Posted on: 01/05/2026
Job Title : Senior DevOps Engineer (GCP & Kubernetes Specialist)
Experience : 8+ Years
Type : Full-time
Role Overview :
The ideal candidate has a security first mindset and the technical depth to implement automated security gates within our GitHub Actions pipelines and Terraform workflows.
Key Responsibilities :
i. Infrastructure Hardening : Design and implement "Zero Trust" networking using GCP VPC service controls, private Google access, and strictly defined firewall rules.
ii. WAF & Edge Security : Configure and manage Google Cloud Armor policies to protect against DDoS and OWASP Top 10 threats.
iii. Identity & Access Management : Own the IAM hierarchy using the Principle of Least Privilege (PoLP), ensuring service accounts and user permissions are tightly scoped.
iv. Compliance & Audit : Prepare the infrastructure for audits (SOC2, PCI-DSS) by implementing automated logging, audit trails, and configuration drift detection.
2.) Secure Container Orchestration:
i. GKE Security : Implement Pod Security Standards, Network Policies, and ensure nodes are running on hardened image.
ii. Vulnerability Management : Integrate automated container scanning into the CI/ CD pipeline to block insecure images from reaching production.
iii. Secret Management : Architect secure secret injection for Node.js/ NestJS apps using Google Secret Manager and HashiCorp Vault or Kubernetes Secrets.
3.) Automated DevSecOps Pipelines:
i. Shift Left Security : Integrate SAST, DAST, and dependency scanning directly into GitHub Actions and Google Cloud Build.
ii. IaC Security : Use tools like tfsec or checkov to scan Terraform code for security misconfigurations before deployment.
iii. GitOps Security : Use ArgoCD to maintain a Single Source of Truth, ensuring that the production state matches our version-controlled, audited configurations.
4.) Data & Messaging Resilience:
i. Database Security : Ensure PostgreSQL encryption at rest and in transit, manage automated rotation of database credentials, and oversee secure backup strategies.
ii. Secure Messaging : Harden RabbitMQ clusters with TLS/ SSL encryption and secure authentication mechanisms.
Required Skills & Qualifications :
- GCP Security Expertise : Deep knowledge of Shared VPCs, Cloud NAT, Cloud Armor, and VPC Service Controls.
- Kubernetes Hardening : Proven experience securing GKE, including NetworkPolicies, RBAC, and admission controllers.
- Encryption Mastery : Strong understanding of KMS, TLS termination, and certificate management.
- Automation Pro : Expert in Terraform and GitHub Actions with a focus on automated security gates.
- Incident Response : Ability to lead Root Cause Analysis (RCA) for security events and perform forensic logging/monitoring using GCP Operations Suite and ELK.
Preferred Skills :
- Fintech Background : Experience handling sensitive financial data and regulatory compliance.
- Service Mesh : Experience with mTLS and fine grained traffic encryption.
- Side-channel Security : Knowledge of API Gateway security and rate-limiting strategies.
Our Tech Stack :
- Orchestration : GKE, Helm, Kustomize, Docker
- IaC : Terraform
- CI/CD : GitHub Actions, ArgoCD, Cloud Build
- Messaging/Data : RabbitMQ, PostgreSQL
- Monitoring : Prometheus, Grafana, Elasticsearch, Cloud Logging
Did you find something suspicious?
Posted by
Posted in
DevOps / SRE
Functional Area
Cyber Security
Job Code
1632666