Negotiable
Undetermined
Undetermined
London Area, United Kingdom
Summary: We are seeking a skilled DevSecOps Engineer with expertise in Google Cloud Platform (GCP) to enhance the security of our software development processes. The role involves developing security policies, integrating security into CI/CD pipelines, and implementing secure microservices. The ideal candidate will have a strong background in GCP, Terraform, and security best practices. This position is crucial for maintaining compliance and addressing vulnerabilities within our GCP infrastructure.
Key Responsibilities:
- Develop, implement, and maintain Rego policies for security controls and compliance in GCP.
- Collaborate with teams to integrate security into GCP-focused CI/CD pipelines.
- Architect and implement secure microservices and containerized applications on GCP.
- Design and implement infrastructure-as-code (IaC) using Terraform for GCP resources.
- Perform security assessments on GCP environments to identify vulnerabilities.
- Conduct threat modeling and risk assessments for GCP deployments.
- Respond to GCP-specific security incidents and conduct root cause analysis.
- Stay updated on GCP advancements and share knowledge with the team.
- Drive a culture of security awareness in GCP environments.
Key Skills:
- Bachelor's degree in Computer Science, Information Security, or related field.
- Proven experience as a DevSecOps Engineer with a focus on GCP.
- Expertise in Rego policies and policy-as-code practices in GCP.
- In-depth understanding of GCP services and security best practices.
- Proficiency in GCP-specific security tools and vulnerability scanners.
- Experience with infrastructure-as-code (IaC) using Terraform.
- Familiarity with CI/CD pipelines and automation tools.
- Knowledge of GCP security frameworks and compliance requirements.
- Understanding of container security in GCP.
- Excellent communication and collaboration skills.
- Relevant GCP certifications are advantageous.
Salary (Rate): undetermined
City: London Area
Country: United Kingdom
Working Arrangements: undetermined
IR35 Status: undetermined
Seniority Level: undetermined
Industry: IT
Job Description : We are seeking a skilled and experienced DevSecOps Engineer with a strong specialization in Google Cloud Platform (GCP) to join our dynamic team. In this role, you will play a pivotal role in ensuring the security and integrity of our software development processes on GCP. Your expertise in GCP, Rego policies, and Terraformwill be instrumental in building a secure and efficient development pipeline.
Responsibilities:
- · Develop, implement, and maintain Rego policies to enforce security controls and compliance standards within our GCP infrastructure and applications.
- · Collaborate with development and operations teams to integrate security into the GCP-focused CI/CDpipeline, ensuring security checks and scans are automated and seamlessly incorporated.
- · Leverage your GCP expertise to architect and implement secure microservices and containerized applications, ensuring compliance with GCP security best practices.
- · Design and implement infrastructure-as-code (IaC) using Terraform to define and manage GCP resources securely and efficiently.
- · Perform thorough security assessments on GCP environments, utilizing GCP-specific security tools andtechnologies, to identify and address potential vulnerabilities.
- · Conduct threat modeling and risk assessments for GCP deployments, designing effective security solutionstailored to GCP services.
- · Collaborate with cross-functional teams to respond to GCP-specific security incidents promptly, conduct root cause analysis, and implement corrective actions.
- · Stay current with GCP advancements, industry security trends, and best practices, sharing knowledgeandinsights with team members.
- · Drive a culture of security awareness specific to GCP environments, ensuring security considerations areintegrated throughout development.
Requirements:
- · Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent experience).
- · Proven experience as a DevSecOps Engineer with a strong focus on GCP
- · Expertise in Rego policies and policy-as-code practices especially with implementation in GCP
- · In-depth understanding of GCP services, security controls, and best practices.
- · Proficiency in using GCP-specific security tools, vulnerability scanners, and penetration testing tools.
- · Strong experience with infrastructure-as-code (IaC) using Terraform for GCP resource provisioning and management.
- · Familiarity with CI/CD pipelines and automation tools (e.g., Jenkins, GitLab CI/CD) with GCP integrations.
- · Solid knowledge of GCP security frameworks, standards, and compliance requirements.
- · Strong understanding of container security in GCP and experience securing microservices.
- · Excellent communication and collaboration skills, with a proven ability to work effectively in cross functional teams.
- · Relevant GCP certifications such as Google Professional DevOps Engineer, Google Professional Cloud Security Engineer, or similar certifications are highly advantageous.