Kubernetes engineer job description template (2026)
A complete Kubernetes engineer job description you can copy, plus seniority levels and tips for hiring someone who runs clusters other teams can depend on.
By the Ryz Labs team · Updated October 2026
A Kubernetes engineer job description should say how many clusters you run, where they run, who deploys to them and what goes wrong today. Running a single managed cluster for one product is a different job from operating a multi-tenant platform for dozens of teams, writing custom operators or managing bare-metal control planes. Candidates also want to know whether you have already chosen your GitOps, networking and policy tools. The template below is written for a senior Kubernetes engineer who owns production clusters and the internal platform that product teams deploy to. Copy it and adjust the bracketed details.
Kubernetes engineer job description template
Job title
Senior Kubernetes Engineer (Platform and Cluster Operations)
Employment type: full-time or contract. Location: remote, with at least four hours of overlap with US Eastern time.
About the role
We are looking for a senior Kubernetes engineer to own the clusters behind [product name]. We run [number] clusters on [EKS / GKE / AKS / self-managed], serving [number] services from [number] product teams. You will be responsible for cluster lifecycle, upgrades, networking, security and the developer experience of deploying to Kubernetes. You will work with platform, security and application engineers and report to [title].
Responsibilities
- Provision and upgrade clusters with infrastructure as code, keeping control planes, node groups and add-ons within supported Kubernetes versions.
- Plan and run minor version upgrades, including deprecated API checks with tools such as Pluto or kubent, and node pool rotations with no customer impact.
- Own the GitOps workflow with Argo CD or Flux, including app-of-apps or ApplicationSet patterns, sync waves and drift alerts.
- Maintain Helm charts or Kustomize bases that product teams use, with sensible defaults for resources, probes, PodDisruptionBudgets and topology spread.
- Design multi-tenancy: namespaces, RBAC, ResourceQuotas, LimitRanges, NetworkPolicies and, where needed, separate clusters for isolation.
- Run cluster networking and ingress with a CNI such as Cilium or the cloud VPC CNI, an ingress controller or Gateway API, and cert-manager for TLS.
- Manage autoscaling with the Horizontal Pod Autoscaler, KEDA, Cluster Autoscaler or Karpenter, and tune bin-packing to control cost.
- Enforce policy with Kyverno or OPA Gatekeeper and Pod Security Standards, and handle image signing and admission controls.
- Build and maintain operators or controllers in Go with controller-runtime or Kubebuilder where off-the-shelf tools do not fit.
- Run observability for clusters and workloads with Prometheus, Grafana and OpenTelemetry, and debug issues such as OOMKills, CrashLoopBackOff, DNS failures and evictions.
- Write runbooks and train product engineers to debug their own workloads.
Requirements
- 5+ years in infrastructure or platform engineering, with at least 3 years running production Kubernetes.
- Deep understanding of Kubernetes internals: the API server, scheduler, controllers, kubelet, etcd and how reconciliation works.
- Production experience with a managed service such as EKS, GKE or AKS, including at least two version upgrades.
- Strong Helm or Kustomize skills and production experience with Argo CD or Flux.
- Solid Kubernetes networking knowledge: Services, kube-proxy or eBPF data paths, ingress, DNS and NetworkPolicies.
- Experience with RBAC, service accounts and workload identity (IRSA, EKS Pod Identity or GKE Workload Identity).
- Experience setting resource requests and limits from real usage data and diagnosing scheduling and eviction problems.
- Infrastructure as code with Terraform or Pulumi, and scripting in Bash plus Go or Python.
- Clear written English for design docs, upgrade plans and runbooks.
Nice to have
- Writing custom controllers or CRDs in Go.
- Service mesh experience with Istio, Linkerd or Cilium service mesh.
- Multi-cluster management with Cluster API, Crossplane or fleet tooling.
- CKA, CKAD or CKS certification.
- Running stateful workloads on Kubernetes, such as Postgres with CloudNativePG or Kafka with Strimzi.
- GPU scheduling with the NVIDIA device plugin or GPU operator.
Tech stack
EKS, Terraform, Karpenter, Argo CD, Helm, Kustomize, Cilium, Gateway API, cert-manager, external-secrets, Kyverno, Prometheus, Grafana, Loki, OpenTelemetry, Go. Replace this with your real cluster stack; Kubernetes engineers read add-on lists carefully.
