All Jobs Vacancy

Senior GCP DevSecOps Engineer

Posted 1 day ago by Whitehall Resources

Key responsibilities:

  • Engineer repeatable platform and security capabilities using Infrastructure as Code (IaC), such as Terraform and/or Config Connector, following established engineering standards.
  • Implement and enhance preventive security controls and guardrails centrally to improve overall cloud security posture and reduce operational risk.
  • Integrate, configure, deploy and manage common cloud services across IAM, networking, logging/monitoring, operating systems and container platforms.
  • Embed security into delivery pipelines by building and supporting CI/CD and continuous testing capabilities (e.g., Cloud Build, GitOps tooling such as FluxCD, Helm).
  • Ensure alignment and compliance with centrally defined Cloud Security Standards and contribute to auditability through evidence, controls mapping and documentation.
  • Operate within agreed change management practices, producing impact assessments where required and ensuring controlled, traceable deployments.
  • Maintain high-quality operational documentation, runbooks and support procedures to enable sustainable operations and effective handover.

Essential skills and experience:

  • Hands-on, demonstrable experience on GCP building and operating cloud services in production (hands-on GCP experience is essential).
  • Strong experience with core GCP services; exposure to GKE, BigQuery, Cloud Build and/or Cloud Run is highly desirable.
  • Expert understanding of cloud security principles and GCP-specific best practices, including IAM design, logging/monitoring, network security controls and workload security.
  • Strong understanding of DevOps/SRE principles, including reliability, observability, incident response supportability and engineering for resilience.
  • Proven experience implementing Infrastructure as code using Terraform (and/or Config Connector), including module design, environments, policy-driven controls and automated deployment patterns.
  • Experience building and operation CI/CD and related tooling (e.g., Cloud Build, GitOps, FluxCD, Helm) with security controls embedded into delivery workflows.
  • Good programming/scripting skills in at least one of: Python, Go, Bash, with practical mindset for automation and operational tooling.
  • Security and compliance experience, including auditability, control evidence, configuration management and the ability to work with compliance/auditing/monitoring tooling.
  • Strong communication and stakeholder management skills, with the ability to explain complex technical topics clearly to engineers and non-engineers.
  • A solid understanding of risk management and proven experience ensuring compliance with relevant regulatory and internal control requirements.
  • Building secure and compliant GCP capabilities using automation-first approaches.
  • Implementing and operating preventive controls and guardrails at scale.
  • Strong troubleshooting capability across cloud infrastructure, Kubernetes/container platforms and CI/CD pipelines.
  • Ability to drive continuous improvement, simplify operational processes and resuce oil through automation.

Desirable skills:

  • GCP certifications (e.g., Professional Cloud Security Engineer, Professional Cloud DevOps Engineer, Professional Cloud Architect).
  • Experience operation regulated workloads in a large enterprise environment.
  • Experience with container security patterns and Kubernetes hardening approaches.
  • Familiarity integrating security findings and policy checks into DevSecOps workflows and reporting.
Rate:
Not specified
Location:
Sheffield
IR35 Status:
Inside
Remote Status:
Hybrid
Industry:
IT
Seniority Level:
Senior

Take-Home Pay

Not Available

Visit calculators for additional details

Create a free account to view the take-home pay for this contract

Share job