Kubernetes Platform Engineer - Networking & Security

Build the Future of European Cloud Infrastructure

Are you looking for a place where your work truly matters?

At CloudFerro, we build cloud technologies used every day by Europe's leading scientific institutions and space organizations, including ESA, EUMETSAT, ECMWF, Mercator Ocean International, DLR, and EGI. By working closely with the Earth Observation sector, you'll contribute to technologies that help researchers better understand our planet.

If you're passionate about modern cloud technologies, large-scale distributed systems, and solving complex infrastructure challenges in an environment where you can continuously grow and make a real impact, CloudFerro is the place for you.

Learn more: www.cloudferro.com

We are currently building a sovereign European cloud platform from the ground up—creating a true alternative to global hyperscalers.

Our platform is a complete Kubernetes-based, open-source PaaS stack, covering everything from serverless computing and managed databases to MLOps, monitoring, and observability.

Joining us means becoming part of a team that designs the very foundations of the platform rather than extending an existing product. We work with full ownership—every architectural decision you make will shape the platform for years to come. This is a unique opportunity to influence the future of European cloud infrastructure.

Role Overview

As a Platform Network & Security Engineer, you will own the networking and security layer of our PaaS platform.

You will design multi-tenant network architecture, implement tenant isolation, integrate with the underlying IaaS networking stack, and define the platform's network security standards.

Within the team, you will be the primary expert responsible for securing the platform's networking layer. Your architectural decisions will directly protect customer workloads and data.

What You'll Do

·        Design, implement, and maintain the platform networking architecture (CNI, Ingress, Load Balancing).

·        Design and enforce multi-tenant network isolation.

·        Build and maintain admission controllers and policy engines (OPA/Gatekeeper or Kyverno).

·        Review networking architecture for new platform services and components.

·        Implement security hardening practices, including: image scanning pipelines, Pod Security Standards, RBAC reviews.

·        Integrate Kubernetes networking with the underlying IaaS infrastructure. 

What We're Looking For

·        Proven experience designing and implementing Kubernetes networking in production multi-tenant environments.

·        Deep knowledge of Cilium or Calico, including configuration, troubleshooting, and eBPF.

·        Hands-on experience with: Kubernetes Network Policies, multi-tenant isolation.

·        Experience with OPA/Gatekeeper or Kyverno, including writing and maintaining security policies.

·        Strong Go programming skills and working knowledge of Python for developing admission controllers, webhooks, or Kubernetes operators.

·        Comfortable using AI-assisted development tools (such as Claude Code or GitHub Copilot) as part of everyday engineering work. 

Nice to Have

·        Experience with Ingress controllers (NGINX, Envoy, Cilium Ingress) and load balancing.

·        Experience with service mesh technologies (Istio, Linkerd, Cilium Service Mesh).

·        Strong understanding of Kubernetes security: Pod Security Standards, seccomp, AppArmor, container image scanning.

·        Knowledge of BGP, VXLAN, and WireGuard in overlay networking environments.

·        Experience managing DNS in multi-tenant Kubernetes clusters (CoreDNS, ExternalDNS).

·        CKS (Certified Kubernetes Security Specialist) certification.

·        Experience with security audits and compliance frameworks such as SOC 2 or ISO 27001.

·        Experience operating HashiCorp Vault on Kubernetes. 

Why Join CloudFerro?

·        Build a cloud platform from scratch that powers European space programs, climate research, and scientific innovation.

·        Join a newly formed, highly autonomous engineering team.

·        Work with production-grade CNCF technologies including Kubernetes, Knative, Cilium, Argo CD, Kubeflow, and contribute back to open-source projects.

·        Influence architectural and product decisions that will shape the platform for years to come.

·        Work in an AI-native engineering environment where tools like Claude Code are part of everyday development.

·        Enjoy a high level of ownership, autonomy, and long-term career stability.

·        Work remotely, with the option to use our Warsaw office.

·        Receive a comprehensive benefits package including: private healthcare, Multisport card, life insurance, language classes.

ID: 148 job_post.published_on: 24/07/2026
announcement.apply