What success looks like in 6 months
- You have led at least one cluster version upgrade end to end, with a written plan and no customer-facing incident.
- Every cluster and add-on is defined in Git and reconciled by GitOps, with no manual kubectl changes in production.
- Product teams use a standard chart or template with resource requests, probes and disruption budgets set by default.
- Node cost has dropped, or utilization has risen, by an amount you can show from our own billing and cluster metrics.
How to apply and interview process
Send your resume or LinkedIn profile and a short note about a cluster or platform you ran. Our process has four steps: a 30-minute intro call, a technical conversation about systems you have operated, a practical troubleshooting or design exercise, and a final conversation with the team you would join. We aim to give feedback within a few days of each step.
Junior vs mid vs senior Kubernetes engineer
Many engineers can deploy to Kubernetes. Fewer can run it. Hire for the level of cluster ownership the role needs.
| Level | Scope | Typical experience | Key skills |
|---|
| Junior | Deploys and debugs workloads on existing clusters, edits manifests and charts under review | 0-2 years | kubectl, core objects (Pods, Deployments, Services), reading events and logs, Docker |
| Mid-level | Owns add-ons and parts of cluster operations, handles workload incidents | 2-5 years | Helm, GitOps, ingress and DNS, autoscaling, RBAC, resource tuning, Prometheus |
| Senior | Cluster architecture, upgrades, multi-tenancy, security posture and platform direction | 5+ years | Control plane internals, CNI and eBPF networking, policy engines, operators in Go, multi-cluster design |
Tips for writing a Kubernetes engineer job description that attracts senior talent
- State cluster count, provider and version. "Six EKS clusters on 1.31 across two regions" tells a candidate more than a paragraph. If you are several versions behind, say so; upgrade work attracts the right people.
- Say who the users are. Is the person serving one product team or running a shared platform for many teams? Multi-tenancy changes the job.
- Name the add-ons you already chose. CNI, ingress, GitOps tool, policy engine and secrets operator define daily work. Senior engineers often have strong views and want to know which decisions are open.
- Be clear about operators. If the role includes writing controllers in Go, require Go. If it does not, do not ask for it and risk losing operators-only candidates later.
- Describe stateful workloads honestly. Running databases or Kafka on Kubernetes is a serious commitment. Candidates want to know before they join.
- Mention cost pressure. If node spend is a concern, say that bin-packing, Karpenter tuning or spot capacity is part of the job.
- Keep certifications optional. CKA and CKS show effort, but a story about recovering from a broken etcd or a botched upgrade shows more.
Skip the job post: hire a vetted senior Kubernetes engineer
Experienced Kubernetes engineers are hard to find through job posts, and clusters do not pause while you search. Ryz Labs can match you with senior Kubernetes engineers from Latin America who work on your team, work in your repos, clusters and standups, and keep hours within ±1h of US time zones. Only the top 1% of the engineers we interview make it through our vetting, which covers cluster internals, networking, GitOps and production troubleshooting.
Our staff augmentation model lets you add one engineer or a whole platform group without changing how your team runs. Ryz engineers work on your team and report to your leads. Talk to us to scope the team you need. If you are interviewing on your own, our Kubernetes interview questions cover what we test and what strong answers sound like.
FAQ
What does a Kubernetes engineer do?
A Kubernetes engineer provisions, upgrades and secures clusters, manages networking, autoscaling and add-ons, and builds the deployment patterns that product teams use. In larger organizations they also write operators and run multi-tenant platforms. The job description should say which of these the role covers.
Is a Kubernetes engineer the same as a DevOps engineer?
There is overlap, but a Kubernetes engineer goes much deeper on cluster internals, networking, policy and multi-tenancy. A DevOps engineer usually owns the wider delivery pipeline and may deploy to Kubernetes without running it. If clusters are the core of the job, use the Kubernetes title.
Should I require CKA or CKS certification?
List them as a plus rather than a requirement. They confirm a baseline of knowledge, but production experience with upgrades, incidents and multi-tenant clusters predicts success better than an exam.
Questions we didn't answer? Email info@ryzlabs.com.