Senior DevOps Engineer
Senior DevOps Engineer - Kubernetes & OpenLDAP (EBSA - IDAM DevOps HO - SFIA 4/5)
Location: London (Hybrid/2-3 days onsite per week)
Sector: Public Sector
Clearance Required: Security Clearance (SC) required | NPPV3 eligible
Nationality Requirement: Single National
Rate: £650-£670/day inside IR35
Role Overview
We are seeking a highly experienced Senior DevOps Engineer with deep, hands-on expertise in Kubernetes platform engineering and OpenLDAP-based Identity and Access Management (IDAM). This is a senior technical role within a secure, regulated public sector environment, requiring an individual who can operate independently, lead from the front, and deliver robust, scalable, and secure containerised platforms.
The successful candidate must be fully confident working across Kubernetes and directory services (particularly OpenLDAP) and be able to hit the ground running with minimal ramp-up, bringing strong practical experience in production-grade environments.
In addition to hands-on delivery, the role includes technical leadership responsibilities for a small DevOps team, supporting CI/CD capability, secure deployments, and production governance.
This position operates at SFIA Level 4/5, requiring autonomy, technical authority, and the ability to make informed decisions in complex, security-controlled environments.
Key Responsibilities
Kubernetes Platform Engineering
- Design, build, and operate secure and scalable Kubernetes clusters
- Manage full cluster life cycle including provisioning, upgrades, scaling, and decommissioning
- Implement and enforce RBAC, network policies, and pod security standards
- Configure ingress controllers and service mesh integration
- Define and support multi-environment strategies (Dev/Test/Prod)
- Troubleshoot complex production incidents and performance issues
- Deliver deployments using Helm and Kustomize
- Ensure platform resilience, scalability, and operational excellence
OpenLDAP/Identity & Access Management (Core Requirement)
- Deep hands-on experience with OpenLDAP in enterprise environments
- Install, configure, and harden OpenLDAP services
- Design directory structures and schemas aligned to enterprise identity models
- Implement secure authentication using LDAPS, certificates, and RBAC mapping
- Integrate LDAP authentication with Kubernetes and CI/CD tooling
- Support identity federation patterns across enterprise platforms
- Design and maintain high availability and replication strategies
- Diagnose and resolve directory performance, latency, and synchronisation issues
- Strong practical understanding of directory services is essential for success in this role
CI/CD Engineering (Jenkins)
- Develop and maintain Jenkins pipelines using Groovy (pipeline-as-code)
- Build and manage shared libraries and governance frameworks
- Integrate Jenkins with Kubernetes-based build agents
- Implement secure credential and secrets management practices
- Integrate automated testing into CI/CD workflows
- Support release orchestration and deployment automation
Supporting Skills
Strong Working Knowledge:
- Docker (multi-stage builds, image optimisation, secure base images)
- Python (automation, Scripting, infrastructure tooling)
Working Knowledge:
- AWS (IAM, networking concepts, container services)
- Terraform (infrastructure-as-code principles and module usage)
- Other networking technologies relevant to secure infrastructure environments
Leadership & Governance Responsibilities
- Act as a technical point of contact for DevOps-related queries
- Support technical design authority decisions for incoming work
- Oversee governance and assurance of production releases
- Provide mentoring, coaching, and performance feedback to engineers
- Drive capability uplift and continuous improvement within the team
Key Attributes
- Strong hands-on technical engineer with deep Kubernetes and OpenLDAP expertise
- Proven ability to operate independently within complex environments
- Experience in secure, regulated (ideally public sector/government) environments
- Strong communication and stakeholder engagement skills
- Security-first mindset and disciplined engineering approach
- Comfortable making decisions in high-accountability environments
Additional Vetting Requirement
This role requires additional vetting beyond standard onboarding processes, which may extend the clearance and mobilisation timeline. Candidates should be aware that SC/NPPV3-related checks may result in longer onboarding periods than usual.