Kubernetes Network Security Engineer (M/F)
Devoteam is a technology, cloud, cyber, AI, and sustainable development consulting company. With more than 11,000 employees in more than 25 countries, we have been guiding our clients through the technological transformation of their businesses for nearly 30 years. In France, we have 4,500 Digital Architects distributed across more than 50 expertise tribes and coached by more than 400 expert managers. Joining us means: working on innovative and sustainable projects to put Technology at the service of humanity, continuously certifying in new market technologies, and sharing unique moments with colleagues! To find out more about Devoteam, visit here.
We are looking for a Kubernetes Network Security Engineer to design, implement, and maintain secure network infrastructures in our cloud-native environments. You will be responsible for implementing network security policies, observability, and compliance for our clients' Kubernetes clusters in production.
Main Missions:
Network Security and Policies Design and deploy Kubernetes Network Policies to implement a Zero Trust security strategy Define and maintain network segmentation policies between microservices Implement granular network access controls and audit their effectiveness Kubernetes Architecture and Components Secure all control plane components (API Server, etcd, Scheduler, Controller Manager) Harden the configuration of worker nodes and container runtimes The following points would be a real plus: Implement security strategies for Ingress/Egress, Service Mesh, and CNI (Istio is a big plus) Manage TLS certificates and mutual authentication (mTLS) CNI and Cilium Deploy, configure, and maintain Cilium as the primary CNI Configure Cilium Network Policies, CiliumClusterwideNetworkPolicies, and Identity-based policies Observability and Monitoring (bonus) Deploy and maintain an observability stack for the CNI Analyze logs and traces to detect abnormal behavior
Required Skills
Essential: Mastery of Kubernetes Network Policies (namespace-scoped and cluster-scoped) In-depth knowledge of Kubernetes components and their security model (RBAC, Pod Security Standards, Service Accounts) Expertise in Cilium: installation, configuration, network policies, Hubble observability Understanding of CNI (Container Network Interface) concepts and different implementations Experience in observability: metrics, logs, traces, SLI/SLO Knowledge of network protocols (TCP/IP, DNS, HTTP/S, gRPC) Appreciated Assets: Grafana: dashboard creation, datasource configuration, alerting Elasticsearch: log indexing, KQL/Lucene queries, cluster management BGP: peering configuration, route advertisement, integration with Cilium BGP Control Plane Prometheus, Loki, Tempo for cloud-native observability eBPF and XDP technologies Service Mesh (Istio, Linkerd) Vulnerability scanning tools (Trivy, Falco, Tetragon) Profile sought: Master's degree (Bac+5) in computer science, networks, or telecommunications
Minimum 3 years of experience in network administration and/or Kubernetes
Valued Certifications: CKA, CKS, CKAD, network/cloud certifications (CCNP, AWS network)
Ability to script (Python) to automate tasks
Proficiency in technical English
Team spirit, rigor, and analytical skills Technical Environment: Kubernetes (OpenShift)
Cilium CNI
GitOps (ArgoCD)
Infrastructure as Code (Terraform)
CI/CD (GitLab CI)
Observability stack (Prometheus, Grafana, Elasticsearch, Kibana)
Why join us? Career follow-up conducted by a tech manager with regular exchanges;
Technical and soft skills certifications freely accessible with a goal of at least 2 certifications per year, vouchers provided, and expert coaching;
Top-tier technological partners: Google, AWS, Microsoft, ServiceNow, Snowflake, MuleSoft, Outsystems, SAP, Databricks, Gitlab, …;
A trajectory with varied possibilities via geographic, functional, and inter-entity / tribe or squad internal mobility.
Internal roles to build your career within the Group: manager, internal trainer, tech leader, digital champion, squad leader, …
Internal contributions to expand your skills such as school relations, recruitment, sales, writing articles, hosting meetups or communities, …
A strong sense of community through internal events and sporting and cultural activities thanks to more than 30 Happiness@Devoteam clubs, allowing you to meet your colleagues regularly and share your passions;
A Tech for People vision embodied in our values, our responsible practices, our sustainable development program rewarded by the Ecovadis label, and our strong commitments, notably with the Devoteam Foundation.
How does the recruitment process work at Devoteam? It consists of 2 to 3 interviews: Talent Acquisition Interview: the goal is to review your skills, your level of English, and validate your motivations
Tech & Business Interview: this interview aims to deepen your technical skills and verify their suitability for our needs during an exchange with a business expert
Leadership Interview: this allows us to evaluate your potential, your ambitions, and consider your evolution within Devoteam.
We prioritize at least one in-person interview. A reference check is requested and, depending on your profile, tests (technical, English, personality...) may be sent to you. If your application is selected, we will send you a proposal presenting the hiring conditions. Upon acceptance, the employment contract is formalized. If you share our passion for technology and want to build tomorrow's responsible digital world, then you might be the enthusiast we are looking for at Devoteam. The Devoteam Group works for equal opportunity, for the promotion of its employees based on merit, and actively fights against all forms of discrimination. We are convinced that diversity contributes to the creativity, dynamism, and excellence of our organization. All our positions are open to people with disabilities.