RHEL & OCP Specialist

Temp agencyZENITH INFOTECH (S) PTE LTD.Singaporemycareersfuturepublished 08/20/2026
Must-have:JavaNode.jsAWSKubernetesCI/CDMicroservicesSecurityPrincipalHybrid

Zenith Infotech (S) Pte Ltd. was started in 1997, primarily with the vision of offering state-of-the-art IT Professionals and solutions to various organizations and thereby helping them increase their productivity and competitiveness. From the deployment of one person to the formation of whole IT teams, Zenith Infotech has helped clients with their staff augmentation needs. Zenith offers the opportunity to be engaged in long term projects with large IT savvy companies, Consulting organizations, System Integrators, Government, and MNCs.

EA Licence No: 20S0237

Roles and Responsibilities:

  • RHEL Platform Management (Primary Focus)
  • Own and maintain the RHEL OS fleet underpinning OCP worker/control-plane nodes and non-containerised application servers
  • Plan and execute RHEL OS patching cycles (EUS channel management, kernel upgrades, reboot sequencing) with minimal service disruption
  • Implement and validate OS hardening benchmarks — SELinux policies, firewalld rules, auditd configuration, and cryptographic policy settings
  • Troubleshoot system-level issues: kernel parameters, resource limits (ulimits, cgroups), storage mounts (NFS, iSCSI, SMB/CIFS PVs on OCP)
  • Manage RHEL subscriptions, entitlements, and satellite/image registries
  • OCP Cluster Administration (Primary Focus)
  • Deploy, upgrade, and maintain OCP 4.x clusters — including control plane, etcd health, and worker node lifecycle
  • Configure and manage OCP Machine Config Operator (MCO) for node-level OS customisation: chrony NTP, SSH hardening, kernel arguments, and custom MachineConfigs
  • Manage cluster certificates, ingress/route configurations, HAProxy timeout tuning for long-running enterprise workloads (e.g., Pega BIX, batch jobs)
  • Administer Quay mirror registry — image mirroring, vulnerability scanning results, VAPT remediation for bundled components (e.g., jQuery CVEs)
  • Implement OCP RBAC, SCCs, network policies, and resource quotas across multiple namespaces and project environments
  • Support JVM and container resource tuning for Java workloads on OCP (heap sizing, Metaspace limits, G1GC flags, container memory budgeting)
  • Application Platform & Integration Support
  • Take ownership of one or more application platforms (e.g., Pega Infinity, WebSphere, IBM MQ) — covering setup in HA mode, application patching, and ongoing operational support
  • Participate in architecture sessions with build teams, advising on integration points (web services, MQ, SFTP, API gateway)
  • Support container provisioning, image lifecycle, and deployment of containerised services across DEV / SIT / UAT / PROD environments
  • Operational Governance & Security
  • Define and execute operational processes: OS patching, application-level patching, performance monitoring, housekeeping, backup and recovery
  • Support VAPT engagements — assess Nessus/vulnerability findings, coordinate remediation, and produce risk acceptance or remediation reports
  • Apply government-grade security hardening principles (IM8 compliance, SSCT framework, CIS benchmarks) across RHEL and OCP layers
  • Contribute to DevSecOps tooling and automation concepts — CI/CD pipelines, IaC, and operational runbooks
  • Support AWS administration tasks where applicable (CloudWatch monitoring, IAM, S3, hybrid integration)

Top 3 Must-Have Skills

  • RHEL System Administration (Required — Primary Differentiator)
  • Hands-on experience administering RHEL 8/9 in enterprise production environments
  • Proficiency in OS-level patching, package management (dnf/yum), SELinux enforcement, and system hardening per CIS/DISA benchmarks
  • Experience with RHEL Extended Update Support (EUS) lifecycle management and version upgrades
  • Familiarity with RHEL subscription management, satellite server, and image-based deployments (RHEL Image Mode / Bootc)
  • OpenShift Container Platform (OCP) Administration (Required — Primary Differentiator)
  • Hands-on experience deploying, configuring, and administering OCP 4.x clusters (bare metal or IaaS)
  • Proficiency with OCP Day-2 operations: node management, Machine Config Operator (MCO), cluster upgrades, certificate rotation, and resource quota management
  • Experience with OCP networking (Routes, Ingress, HAProxy), storage (PV/PVC, storage classes), and role-based access control (RBAC)
  • Familiar with OCP security hardening: SSH cipher/MAC remediation via MCO, SCC policies, network policies, and image vulnerability scanning (Quay/Clair)
  • Experience with Quay registry administration including mirror registry setup for air-gapped or restricted environments
  • Enterprise Container Architecture & Integration Platforms
  • Designing and operating multi-tier containerised architectures on OCP/Kubernetes
  • Working knowledge of IBM MQ messaging — queue manager setup, channel administration, troubleshooting, and HA configuration
  • Familiar with microservices architecture, API gateway integration, and container image lifecycle management

Only shortlisted applicants will be contacted. By submitting your application, you acknowledge and agree that your personal data will be collected, used, and retained in accordance with our Privacy Policy. This information will be used solely for recruitment and employment purposes.