We are seeking an experienced Cloud Engineer – Application Deployment to support the packaging, deployment and management of applications on a secure, bare-metal Kubernetes platform.
This role would suit a hands-on engineer with strong Kubernetes, containerisation and application deployment experience, particularly in restricted, air-gapped or high-assurance environments where internet access, network segmentation and controlled artifact promotion are key delivery constraints.
You will work across a secure Kubernetes platform orchestrated by NVIDIA Base Command Manager (BCM), supporting application delivery into namespace-isolated user environments. The work will include preparing container images, managing deployment artefacts, supporting internal registries, and enabling workloads such as notebooks, APIs and batch jobs to operate reliably within a controlled platform.
Please note: Due to the secure nature of this environment, candidates must hold a current Negative Vetting 2 (NV2) security clearance to be considered.
Key responsibilities
In this role, you will:
- Package, deploy and manage applications on a bare-metal Kubernetes cluster.
- Translate application requirements into Kubernetes manifests, Helm charts or operator-based deployments.
- Prepare and maintain container images for air-gapped environments, including dependency bundling, version pinning and compatibility validation.
- Manage application delivery through internal artifact repositories such as Artifactory, with no direct internet access.
- Deploy and expose services using Kubernetes ingress and secure platform access patterns.
- Work within restricted network environments, including segmented management and production VLANs.
- Support namespace-isolated user environments and controlled access models.
- Enable user-facing workloads including notebooks, APIs, batch jobs and containerised developer tools.
- Produce deployment artefacts, runbooks and reproducible delivery processes suitable for controlled environments.
- Troubleshoot container runtime issues, Kubernetes scheduling failures, storage mounts and network access constraints.
Essential experience
To be successful, you will bring:
- Current Negative Vetting 2 (NV2) security clearance.
- Strong hands-on experience deploying applications to Kubernetes in restricted or air-gapped environments.
- Experience building, managing and hardening container images.
- Practical experience with offline dependency management, image minimisation and multi-stage builds.
- Strong knowledge of Kubernetes primitives, including Deployments, Jobs, Services, Ingress, RBAC and namespace isolation.
- Understanding of GPU scheduling concepts such as node selectors and tolerations.
- Experience with internal container registries and artifact promotion workflows, with no reliance on external pulls.
- Ability to work with infrastructure-as-code outputs and translate platform constraints into deployable application patterns.
- Strong Linux runtime knowledge and experience debugging containerised workloads without external tooling access.
- Strong troubleshooting capability across runtime, scheduling, storage and network-related issues.
Highly regarded experience
The following experience will be well regarded:
- Exposure to BCM-managed, HPC-style or GPU-backed Kubernetes clusters.
- Experience deploying ML, AI or data science workloads using patterns such as Kubeflow, KServe, notebooks or batch inference.
- Air-gapped CI/CD experience, including artifact mirroring and offline Helm or chart repositories.
- Knowledge of Kubernetes operators such as GPU Operator or Prometheus Operator.
- Experience packaging developer tooling such as Jupyter or VS Code Server in restricted environments.
- GitOps-style delivery using internal GitLab without external integrations.
- Experience in Defence, classified, secure or high-assurance environments.
- Understanding of secure software supply chain practices, including image provenance and vulnerability scanning prior to import.
- Experience supporting multi-tenant Kubernetes environments with strict namespace isolation and RBAC controls.
- Ability to optimise workloads for fixed-capacity, non-elastic environments.
About you
You are a practical, delivery-focused engineer who understands that secure platform work is not just about Kubernetes knowledge. You are comfortable working within controlled environments where dependencies must be planned, artefacts must be reproducible, and applications need to operate without direct internet access.
You will be confident working with platform engineers, application teams and technical stakeholders to turn deployment requirements into reliable, repeatable outcomes.
Apply now
If you are an experienced Kubernetes / Cloud Engineer with strong container deployment experience in secure or restricted environments, and you hold a current NV2 security clearance, we would welcome your application.
To be considered for the role click the 'apply' button or for more information about this and other opportunities please contact Rashmi Kapse on + 612 6151 9206 or email rkapse@paxus.com.au and 274489 the above job reference number.
Paxus values diversity and welcomes applications from Indigenous Australians, people from diverse cultural and linguistic backgrounds and people living with a disability. If you require an adjustment to the recruitment process, including the application form in an alternate format, please contact me on the above contact details.




