We are seeking a seasoned Senior Cloud Platform / DevSecOps Engineer to lead the design, automation, security, and operation of enterprise-grade cloud platforms. This role requires full ownership of infrastructure, from architecture and Infrastructure-as-Code (IaC) through deployment, security, observability, operations, and disaster recovery. The ideal candidate will be hands-on, capable of working independently, troubleshooting complex platform issues, and collaborating closely with application, data, security, and infrastructure teams.
Key Responsibilities
- Design and manage cloud infrastructure using declarative IaC with reusable, versioned modules, Git-based environment configurations, peer reviews, and testing. Implement organizational hierarchy, policy-as-code, role-based access control (RBAC), privileged access management, enterprise landing zones, directory services, application registrations, service identities, and OIDC/workload identity federation.
- Architect enterprise networking solutions including hub-and-spoke topologies, network firewalls, private DNS and service connectivity, dedicated hybrid connectivity gateways, web application firewalls (WAF) with Layer 7 load balancing, and secure segmentation between cloud and on-premises environments. Manage DNS, edge security, zero-trust access, tunneling, and global load balancing through IaC.
- Design and operate private managed Kubernetes clusters, including container network interface (CNI), node pools, workload identity, and storage drivers. Manage package deployments, automate certificate lifecycle management, and troubleshoot workloads, networking, storage, and ingress components.
- Administer source control systems, access controls, and branch protections. Build CI/CD pipelines with self-hosted autoscaling runners and container build/release pipelines. Deploy using GitOps with environment promotion across development, testing, staging, and production stages, while ensuring secure secrets management within pipelines.
- Manage and automate container registries, secrets and key management, relational and NoSQL databases, and data lake/object storage with private connectivity. Oversee backup, migration, and data movement tooling. Implement monitoring using open telemetry standards, centralized logging, dashboards, alerts, tracing, and metrics. Conduct root cause analysis and implement Kubernetes backup/restore, database point-in-time recovery, disaster recovery validation, restore testing, and recovery runbooks aligned with recovery point objectives (RPO) and recovery time objectives (RTO).
- Integrate security throughout infrastructure and pipelines by automating scanning for IaC, static application security testing (SAST), software composition analysis (SCA), container images, Kubernetes policy-as-code admission controls, WAF, and enforcing least-privilege access. Automate tasks using shell scripting, PowerShell, cloud CLIs, Kubernetes CLI tools, Git, and IaC/package manager CLIs.
Required Qualifications
- Minimum of 7 years’ experience in Cloud Engineering, Platform Engineering, DevOps, or Site Reliability Engineering (SRE) roles.
- Strong hands-on expertise with at least one major public cloud platform.
- Advanced skills in Infrastructure-as-Code, including modular design and multi-environment management.
- Deep understanding of cloud governance and enterprise landing zone concepts.
- Practical experience with managed Kubernetes and container orchestration.
- Proven ability in CI/CD pipeline development and GitOps methodologies.
- Solid knowledge of enterprise networking and security principles.
- Extensive experience with cloud identity and access management.
- Proficiency in observability, monitoring, and production troubleshooting.
- Hands-on experience with security scanning and DevSecOps practices.
- Demonstrated success operating production-grade platforms in enterprise environments.
Preferred Qualifications
- Professional cloud certifications such as architect, DevOps, or security tracks.
- Kubernetes certifications including administrator, developer, or security specialist.
- Experience supporting large-scale, regulated, or mission-critical environments.
- Background working with globally distributed engineering teams.
- Experience with enterprise data platforms and cloud migration initiatives.
This position offers the opportunity to work on cutting-edge cloud platforms in a collaborative, fast-paced environment, driving innovation and operational excellence across critical enterprise systems.