WLG

Kubernetes Platform Operations and Maintenance Expert for NATO with security clearance

WLG Brussels, Brussels-Capital, Belgium

Financial Services · 2-10 employees

5 h ago
kubernetes Mid (2-5 yrs) Full-time Belgium
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The role involves daily monitoring of cluster health, node lifecycle management, and maintaining Kubernetes components like CNI, CSI, and ingress. Additionally, the expert is responsible for security compliance, vulnerability remediation, and producing monthly reports on cluster performance and configuration.

What they look for

Kubernetes Platform Operations SUSE RKE2 Prometheus Grafana Cilium CNI ArgoCD GitOps Harbor Cert-manager Velero Vulnerability Scanning RBAC Administration Network Policy Management Security Compliance

Requirements

Candidates must have at least three years of hands-on Kubernetes operations experience and a university degree or equivalent. A valid security clearance and citizenship of a NATO member country are mandatory requirements for this position.

Full description

A NATO organisation in Brussels runs its own Kubernetes platform on premise, and itis looking for the person who keeps it healthy. This is a pure platform-operations role: theclusters, the tooling inside them, and the monthly evidence that the whole thing is compliant andunder control. Application development and the underlying virtual, storage and networkinfrastructure sit with other teams.

What you would be doing

  • Daily monitoring of cluster health and alerts, and node lifecycle operations — join, drain,cordon, replacement.
  • Managing the Kubernetes components: CNI, CSI, ingress, metrics server and CoreDNS.
  • Certificate rotation and secrets management, RBAC administration with periodic audits, andnetwork policy management.
  • Upgrades and patching, including quarterly upgrade readiness.
  • Vulnerability scanning and remediation inside the cluster.
  • Backup operations with Velero or K10 (disaster recovery testing stays with the customer).
  • Maintaining documentation and runbooks, and helping application teams troubleshoot theirdeployments.
  • Producing the monthly artefacts: cluster health, security compliance (CIS benchmarks, RBACaudit, network policy, vulnerabilities), capacity and performance, patching and upgrades,incidents and root cause analysis, configuration drift against the approved baseline, the changelog and the risk register.

The stack inside the cluster

  • Prometheus and Grafana, a logging stack, NGINX or another ingress, Cilium CNI.
  • Backup tooling, an on-premise registry such as Harbor or SUSE, ArgoCD for GitOps, metricsserver, cert-manager and Zabbix integration hooks.

What they are looking for

  • A university degree plus three years of relevant experience, or the equivalent.
  • Three or more years of hands-on Kubernetes operations.
  • Experience with SUSE RKE2.
  • Real experience of monitoring, logging, registries, ingress, CNI and backup tooling.
  • Nice to have: an international environment with both military and civilian colleagues, and anunderstanding of NATO's structure.

Practical detail

  • Brussels, Belgium — on site; most daily activity has to be done in theoffice. No travel.
  • 28 September to 31 December 2026, 570 hours in total.
  • You must hold a valid clearance and be a citizen of a NATO member country with the right towork in Belgium.

If you would rather operate a platform properly than build a new one every quarter, this is thekind of role where that is the whole point.

Similar roles