Summary
Join a cloud engineering team responsible for building secure, scalable platform foundations on Google Cloud. You will automate infrastructure with IaC, integrate cloud services across identity, networking and observability, embed security into delivery pipelines, and strengthen centralized controls and compliance.
Highlights
Build and manage modern cloud infrastructure with a strong security focus. The role offers hands-on ownership of GCP foundations, infrastructure automation, security guardrails, CI/CD, and compliance capabilities.
Description
Role Description:
• Build, deploy and manage components of the bank GCP foundation platform using Google Cloud services (e.g., GKE, BigQuery, Cloud Build, Cloud Run) and automation-first engineering practices.
• Engineer repeatable platform and security capabilities using Infrastructure as Code (IaC), such as Terraform and/or Config Connector, following established engineering standards.
• Implement and enhance preventive security controls and guardrails centrally to improve overall cloud security posture and reduce operational risk.
• Integrate, configure, deploy and manage common cloud services across IAM, networking, logging/monitoring, operating systems and container platforms.
• Embed security into delivery pipelines by building and supporting CI/CD and continuous testing capabilities (e.g., Cloud Build, GitOps tooling such as FluxCD, Helm).
• Ensure alignment and compliance with centrally defined Cloud Security Standards and contribute to auditability through evidence, controls mapping and documentation.
• Operate within agreed change management practices, producing impact assessments where required and ensuring controlled, traceable deployments.
• Maintain high-quality operational documentation, runbooks and support procedures to enable sustainable operations and effective handover.
• Hands-on, demonstrable experience on GCP building and operating cloud services in production (hands-on GCP experience is essential).
• Strong experience with core GCP services; exposure to GKE, BigQuery, Cloud Build and/or Cloud Run is highly desirable.
• Expert understanding of cloud security principles and GCP-specific best practices, including IAM design, logging/monitoring, network security controls and workload security.
• Strong understanding of DevOps/SRE principles, including reliability, observability, incident response supportability and engineering for resilience.
• Proven experience implementing Infrastructure as code using Terraform (and/or Config Connector), including module design, environments, policy-driven controls and automated deployment patterns.
• Experience building and operation CI/CD and related tooling (e.g., Cloud Build, GitOps, FluxCD, Helm) with security controls embedded into delivery workflows.
• Good programming/scripting skills in at least one of: Python, Go, Bash, with practical mindset for automation and operational tooling.
• Security and compliance experience, including auditability, control evidence, configuration management and the ability to work with compliance/auditing/monitoring tooling.
• Strong communication and stakeholder management skills, with the ability ot explain complex technical topics clearly to engineers and non-engineers.
• A solid understanding of risk management and proven experience ensuring compliance with relevant regulatory and internal control requirements.
• Building secure and compliant GCP capabilities using automation-first approaches.
• Implementing and operating preventive controls and guardrails at scale.
• Strong troubleshooting capability across cloud infrastructure, Kubernetes/container platforms and CI/CD pipelines.
• Ability to drive continuous improvement, simplify operational processes and resuce oil through automation.
• GCP certifications (e.g., Professional Cloud Security Engineer, Professional Cloud DevOps Engineer, Professional Cloud Architect).
• Experience operation regulated workloads in a large enterprise environment.
• Experience with container security patterns and Kubernetes hardening approaches.
• Familiarity integrating security findings and policy checks into DevSecOps workflows and reporting.