DevOps Engineer
Abbott · Los Angeles, CA · 1 wk ago
EngineeringContract
Responsibilities
- Administer self-hosted Kubernetes clusters, including lifecycle management, upgrades, node maintenance, and workload troubleshooting
- Assess and implement Kubernetes RBAC, auditing existing roles and bindings against least privilege standards
- Maintain and extend our Ansible automation, which drives cluster provisioning and configuration management across the environment
- Administer on-premises Azure DevOps Server, including pipeline design and maintenance, agent pools, project administration, and permissions configuration
- Build and troubleshoot CI/CD pipelines end to end, deploying into the on-prem Kubernetes environment with integrated Harbor image workflows
- Administer our on-prem Harbor registry, including project configuration, image scanning, vulnerability policy enforcement, and retention
- Manage TLS certificates within the clusters, including issuance, rotation, and renewal automation via cert-manager or equivalent
- Perform Azure administration and cost management, producing spend forecasts and optimization recommendations leadership can act on
- Conduct security operations, including least privileged access assessments across Kubernetes, Azure DevOps, and Azure, and vulnerability remediation informed by Harbor scan results and CIS Kubernetes benchmarks
- Maintain and extend dashboards and alerting in our observability stack (Grafana, Prometheus, Loki, OpenTelemetry) and use it for day-to-day troubleshooting
- Provide direct support to developers and users, including onboarding, access troubleshooting, and process documentation
Requirements
- Proven hands-on experience administering on-premises, self-hosted Kubernetes clusters
- Cloud-managed Kubernetes experience alone (AKS, EKS, GKE) will not translate to this environment
- Strong Ansible experience, including playbook and role development and maintaining established automation
- Experience administering on-premises Azure DevOps Server, including pipelines, agents, and permissions
- Kubernetes RBAC implementation and access control assessment experience
- TLS certificate management within Kubernetes (cert-manager or equivalent)
- Azure administration experience, including cost analysis and projection
- Security operations experience, including least privilege assessments and vulnerability remediation
Preferred Qualifications
- Terraform experience, as future adoption is under consideration
- Azure Key Vault, particularly secrets integration with pipelines and workloads
- Identity federation with Azure AD / Entra ID across Kubernetes, Azure DevOps, and supporting services
- Harbor registry administration
- Experience with Grafana, Prometheus, Loki, and OpenTelemetry
- Certifications such as CKA or AZ-400