Principal OpenShift Networking Architect
Summary
Own networking architecture for OpenShift Container Platform and Virtualisation, defining future-state networking and segmentation models. Lead transition from NSX-based segmentation to OpenShift-native networking controls with hands-on expertise in Kubernetes networking.
Job Description – Principal OpenShift Networking
Architect
Location: Dublin 18 (2 days onsite per week)
Duration: Until the end of the year, likely to be
extended
Summary
of this role: his resource will own
the networking architecture for the OpenShift Container Platform and OpenShift
Virtualisation platforms. They will be responsible for defining the
future-state networking, segmentation and connectivity model across container
and virtual machine workloads, including evaluation of modern Kubernetes
networking and micro-segmentation technologies.
A key
responsibility will be leading the transition from traditional NSX-based
segmentation models to OpenShift-native networking and security controls,
including the discovery, analysis and rationalisation of existing NSX
Distributed Firewall policies into scalable OpenShift-native segmentation
patterns for both container and virtual machine workloads.
This is
a hands-on architecture role rather than a traditional network infrastructure
role. The successful candidate must be a recognised OpenShift/Kubernetes
networking specialist capable of defining standards, producing architecture
deliverables, guiding implementation teams and providing technical leadership
around network isolation, multi-tenancy, virtualisation networking and
software-defined networking.
Skillset
and background:
- 10+ years of
enterprise networking and infrastructure experience
- 5+ years of hands-on
Kubernetes networking experience
- Strong OpenShift
networking experience within large enterprise or regulated environments
- Expert knowledge of
OVN-Kubernetes architecture, operation and troubleshooting
- Expert knowledge of
Kubernetes networking constructs including Services, Ingress, Egress and
Network Policies
- Hands-on experience
with Multus and secondary network architectures
- Strong understanding
of namespace isolation, multi-tenancy and Kubernetes micro-segmentation
- Experience
translating existing VMWare NSX Firewall and micro-segmentation policies
into Kubernetes-native segmentation models using OpenShift Network
Policies, Admin Network Policies, Cilium or Calico
- Strong understanding
of the challenges associated with migrating from VM-based security
controls to container and OpenShift-native security architectures
- Experience defining
and implementing Zero Trust networking architectures
- Hands-on experience
with OpenShift Virtualisation and KubeVirt networking models
- Experience
evaluating and implementing modern Kubernetes networking platforms such as
OVN-Kubernetes, UDN/CUDN, Isovalent Enterprise for Cilium, Calico
Enterprise or equivalent
- Ability to produce
High-Level Designs (HLDs), Low-Level Designs (LLDs), standards and
reference architectures
- Strong stakeholder
management and technical leadership skills
- Red Hat OpenShift
certifications or equivalent Kubernetes networking certifications would be
advantageous
Requirements
Key
Deliverables:
- OpenShift Networking
Reference Architecture
- Container and VM
Segmentation Strategy
- Multi-Tenancy Design
Standards
- Network Policy
Framework
- OpenShift
Virtualisation Networking Standards
- SDN/CNI Assessment
and Recommendations
- Network Security and
Micro-Segmentation Architecture
- Platform Networking
Design Governanc