Requirement: Kubernetes Platform Operations and Maintenance Expert
Location: Brussels, BELGIUM
Full Time On-Site: Yes
Time On-Site: 100%
Not to Exceed Rate: 72 EUR
Total Scope of the request (hours): 570
Required Start Date: 28 September 2026
End Contract Date: 31 December 2026
Required Security Clearance: NATO SECRET
Please do NOT apply for any NATO contract positions unless you meet ALL the following criteria:
- Current National or NATO SECRET clearance
- Nationality of one of the NATO member countries
- Current work visa for the specific location if applying for an in-country position
Duties & Role:
- The Kubernetes Platform Operations and Maintenance Expert will report to the Head of Processing and Storage Section.
- Deliver monthly artifacts; maintain cluster operations; perform upgrades and patching; maintain documentation; provide knowledge transfer; ensure compliance with defined performance SLA and internal procedures.
- Participate in weekly status update meetings, activity planning and other meetings as instructed, physically in the office, or in person via electronic means using Conference Call capabilities, according to the Team Leaders instructions.
- Tooling stack (inside the cluster): The Kubernetes Platform Operations and Maintenance Expert operate and maintain the following Kubernetes native tooling: Prometheus & Grafana; Logging stack; NGINX or ingress; Cilium CNI; Backup tooling; On prem registry (e.g. Harbor/SUSE); ArgoCD GitOps; Metrics server; Cert manager; Zabbix integration hooks.
- Out of Scope: Underlying VMs, storage, and network infrastructure (NCIA responsibility); disaster Recovery tests (NCIA responsibility; Service Contractor provides performance artifacts); application development or debugging; any activity outside the Kubernetes clusters.
- Cluster Health Report - node health, pod health, workloads, resource utilization, cluster events, degraded components.
- Security Compliance Report - CIS benchmark checks, RBAC audit, network policy compliance, vulnerability scan results, remediation actions.
- Capacity and Performance Report - CPU/memory/storage trends, saturation risks, performance anomalies, capacity forecasting.
- Patching and Upgrade Report - Applied patches, pending patches, quarterly upgrade status, upgrade readiness checks.
- Incident and RCA Report - Summary of P1-P3 incidents, root cause analysis, corrective actions, prevention measures.
- Configuration Drift Report - Comparison of cluster configuration vs approved baseline, drift items, remediation plan.
- Monthly Change Log - All changes applied to clusters, manifests, GitOps commits, registry updates, configuration changes.
- Monthly Risk Register Update - Identified risks, severity, mitigation actions, owner, expected resolution timeline.
- Daily monitoring of cluster health and alerts.
- Node lifecycle operations (join, drain, cordon, replacement).
- Management of Kubernetes components (CNI, CSI, ingress, metrics server, CoreDNS).
- Certificate rotation and secrets management.
- RBAC administration and periodic audits.
- Network policy management.
- Vulnerability scanning and remediation inside the cluster.
- Backup operations using Commvault Velero/K10 (excluding DR tests).
- Maintaining documentation and runbooks.
- Assisting application teams with deployment troubleshooting.
- Participation in planning meetings, retrospectives, and workshops.
Skills, Knowledge & Experience:
- The candidate must have a currently active NATO SECRET security clearance
- University Degree + 3 years relevant experience, or equivalent.
- 3+ years hands on Kubernetes operations experience.
- Experience with SUSE RKE2 Kubernetes distributions.
- Experience with monitoring, logging, repositories, ingress, CNI, and backup tooling.


