Principal OpenShift Networking Architect
Job Summary
Job Description Principal OpenShift Networking Architect
Location: Dublin 18 (2 days onsite per week)
Duration: Until the end of the year likely to be extended
Summary of this role: his resource will own the networking architecture for the OpenShift Container Platform and OpenShift Virtualisation platforms. They will be responsible for defining the future-state networking segmentation and connectivity model across container and virtual machine workloads including evaluation of modern Kubernetes networking and micro-segmentation technologies.
A key responsibility will be leading the transition from traditional NSX-based segmentation models to OpenShift-native networking and security controls including the discovery analysis and rationalisation of existing NSX Distributed Firewall policies into scalable OpenShift-native segmentation patterns for both container and virtual machine workloads.
This is a hands-on architecture role rather than a traditional network infrastructure role. The successful candidate must be a recognised OpenShift/Kubernetes networking specialist capable of defining standards producing architecture deliverables guiding implementation teams and providing technical leadership around network isolation multi-tenancy virtualisation networking and software-defined networking.
Skillset and background:
- 10 years of enterprise networking and infrastructure experience
- 5 years of hands-on Kubernetes networking experience
- Strong OpenShift networking experience within large enterprise or regulated environments
- Expert knowledge of OVN-Kubernetes architecture operation and troubleshooting
- Expert knowledge of Kubernetes networking constructs including Services Ingress Egress and Network Policies
- Hands-on experience with Multus and secondary network architectures
- Strong understanding of namespace isolation multi-tenancy and Kubernetes micro-segmentation
- Experience translating existing VMWare NSX Firewall and micro-segmentation policies into Kubernetes-native segmentation models using OpenShift Network Policies Admin Network Policies Cilium or Calico
- Strong understanding of the challenges associated with migrating from VM-based security controls to container and OpenShift-native security architectures
- Experience defining and implementing Zero Trust networking architectures
- Hands-on experience with OpenShift Virtualisation and KubeVirt networking models
- Experience evaluating and implementing modern Kubernetes networking platforms such as OVN-Kubernetes UDN/CUDN Isovalent Enterprise for Cilium Calico Enterprise or equivalent
- Ability to produce High-Level Designs (HLDs) Low-Level Designs (LLDs) standards and reference architectures
- Strong stakeholder management and technical leadership skills
- Red Hat OpenShift certifications or equivalent Kubernetes networking certifications would be advantageous
Key Deliverables:
- OpenShift Networking Reference Architecture
- Container and VM Segmentation Strategy
- Multi-Tenancy Design Standards
- Network Policy Framework
- OpenShift Virtualisation Networking Standards
- SDN/CNI Assessment and Recommendations
- Network Security and Micro-Segmentation Architecture
- Platform Networking Design Governanc
Required Skills:
Key Deliverables: OpenShift Networking Reference Architecture Container and VM Segmentation Strategy Multi-Tenancy Design Standards Network Policy Framework OpenShift Virtualisation Networking Standards SDN/CNI Assessment and Recommendations Network Security and Micro-Segmentation Architecture Platform Networking Design Governance