RHEL & OpenShift (OCP) Platform Engineer
Our client is looking for an experienced RHEL & OpenShift Platform Engineer to own the Linux and container platform layer supporting the enterprise applications.
You will be responsible for the health, security, and performance of the RHEL fleet and OpenShift Container Platform (OCP) clusters, while also supporting integration with key application platforms such as Pega, WebSphere, and IBM MQ.
This role is central to the infrastructure and DevSecOps strategy, ensuring compliance with government-grade security standards.
What You'll Do
RHEL Platform Management
● Own and maintain the RHEL OS fleet underpinning OCP worker/control-plane nodes and non-containerised application servers
● Plan and execute RHEL OS patching cycles (EUS channel management, kernel upgrades, reboot sequencing) with minimal service disruption
● Implement and validate OS hardening benchmarks — SELinux policies, firewalld rules, auditd configuration, and cryptographic policy settings
● Troubleshoot system-level issues: kernel parameters, resource limits (ulimits, cgroups), storage mounts (NFS, iSCSI, SMB/CIFS PVs on OCP)
● Manage RHEL subscriptions, entitlements, and satellite/image registries
OCP Cluster Administration
● Deploy, upgrade, and maintain OCP 4.x clusters — including control plane, etcd health, and worker node lifecycle
● Configure and manage the Machine Config Operator (MCO) for node-level OS customisation: chrony NTP, SSH hardening, kernel arguments, and custom MachineConfigs
● Manage cluster certificates, ingress/route configurations, and HAProxy timeout tuning for long-running enterprise workloads (e.g., Pega BIX, batch jobs)
● Administer the Quay mirror registry — image mirroring, vulnerability scanning, and VAPT remediation for bundled components
● Implement OCP RBAC, SCCs, network policies, and resource quotas across namespaces and project environments
● Support JVM and container resource tuning for Java workloads on OCP (heap sizing, Metaspace limits, G1GC flags, container memory budgeting)
Application Platform & Integration Support
● Take ownership of one or more application platforms (e.g., Pega Infinity, WebSphere, IBM MQ) — covering HA setup, patching, and operational support
● Participate in architecture sessions with build teams, advising on integration points (web services, MQ, SFTP, API gateway)
● Support container provisioning, image lifecycle, and deployment across DEV / SIT / UAT / PROD environments
Operational Governance & Security
● Define and execute operational processes: patching, performance monitoring, housekeeping, backup and recovery
● Support VAPT engagements — assess vulnerability findings and coordinate remediation
● Apply government-grade security hardening principles (IM8, SSCT, CIS benchmarks) across RHEL and OCP layers
● Contribute to DevSecOps tooling and automation — CI/CD pipelines, IaC, and operational runbooks
● Support AWS administration tasks where applicable (CloudWatch, IAM, S3, hybrid integration)
What We're Looking For
● Solid hands-on experience administering Red Hat Enterprise Linux (RHEL) in production, including patching, hardening, and troubleshooting
● Practical experience deploying and operating Red Hat OpenShift Container Platform (OCP 4.x) clusters
● Familiarity with SELinux, firewalld, auditd, and CIS/IM8-style security hardening frameworks
● Experience with container/Java workload tuning (JVM heap, GC, container resource limits) is a plus
● Exposure to enterprise application platforms such as Pega, WebSphere, or IBM MQ is advantageous
● Working knowledge of AWS services (CloudWatch, IAM, S3) is a plus
● Strong troubleshooting mindset and ability to work across infrastructure, security, and application teams
● Relevant certifications (RHCE, Red Hat OpenShift Administration, AWS) are a plus