Senior Service Mesh Engineer (Istio/Linkerd)

Remote
Apply
AI Summary

Bright Vision Technologies is seeking a skilled Service Mesh Engineer to design, deploy, and operate service mesh platforms. The ideal candidate has experience operating service mesh in production and deeply understands Envoy and the data plane. The role focuses on platform engineering, mesh adoption, and helping application teams reap the benefits of a mesh.

Key Highlights
Service mesh platform design and operation
Istio and Linkerd expertise
Platform engineering and mesh adoption
Key Responsibilities
Design and operate service mesh platforms
Implement and operate mTLS, certificate rotation, and identity propagation
Define traffic management policies
Integrate the mesh with ingress, egress, and API gateway tiers
Build observability for mesh traffic
Technical Skills Required
Istio Linkerd Envoy Kubernetes Go Python mTLS PKI Distributed tracing
Benefits & Perks
Competitive base salary
Benefits
100% remote work
Nice to Have
Experience with multi-cluster Istio or Linkerd deployments
Familiarity with Cilium service mesh and eBPF networking
Open-source contributions to service mesh projects
Experience with SPIFFE/SPIRE for workload identity

Job Description


Bright Vision Technologies is a forward-thinking software development company dedicated to building innovative solutions that help businesses automate and optimize their operations. We leverage cutting-edge technologies to create scalable, secure, and user-friendly applications.

As we continue to grow, we’re looking for a skilled Service Mesh Engineer (Istio / Linkerd) to join our dynamic team and contribute to our mission of transforming business processes through technology.

This is a fantastic opportunity to join an established and well-respected organization offering tremendous career growth potential.

Job Title: Service Mesh Engineer (Istio / Linkerd)

Location: 100% Remote (Continental United States)

Position Type: In-house Bright Vision Technologies SOW engagement (no third-party client or vendor)

Salary: $100K - $150K

Experience: 5+ years

Sponsorship: No new H1B sponsorship available. H1B transfers welcomed for qualified candidates.

Employment Type: Full-time, direct W2 with Bright Vision Technologies (no C2C, no 1099, no third-party)

Engagement: Long-term, multi-year, aligned to the Bright Vision SOW delivery roadmap

Compensation: Competitive base salary commensurate with experience, plus benefits.

Employment Terms & Visa Policy

This is a 100% remote, full-time, direct W2 position with Bright Vision Technologies.

This role is part of Bright Vision Technologies’ in-house Statement of Work (SOW) engagement. The client, end customer, and employer for this position is Bright Vision Technologies — there is no third-party client, vendor, or implementation partner involved.

We do not engage in C2C, 1099, or third-party arrangements for this role.

BUT STRICTLY NO C2C/1099/3RD PARTY COMPANIES. ALL OUR ROLES ARE W2 AND NO 3RD PARTY BROKERING PLEASE.

Candidates must be willing to work directly as a full-time W2 employee of Bright Vision Technologies and contribute to our in-house SOW deliverables.

No new H1B sponsorship is available for this role.

However, candidates who are currently on a valid H1B visa and require a transfer are welcome to apply. We will support H1B transfers for qualified candidates.

For every role, a technical coding assessment is mandatory. Please apply only if you are confident in your technical abilities and hands-on experience.

Job Summary

We are looking for a Service Mesh Engineer to design, deploy, and operate service mesh platforms — primarily Istio and Linkerd — that provide secure, observable, and reliable service-to-service communication across our Kubernetes estate. The role focuses on platform engineering, mesh adoption, mTLS, traffic policy, and helping application teams reap the benefits of a mesh without paying for unnecessary complexity. The ideal candidate has operated service mesh in production, deeply understands Envoy and the data plane, and brings both platform engineering discipline and pragmatic adoption strategies.

Key Responsibilities

  • Design and operate service mesh platforms — primarily Istio and Linkerd — across multi-cluster Kubernetes environments
  • Implement and operate mTLS, certificate rotation, and identity propagation across the mesh
  • Define traffic management policies including routing, retries, circuit breaking, and fault injection
  • Integrate the mesh with ingress, egress, and API gateway tiers for unified traffic management
  • Build observability for mesh traffic including distributed tracing, golden signals, and topology visualization
  • Design multi-cluster and cross-cluster mesh topologies for high availability and tenant isolation
  • Profile and optimize mesh performance, sidecar resource usage, and control-plane footprint, applying systematic measurement, targeted improvements, and data-driven validation to deliver quantifiable gains in throughput, latency, or resource efficiency
  • Develop paved-road adoption patterns and onboarding guides that make mesh adoption easy for app teams
  • Implement authorization policies and zero-trust patterns at the service mesh layer
  • Operate service mesh upgrades, control-plane lifecycle management, and configuration governance, applying disciplined release practices that keep the mesh current without disrupting workloads running on top of it
  • Partner with SRE, platform, and security teams on mesh policy and incident response
  • Troubleshoot complex networking, mTLS, and traffic issues spanning sidecar and gateway tiers
  • Maintain runbooks, architecture diagrams, and onboarding materials for the service mesh platform
  • Stay current with Istio, Linkerd, Cilium, and broader service mesh ecosystem developments

Required Qualifications

  • Bachelor’s degree in Computer Science or a related field
  • Five or more years of experience in platform engineering, SRE, or networking roles
  • Hands-on experience operating Istio or Linkerd in production
  • Strong understanding of Envoy proxy internals and configuration
  • Deep Kubernetes expertise including networking, CNI, and ingress
  • Strong understanding of mTLS, PKI, and certificate lifecycle management
  • Experience with distributed tracing and observability for mesh traffic
  • Proficiency in Go or Python for tooling and automation
  • Strong troubleshooting skills across networking, application, and control plane layers
  • Excellent communication and collaboration skills

Preferred Qualifications

  • Experience with multi-cluster Istio or Linkerd deployments
  • Familiarity with Cilium service mesh and eBPF networking
  • Open-source contributions to service mesh projects
  • Experience with SPIFFE/SPIRE for workload identity
  • Exposure to zero-trust networking initiatives at enterprise scale

How To Apply

Would you like to know more about this opportunity?

For immediate consideration, please send your resume to [email protected]

Learn more about Bright Vision Technologies at www.bvteck.com.

We recognize that our people are our strength, and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company.

We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants’ and employees’ religious practices and beliefs, as well as mental health or physical disability needs.

Bright Vision Technologies is an Equal Opportunity Employer, including Disability/Veterans.

Position offered by “No Fee Agency.”

Equal Employment Opportunity (EEO) Statement

Bright Vision Technologies (BV Teck) is committed to equal employment opportunity (EEO) for all employees and applicants without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, genetic information, disability, veteran status, or any other protected status as defined by applicable federal, state, or local laws. This commitment extends to all aspects of employment, including recruitment, hiring, training, compensation, promotion, transfer, leaves of absence, termination, layoffs, and recall.

BV Teck expressly prohibits any form of workplace harassment or discrimination. Any improper interference with employees' ability to perform their job duties may result in disciplinary action up to and including termination of employment.

Powered by JazzHR

661NKCj8xa

Similar Jobs

Explore other opportunities that match your interests

Java Developer Intern

Programming
5h ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

TEKsystems

United State
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Associate

sundayy

United State

Field Deployment Engineer

Programming
5h ago
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Mid-Senior level

remotehunter

United State

Subscribe our newsletter

New Things Will Always Update Regularly