We are looking for a senior, hands-on architect to lead the containerization of a large-scale API estate for an enterprise financial services client and turn an approved AWS EKS reference architecture into a secure, repeatable production platform. This is an architect-who-builds role: you will write and review Terraform, Helm, Kustomize, Flux, and Istio policy, and stay close enough to the code, pipelines, and operational data to prove the platform works. Application images stay stateless and portable; the platform owns transport security, identity, routing, secrets, telemetry, admission policy, and rate limiting.
• EKS platform. A repeatable, multi-AZ EKS Auto Mode foundation and golden path — VPC CNI, Karpenter, KEDA, reusable Terraform/Helm/Kustomize modules — implemented, documented, and operable by SRE.
• GitOps delivery. Flux as the sole production path: continuous reconciliation, signed digest-pinned images, GitLab CI and Artifactory integration, Flagger SLO-gated canaries, no ClickOps.
• Service mesh. Istio Ambient — istiod, istio-cni, ztunnel, opt-in waypoints, SPIFFE workload identity, strict mTLS, AuthorizationPolicy, default-deny NetworkPolicy — with measured latency and overhead.
• API gateway and containerization. A single governed north-south ingress (Tyk Self-Managed, Operator-driven from Git): authentication, rate limits, routing, REST-to-gRPC transcoding, and migration of existing APIs onto the platform.
• Security and audit. Pod Security Standards, Kyverno admission policy, EKS Pod Identity, Secrets Manager/CSI, KMS, cert-manager, image signing and SBOMs — plus a durable billing/audit capture path (Kinesis, Firehose, S3 Object Lock) with an approved, load-tested reliability contract.
• Contracts and operations. gRPC/Protobuf as the east-west standard with buf breaking-change checks; SLOs, error budgets, and OpenTelemetry-based metrics, logs, and traces built into the platform.
• Technical leadership. Architecture decision records, threat models, and standards; coaching platform, SRE, and application engineers; representing Opplane in client architecture reviews.
• 12+ years in software, infrastructure, or platform engineering, including 5+ years of hands-on production Kubernetes on AWS — EKS architecture, operations, networking, upgrades, scaling, and incident troubleshooting.
• A proven track record of standing up EKS platforms end to end and containerizing existing API workloads onto them at enterprise scale.
• Strong IaC and Kubernetes configuration skills (Terraform, Helm, Kustomize) and reusable platform-module design, with defensible architecture decisions and cross-team leadership in a regulated environment.
• Production service mesh ownership — Istio architecture, policy, rollout, performance, troubleshooting; Ambient mode especially relevant.
• Deep GitOps experience with continuous reconciliation, drift management, and environment promotion; able to implement the target model in Flux.
• Practical Kubernetes and AWS security: PSS, policy as code, NetworkPolicy, IAM, Pod Identity, KMS, certificate management, image signing, SBOMs.
• API gateway and regulated audit/event-ingestion design; able to own a self-managed gateway (direct Tyk experience strongly preferred).
• Working knowledge of gRPC, HTTP/2, and Protobuf, plus enough Java 21 / Spring Boot familiarity to review the reference runtime pattern.
• Observability depth across metrics, logs, traces, SLOs, and rollout analysis with OpenTelemetry; performance validation at tens of thousands of TPS.
Tyk Operator/Pump and custom Go or gRPC plugins
Flux image automation
Flagger progressive delivery
Kinesis/Firehose/S3 Object Lock compliance-grade event capture
Graviton, Kubecost/OpenCost and cloud-cost optimization
Fluent Bit, AMP, Splunk, Honeycomb, Grafana
PCI-scoped, SOC 2, or fintech platform engineering
AWS Solutions Architect Professional, CKA/CKS
Remote within the US, California preferred for occasional client-site workshops and readiness reviews. Requires US Pacific hours overlap, an escalation rotation during build-out, and client background screening. Opplane Inc. is an equal opportunity employer.
Opplane delivers advanced data and platform solutions for financial services, telecommunications, and reg-tech, accelerating their digital transformation. Our leadership team is made up of Silicon Valley serial entrepreneurs and executives with deep experience at PayPal, Xerox PARC, Amazon, Wells Fargo, and SoFi. We are a small, fast-moving, multicultural team that values ownership over formality.
🌍 Global & Multicultural – Diverse perspectives, global collaboration (US, Portugal, India and Singapore offices)
⚡ Startup Energy – Fast-moving, impact-driven environment
💪 Ownership Mindset – Engineers own what they build
🤝 Collaborative & Friendly – Open, curious, and supportive culture