What You'll Do
- Deploy and operate the platform's Kubernetes-based components on-premises or in a hybrid configuration inside the client's data center (Kubernetes, OpenShift, or Rancher) — Helm charts, operators, container registries, networking/ingress, and RBAC.
- Integrate persistent storage (Kubernetes CSI, software-defined storage such as Portworx or comparable) and validate the environment is ready for configuration.
- Onboard data-source connectors across relational and legacy databases, data warehouses, file/object stores, streaming data, and mainframe.
- Tune sensitive-data classifiers and discovery rules; validate precision and recall against real production data.
- Build the data graph model linking data to identity, access, usage, lineage, and risk.
- Implement attribute-based access control (ABAC) policies and map automated controls/reporting to HIPAA, GLBA, PCI DSS, GDPR, and SOX.
- Integrate platform outputs with the client's SIEM, IAM/IGA, data-catalog, and DLP tooling.
- Translate client objectives into use cases (DSPM posture, DLP, privacy/DSAR automation, AI data-readiness) and build repeatable data workflows.
- Serve as the technical point of contact on the engagement, operating within the client's formal change-control, security, and compliance processes.
Must-Have Skills & Experience
- 3+ years of production experience deploying, operating, and troubleshooting Kubernetes (vanilla Kubernetes, Red Hat OpenShift, or Rancher) in enterprise on-premises or hybrid environments — not pilots or single-node clusters.
- Helm charts, operators, container registries, networking/ingress, and RBAC for containerized enterprise software.
- Kubernetes persistent storage / CSI integration; software-defined or cloud-native storage experience (Portworx or comparable) a strong plus.
- Comfortable working in restricted, segmented, or air-gapped on-prem networks under formal change control.
- Hands-on experience with a data discovery, classification, or DSPM platform (1touch.io/Kontxtual, Microsoft Purview, BigID, Securiti, Varonis, Collibra, or similar).
- PII/PHI/PCI data classification, including how precision and recall are tuned and validated against production data.
- Experience connecting and profiling heterogeneous on-prem sources — relational/legacy databases, data warehouses, object/file stores, and ideally mainframe.
- Comfort with data lineage or knowledge-graph concepts.
- Practical experience with policy-driven access governance (ABAC or comparable) and mapping controls to regulatory frameworks — HIPAA, PCI DSS, GLBA, GDPR, and/or SOX.
- Delivery experience in regulated financial-services or healthcare environments with formal change control and security review.
- Experience integrating governance/classification outputs with SIEM, IAM/IGA, and data-catalog tooling.
- 6+ years combined experience in data security, data governance, or data engineering.
- SQL and at least one scripting language (Python preferred); comfortable with APIs and integration work.
- Strong client-facing communication — able to translate technical work into business and compliance language.
Nice to Have
- Direct experience with 1touch.io/Kontxtual specifically.
- Portworx, Pure Storage, or other Kubernetes-native storage experience.
- Exposure to AI/GenAI or agentic-AI data-readiness work.
- Kubernetes certification (CKA/CKAD) and/or CISSP, CIPP, or CDMP.
- Prior pre-sales, solution-engineering, or proof-of-concept experience.
IR35 Status:
Not specified
Industry:
Data & Analytics