waypointjobs

Mass Digital Health

Principal Security Engineer

boston, MA

Check who can apply and the requirements below before continuing.

About this opportunity

Mass Digital Health lists this Principal Security Engineer opportunity in boston, Massachusetts. Review the employer’s description below for duties, qualifications and application requirements.

Job description

Overview

We are seeking a Senior Kubernetes Engineer to join our global infrastructure team and help scale, automate, and secure our container orchestration environments across on-premises and public cloud platforms. As a Kubernetes specialist, you’ll work closely with DevOps, SRE, and security teams to deliver reliable, self-service, and production-ready Kubernetes clusters that power mission-critical applications.

Responsibilities

Deploy, manage, and upgrade Kubernetes clusters using tools like kubeadm, EKS, AKS, GKE, or Rancher

Implement robust RBAC, network policies, ingress controllers, and security

Design and operate multi-cluster and multi-tenant Kubernetes environments using tools such as Rancher, Fleet, or Spectro Cloud Palette for centralized governance and policy enforcement

Implement tenant isolation, resource quotas, and compliance controls across staging and production clusters

Automate cluster provisioning and application deployment pipelines using Terraform, Helm, and ArgoCD

Build reusable modules for consistent infrastructure delivery across staging and production

Implement Kubernetes Operator patterns and custom controllers (CRDs) to automate operational tasks

CI/CD & Automation

Integrate Kubernetes with modern CI/CD workflows for rapid, safe application delivery

Support GitOps practices and continuous deployment automation

Optimize CI/CD pipelines for multi-environment deployments, progressive delivery, and rollback safety (e.g., canary or blue-green strategies)

Monitoring, Logging & Troubleshooting

Implement observability for Kubernetes using Prometheus, Grafana, Loki, and Fluentd/Fluent Bit

Troubleshoot performance issues, failed pods, memory leaks, and cluster degradation events

Develop resiliency and chaos testing frameworks to validate reliability and failover readiness

Cloud & Hybrid Deployments

Operate Kubernetes workloads across AWS, Azure, GCP, and hybrid/on-prem environments

Use tools like Velero, Kasten, or Stash for backup/restore strategies in Kubernetes

Manage container storage platforms such as Portworx, OpenEBS, or EBS CSI drivers for persistent workloads

Implement disaster recovery runbooks, cross-region replication, and automated failover

Security & Compliance

Implement admission control policies, image scanning, and runtime security with tools like Kyverno, OPA/Gatekeeper, Aqua, or Falco

Enforce CIS Benchmarks, RBAC least privilege, and compliance posture checks using tools like Kubescape or Kube-bench

Integrate secrets management via Vault, External Secrets Operator, or cloud-native secret stores

Collaboration & Support

Partner with application developers, SREs, and security teams to implement best practices

Serve as a technical advisor on cloud-native architectures and containerization

Mentor junior engineers and contribute to a Kubernetes Center of Excellence

Lead architecture reviews, documentation, and standards development for platform operations

Collaborate during infrastructure audits and production rollouts to ensure compliance and readiness

Required Qualifications

8 years of professional technical experience or 6 years plus a Master’s degree

Experience with GitOps tools (ArgoCD, Flux).

Observability tools like Prometheus, Grafana, ELK/EFK stack.

Experience with service mesh technologies (Istio, Linkerd).

Open-source contributions in Kubernetes-related projects

Spectro cloud, Incus, Cloud 9 etc…

Strong knowledge of Kubernetes networking internals, CNI plugins, and eBPF tools (e.g., Cilium)

Proficiency in Go, Python, or Bash scripting for automation and tooling

Experience integrating Kubernetes with enterprise identity providers (OIDC, LDAP, or SSO)

Certifications

Certified Kubernetes Administrator (CKA) – Highly preferred

Certified Kubernetes Application Developer (CKAD)

Certified Kubernetes Security Specialist (CKS)

AWS Certified DevOps Engineer – Professional

Google Professional Cloud DevOps Engineer

HashiCorp Certified: Terraform Associate

Linux Foundation Certified System Administrator (LFCS)

#J-18808-Ljbffr

Worksite address

boston, MA, 02298, US

Who can apply

Review the original listing for work authorization, qualifications and employer requirements.

Ready for your next step?Apply on the official website
Apply on WhatJobs ↗

Explore related searches

Current related jobs

American Honda Motor Co., Inc.

WhatJobs

Senior Product Quality & Root Cause Engineer

haw river, NC

Salary not specified

What Makes a Honda, is Who makes a Honda Honda has a clear vision for the future, and it’s a joyful one.  We are looking for individuals with t…

Listing review due 2026-10-06View job

Avantor

WhatJobs

Process Engineer

carpinteria, CA

See pay details in description

The Opportunity: NuSil (apart of Avantor) is seeking a Process Engineer to be responsible for all phases of silicone products manufacturing…

Listing review due 2026-10-06View job

GE Vernova

WhatJobs

Lead Application Engineer

boston, MA

See pay details in description

Job Description Summary The Lead Application Engineer is an established leader in their respective engineering team. They will drive busine…

Listing review due 2026-10-06View job