Kafka Admin Lead-6months-London
Job Description
Kirtana consulting is looking for Kafka Admin Lead for 6months rolling contract in London.
\nJob description:
\nRole Title: Kafka Admin Lead
\nMinimum years of experience: 12+ years
\nResponsibilities
\nProvision, configure, and manage Kafka clusters (Apache Kafka KRaft or ZooKeeper-backed if Legacy), Confluent Platform components (Schema Registry, Kafka Connect, ksqlDB, REST Proxy, Control Center), and Confluent Cloud resources.
\nEnsure high availability (HA) and resilience across multi AZ/region deployments; manage partition replication, min.insync.replicas (ISR), and rack awareness.
\nImplement and maintain client quotas, broker quotas, throttling, and back pressure strategies.
\nPlan and execute upgrades/patching with zero/minimal downtime; maintain version currency against EOL and security advisories.
\nOwn backup/restore workflows for metadata (eg, cluster configs), Schema Registry, and Connect configs
\nImplement authentication (mTLS/SASL: SCRAM, OAUTHBEARER with IdP, or Kerberos if Legacy) and authorization (Kafka ACLs, Confluent RBAC).
\nEnforce encryption in transit and at rest, secret management (Vault/AKV/SSM), secure endpoint exposure, and private connectivity (VPC peering/PrivateLink).
\nGovern topic naming conventions, retention policies, schema evolution rules (backward/fully compatible), and PII handling.
\nMaintain audit trails (broker, Schema Registry, Control Center, Confluent Cloud audit logs) and compliance artifacts (SOX, GDPR, HIPAA/PCI as applicable).
\nCoordinate vulnerability management (CVE watch, hardening baselines, CIS/STIG alignment).
\nDeploy and maintain metrics pipelines (JMX - Prometheus/Grafana), logs (ELK/OPensearch), and tracing (OpenTelemetry where applicable).
\nDefine and monitor SLOs/SLIs (produce/consume latency, end to end lag, broker CPU/heap/file handles, network throughput, GC pauses).
\nAnalyze broker hotspots, partition skew, large message handling, compaction and retention settings, and tune GC/JVM for sustained throughput.
\nImplement consumer lag monitoring and alerting with actionable runbooks to prevent data loss or SLA breaches.
\nModel workload growth, topic/partition scaling, storage/IOPS, network egress/ingress, and broker sizing.
\nFor Confluent Cloud, optimize environment - cluster - topic hierarchy, throughput tiers, retention costs, and data flow egress; right size Dedicated vs. Standard clusters.
\nDesign partitioning strategies to meet throughput targets while balancing consumer concurrency and avoiding small partitions anti patterns
\nAutomate cluster and topic life cycle using Terraform (providers for Kafka/Confluent), Helm, GitOps workflows.
\nOperate and scale Kafka Connect with distributed workers; manage connectors (JDBC, Debezium CDC, S3/ADLS/GCS, Elasticsearch, etc.), transforms (SMTs), and converter settings.
\nAdminister Schema Registry (compatibility levels, subject naming strategies, serializers/deserializers, schema size & references).
\nOperate ksqlDB and/or Flink for streaming SQL; enforce resource limits and multi tenant governance.
\nEngineer low latency and secure connectivity across data centers/VPCs/VNETs; manage DNS, TLS SANs, LB configurations, advertised.listeners, and inter cluster networking.
\nRequired Skills & Experience
\n5-10 years in platform/SRE/DevOps; 3+ years dedicated to Kafka/Confluent admin in production.
\nStrong hands on with Apache Kafka internals: brokers, controllers (KRaft), partitions/replication, log segments, compaction/retention.
\nConfluent Platform: Schema Registry, Kafka Connect, ksqlDB, Control Center, Confluent REST APIs; or Confluent Cloud admin (environments, clusters, RBAC, audit logs, networking).
\nProficiency with Kafka CLI tools and AdminClient usage; deep knowledge of ACLs, quotas, transactions, idempotent producers, and exactly once semantics scenarios.
\nPrometheus/Grafana, JMX exporters, alerting systems (Alertmanager etc).
\nJVM tuning, Linux performance (NUMA, file descriptors, page cache, disk/RAID, XFS), and network tuning (TCP buffers, MTU, jumbo frames where applicable).
\nLinux administration (systemd, journald, Kernel params), virtualization/containers (Docker, Kubernetes).
\nCloud networking (VPC/VNET peering, transit gateways, PrivateLink/Private Service Connect), multi region architectures.
\nPreferrable
\nConfluent Certified Administrator for Apache Kafka (CCAAK), CKA/CKAD, HashiCorp Terraform Associate, major cloud certs (Azure/AWS/GCP).
\nExperience with Confluent for Kubernetes (CFK) for operator based deployments.
