Monitor service mesh traffic, application performance, latency, errors, and service dependencies.
Troubleshoot Kubernetes and Istio issues including routing failures, connectivity problems, latency, sidecar performance, and service-to-service communication failures.
Define and implement SLIs, SLOs, error budgets, alerts, and reliability metrics.
Perform root-cause analysis and support production incident resolution.
Automation & DevOps
Integrate Kubernetes and Istio configurations with CI/CD and GitOps pipelines.
Automate cluster operations, service mesh configuration, deployments, and operational activities using Python, Bash, or Go.
Build reusable automation and platform capabilities to improve developer productivity.
Enable self-service platform capabilities for application and development teams.
Collaborate with DevOps, SRE, security, application, and cloud infrastructure teams.
Required Skills & Qualifications
7–9 years of experience in Kubernetes, cloud infrastructure, DevOps, SRE, or platform engineering.
Strong hands-on experience with Kubernetes platform engineering and production cluster operations.
Proven production experience implementing and managing Istio Service Mesh.
Strong knowledge of Amazon EKS and Oracle OKE architecture and operations.
Deep understanding of Envoy Proxy, service mesh architecture, and microservices communication patterns.
Strong experience with Terraform, Helm, GitOps, Argo CD/Flux, and YAML-based configuration management.
Strong understanding of Kubernetes and cloud networking concepts, including VPC, CNI, DNS/service discovery, ingress/egress, network policies, and load balancers.
Experience implementing mTLS, zero-trust networking, authentication, authorization, and security policies.
Hands-on experience with observability technologies such as Prometheus, Grafana, Kiali, and Jaeger/Zipkin.
Good scripting and automation skills using Python, Bash, or Go.
Strong troubleshooting skills across Kubernetes, Istio, networking, and cloud infrastructure.
Preferred Qualifications
Experience designing and supporting multi-cluster, multi-region, or multi-cloud service mesh environments.
Knowledge of AWS App Mesh or OCI Service Mesh.
Familiarity with SPIFFE/SPIRE workload identity frameworks.
Experience with container and Kubernetes security tools such as Falco, Trivy, Aqua Security, or Prisma Cloud.
Experience implementing platform engineering and developer self-service capabilities.
Relevant certifications such as:
CKA / CKAD / CKS
AWS Certified Solutions Architect / DevOps Engineer
Oracle Cloud Infrastructure (OCI) Architect
Key Technical Skills
Kubernetes | Istio | AWS EKS | Oracle OKE | Envoy | Terraform | Helm | Argo CD | Flux | GitOps | Prometheus | Grafana | Kiali | Jaeger | CloudWatch | OCI Monitoring | mTLS | Zero Trust | VPC | CNI | CI/CD | Python | Bash | Go | SPIFFE/SPIRE