Senior DevOps Engineer

🧑‍💻 Senior DevOps Engineer (4+ years) – GCP First, AWS‑Hybrid Environment

Your Mission

Own the end‑to‑end build‑and‑run pipeline for our cloud-native platform. You’ll design scalable and secure infrastructure in GCP, containerize microservices, deploy to Kubernetes, embed DevSecOps and observability, and keep production running smoothly with optimized CI/CD and incident-response practices.


Key Responsibilities

  1. 🌐 Cloud Infrastructure (GCP-first)

    • Design, provision, and manage production workloads using Compute Engine, GKE, Cloud SQL, VPC, Cloud DNS, Load Balancers, Pub/Sub, and Cloud KMS.

    • Optimize for cost and high availability.

    • Enforce least-privilege IAM across projects and service accounts.

  2. 💾 Infrastructure as Code (IaC)

    • Create and maintain reusable Terraform modules with remote state, workspaces, and versioned deployments.

    • Automate server/app configurations via Ansible (experience with Chef/Puppet is a plus).

  3. 🔁 CI/CD & DevSecOps

    • Build CI/CD pipelines using Bitbucket Pipelines, Jenkins, or GitHub Actions.

    • Integrate SAST/DAST, container scanning (Trivy/Anchore), image signing, and approval gates.

    • Coordinate promotion workflows across environments.

  4. 🐋 Kubernetes & Containers

    • Build secure, optimized Docker images.

    • Manage GKE lifecycle: Secrets, ConfigMaps, Ingress, HPA/VPA, and node pools.

    • Release packaging via Helm or Kustomize; GitOps experience (Argo CD/Flux) is a bonus.

  5. 📊 Observability & Incident Response

    • Deploy and configure Prometheus + Grafana or Cloud Monitoring with actionable dashboards and alerts.

    • Implement structured logging/tracing using Cloud Logging/Trace or OpenTelemetry.

    • Enable Sentry (or equivalent) for exception tracking.

  6. 🛠️ Linux & Networking

    • Maintain Ubuntu/RHEL systems with hardening, patching, systemd, kernel & GRUB tuning.

    • Manage Nginx/Apache configurations, TLS termination, and reverse proxying.

    • Design VPCs, subnets, firewalls, VPN/Interconnect, and DNS.

  7. 🛡️ Security & Compliance

    • Enforce RBAC via IAM; manage service-account keys and Workload Identity.

    • Implement secrets, encryption (in-transit & at-rest), scans, and policy-as-code.


🎯 Core Technical Skills

Domain Must-Have Tools / Technologies
Cloud Infra GCP (Compute, GKE, SQL, VPC, Pub/Sub, Load Balancing, IAM)
IaC & Automation Terraform, Ansible, Bash/Python scripting
CI/CD Bitbucket Pipelines / Jenkins / GitHub Actions
Containers Docker, GKE, Helm / Kustomize, GitOps
Observability Prometheus, Grafana, Cloud Monitoring, OpenTelemetry, Sentry
Linux & Networking Ubuntu/RHEL, Nginx/Apache, VPC, Firewalls, VPN, DNS
Security IAM, Workload Identity, TLS, secrets management, OWASP mitigations

✨ Preferred / Nice-to-Have

  • Experience with service-mesh / zero-trust (Istio, Linkerd, BeyondCorp)

  • Cost‑monitoring tools (GCP Cost Explorer, budgeting alerts)

  • Multi-cloud or hybrid (AWS, VMware, OpenStack)

  • Kubernetes operators / progressive delivery (Argo Rollouts, KEDA)

  • Extended observability (Loki, Tempo, Jaeger)


🧠 Ways of Working

  • Root‑cause mindset: Calmly handle incidents; lead thorough post‑mortems.

  • Clear communicator: Write runbooks, diagrams, and concise technical notes.

  • Automation-first: Design for repeatable, tested, automated pipelines.

  • Collaborative: Align with dev teams, champion DevSecOps, and accelerate feedback loops.


Apply for this position

Allowed Type(s): .pdf, .doc, .docx

Sign Up to Get Latest Updates

Subscribe to our newsletter and stay updated.