- Australian citizenship with already valid NV2 security clearance; applications without current clearance won’t be pre-d.
- Kubernetes skills at least CKAD level and ability to troubleshoot clusters independently (deploy/manage on bare metal).
- Experience with air-gapped/offline firmware and patch management without internet access, including secure media move/te
Role Type
Pay Rate
Description
Role – Infrastructure Engineer (Air-Gapped Systems)
We’re hiring for a long-term position on a multi-year program. You’ll build, configure and maintain bare-metal infrastructure in secure, disconnected environments, from racking and firmware through to Kubernetes.
We don’t expect you to know the whole stack on day one. We’re looking for someone with solid Linux and Kubernetes fundamentals, real experience with at least one of the hardware platforms below, and the drive to learn the rest. We’ll invest in your training and certifications. In return, we want someone who is in it for the long haul and is willing to put in their own time to build their skills.
The work is mostly on-site in a secure, air-gapped facility, and there is no remote access to the environment. Depending on the program’s coverage needs, some positions may involve a rotating shift pattern that includes evenings, nights, weekends and public holidays, so please tell us up front if shift work isn’t an option for you. Alongside build work, you’ll be part of the team that keeps the platform running day to day. That means responding to incidents quickly, following documented procedures, and handing problems to vendor support with the diagnosis already done. We’ll support you through certification in the first months, including CKA or CKAD if you don’t already hold them.
About Opes
Opes Cyber Security is a Canberra-based Veteran company working at the sharp end of Australian Defence, cyber and intelligence. We design, deliver and support secure infrastructure for Defence programs and industry primes, with a focus on sovereign and classified cloud deployments in air-gapped environments.
We work with a consortium of partners, including one of the world’s leading hyperscale cloud providers and one of the world’s largest technology solutions and system integrators to design, integrate and ultimately deliver secure infrastructure to Australian Defence Programs.
We operate from our own secure facility in the Canberra CBD and work closely with government, industry primes and international technology partners. We’re a growing team, and excited to open the doors as key accounts and programs continue to expand.
Day to Day
You’ll monitor the health of the platform and respond to alerts within agreed response times. When a system stops responding, you’ll use out-of-band management to reach it and work out what went wrong before touching any hardware. You’ll diagnose problems at both the Kubernetes and Linux layers and follow them through to a fix or a clean handover to vendor support. Replacing failed hardware under change control is part of the job, and so is tracking down connectivity faults from the physical layer up. You’ll help look after certificates and security configuration across the platform. Every change goes through version control, and every incident is recorded with enough evidence that someone else can follow your reasoning.
·Deploy and manage Kubernetes clusters on bare-metal hardware
·Administer Linux systems across build, patching and day-to-day operations
·Plan and carry out firmware updates and patches offline in air-gapped environments, including moving and validating media under security controls
·Configure and troubleshoot server, storage, network and firewall components
·Document builds, changes and procedures to a standard suitable for Defence environments
·Work alongside our engineers and partner teams to deliver program milestones
Qualifications and Experience
You’ll need Kubernetes skills at least at CKAD level, and you should be comfortable troubleshooting a cluster on your own rather than only deploying one. You should be confident with Git, including branches, pull requests and code review. You’ll need strong networking fundamentals and a working command of the Linux networking tools, such as ip, tcpdump, dig and ss. Experience with out-of-band management and serial console access in a data centre is essential. Some exposure to a service mesh (like Istio), to certificate and PKI management will count strongly in your favour.
- Scripting or automation (Bash, Python, Ansible)
- Strong Linux system administration skills
- Hands-on experience deploying Kubernetes on bare metal (not just managed cloud services)
- Experience, or a clear understanding of, working in air-gapped or offline environments, particularly firmware and patch management without internet access
- Australian citizenship and already valid NV2 security clearance. Applications without a current clearance will not be reviewed.
- Hands-on experience with at least ONE of the following:
- HPE DL360 servers (firmware, configuration, iLO management)
- NetApp AFF (A30/A90 series) or StorageGRID SG1000
- Cisco switching (L2/L3 configuration)
- Palo Alto Networks firewalls (policies, routing, NAT)
Desirable
·Experience with more than one of the platforms above
·Scripting or automation (Bash, Python, Ansible)
·Previous work in Defence, government or other high-security environments
·Relevant certifications (CKA, RHCSA, HPE, NetApp, CCNA/CCNP, PCNSE)
Apply Here or at recruitment@opescyber.com.au
Australia
New Zealand
United Kingdom
Canada
Singapore
Malaysia





