We are seeking a seasoned Senior Cloud Platform / DevSecOps Engineer to lead the design, automation, security, and operation of enterprise-grade cloud platforms. This role involves full ownership of infrastructure, from architecture and Infrastructure-as-Code (IaC) development to deployment, security, observability, operations, and disaster recovery. The ideal candidate will be hands-on, able to work independently, troubleshoot complex platform issues, and collaborate effectively with application, data, security, and infrastructure teams.

Key Responsibilities

- Design and manage cloud infrastructure using declarative IaC with reusable, versioned modules. Implement Git-based environment configurations, conduct peer reviews, and perform testing. Establish organizational hierarchy, policy-as-code, role-based access control (RBAC), privileged access management, enterprise landing zones, directory services, application registrations, service identities, and OIDC/workload identity federation.

- Architect enterprise networking solutions including hub-and-spoke topologies, network firewalls, private DNS, service connectivity, dedicated hybrid connectivity gateways, web application firewalls (WAF) with Layer 7 load balancing, and secure segmentation between cloud and on-premises environments. Manage DNS, edge security, zero-trust access, tunneling, and global load balancing through IaC.

- Design and operate private managed Kubernetes clusters, covering container network interface (CNI), node pools, workload identity, and storage drivers. Oversee package manager deployments, automate certificate lifecycle management, and troubleshoot workloads, networking, storage, and ingress issues.

- Administer source control systems, access controls, and branch protections. Build and maintain CI/CD pipelines, including self-hosted autoscaling runners and container build/release pipelines. Deploy applications using GitOps with promotion workflows across development, testing, staging, and production environments. Ensure secure secrets management within pipelines.

- Manage and automate container registries, secrets and key management, relational and NoSQL databases, and data lake/object storage with private connectivity. Implement backup, migration, and data movement tooling. Establish monitoring solutions based on open telemetry standards, centralized logging, dashboards, alerts, tracing, and metrics. Conduct root cause analysis for production issues.

- Implement Kubernetes backup and restore strategies, database point-in-time recovery, disaster recovery validation, restore testing, and recovery runbooks to meet Recovery Point Objectives (RPO) and Recovery Time Objectives (RTO).

- Integrate security throughout infrastructure and pipelines, including automated scanning for IaC, static application security testing (SAST), software composition analysis (SCA), container images, Kubernetes policy-as-code admission controls, WAF, and least-privilege access enforcement. Automate tasks using shell scripting, PowerShell, cloud CLIs, Kubernetes CLI tooling, Git, and IaC/package manager command-line interfaces.

Required Qualifications

- Minimum of 7 years’ experience in Cloud Engineering, Platform Engineering, DevOps, or Site Reliability Engineering (SRE) roles.

- Strong hands-on expertise with at least one major public cloud platform (e.g., AWS, Azure, GCP).

- Advanced proficiency in Infrastructure-as-Code, including modular design and managing multiple environments.

- Deep understanding of cloud governance frameworks and enterprise landing-zone architectures.

- Practical experience managing and operating managed Kubernetes and container orchestration platforms.

- Solid background in CI/CD pipeline development and GitOps methodologies.

- Good knowledge of enterprise networking concepts and security best practices.

- Extensive experience with cloud identity and access management solutions.

- Skilled in observability, monitoring, and troubleshooting production environments.

- Hands-on experience with security scanning tools and DevSecOps practices.

- Proven ability to operate production-grade platforms within enterprise settings.

Preferred Qualifications and Benefits

- Professional cloud certifications such as cloud architect, DevOps engineer, or security specialist.

- Kubernetes certifications including administrator, developer, or security specialist credentials.

- Experience supporting large-scale, regulated, or mission-critical environments.

- Background working with globally distributed engineering teams.

- Exposure to enterprise data platforms and cloud migration initiatives.

This role offers the opportunity to work at the forefront of cloud platform engineering, applying advanced DevSecOps practices within a collaborative and dynamic enterprise environment.

Job Details

Total Positions:
1 Post
Job Shift:
First Shift (Day)
Job Type:
Job Location:
Gender:
No Preference
Age:
18 - 65 Years
Career Level:
Manager
Experience:
6 Years - 10 Years
Apply Before:
Oct 08, 2026
Posting Date:
Oct 02, 2026

NKU Technologies

· 11-50 employees - Lahore

What is your Competitive Advantage?

Get quick competitive analysis and professional insights about yourself
Talk to our expert team of counsellors to improve your CV!
Try Rozee Premium
I found a job on Rozee!