Summary
✨ AI‑Generated
Build and operate mission-critical cloud platforms for highly regulated and security-sensitive environments. You will design sovereign infrastructure using infrastructure-as-code, manage production Kubernetes clusters, and create automated platforms capable of operating in disconnected or low-bandwidth conditions. The role combines cloud-native engineering, security architecture, and stringent compliance requirements.
Highlights
Design and operate mission-critical sovereign cloud infrastructure for high-assurance environments. The role combines modern cloud-native engineering with advanced security and compliance requirements, including automated and disconnected infrastructure for sensitive operations.
Description
Role Overview
We are seeking a Senior Cloud Platform Engineer with deep expertise in Google Cloud Platform (GCP), Kubernetes, and High-Assurance UK Defence environments.
In this role, you will design, deploy, and maintain mission-critical, sovereign cloud infrastructure for sensitive national security operations.
You will operate at the intersection of modern cloud-native software engineering and strict defense compliance—building automated, air-gapped platforms using Google Distributed Cloud air-gapped (GDC air-gapped) and GKE Enterprise capable of supporting tactical edge analytics and disconnected containerised workloads.
Requirements
Key Responsibilities
Sovereign Infrastructure as Code (IaC): Design, build, and maintain enterprise-grade GCP environments and Sovereign Landing Zones using Terraform and AnsibleKubernetes Orchestration: Manage, scale, and secure production GKE and GKE Enterprise clusters in air-gapped or low-bandwidth environmentsHigh-Assurance Security Architecture: Implement Zero-Trust network topologies, Private Google Access, Service Controls, and IAM policies aligned with NCSC Cloud Security Principles, JSP 604, and MoD Secure by Design (SbD) frameworksAir-Gapped & Edge Deployments: Operate fully disconnected, sovereign cloud nodes (GDC air-gapped) and handle offline artifact management (e.g., container image mirroring, local Helm repositories, offline Terraform providers)DevSecOps & Policy-as-Code: Build secure CI/CD pipelines incorporating container scanning, cryptographic image signing, secret management (Vault/GCP KMS), and automated policy enforcement (OPA/Gatekeeper)Data Sovereignty & Isolation: Configure private interconnects, network firewalls, and outbound-only proxies to guarantee strict data sovereignty and prevent data exfiltration
Required Experience
Defence & High-Assurance ContextActive UK SC Clearance, ideally MoD Developed Vetting or eligibility for DVProven experience delivering cloud platforms within UK Defence (MoD, CSOC, DE&S), Intelligence, or National Security environmentsWorking knowledge of UK Government Security Classifications (OFFICIAL-SENSITIVE / SECRET / TOP SECRET), NCSC guidelines, and JSP 604 accreditation loops GCP & Infrastructure Automation3+ years of production experience operating Google Cloud Platform (GCP)Expertise in Terraform for declarative infrastructure managementDeep understanding of GCP networking (VPC Service Controls, Cloud Interconnect, Private Service Connect, Cloud NAT, DNS) Containerisation & KubernetesProduction experience administering GKE / GKE EnterpriseHands-on experience with container security, Service Mesh (Istio), and admission controllers (OPA/Gatekeeper or Kyverno)Experience managing air-gapped software deployments where continuous internet connectivity is absent
Desirable Qualifications
Certifications: GCP Professional Cloud Architect, GCP Professional Cloud Security Engineer, or Certified Kubernetes Administrator (CKA)Experience with Google Distributed Cloud air-gapped (GDC air-gapped) hardware appliances or edge deploymentsFamiliarity with event streaming (Kafka, Cloud Pub/Sub) in low-bandwidth, intermittent, or limited (DIL) connectivity scenariosBackground in Armed Forces technical branches, tactical C4ISR systems, or specialised defence consultancies
Benefits
Competitive Pay: Salaries reviewed annually to ensure they reflect your performance and market valueLoyalty Pension: We invest in your future.
Starting at a 5% employer contribution, we increase this by 0.5% every year after your third anniversary, up to a maximum of 8%Protection: Comprehensive Group Life Assurance for peace of mind
Purpose & Culture
Real Impact: Work on mission-critical projects that secure and improve the UK's digital infrastructureAutonomy: A culture that empowers you to make decisions, prototype rapidly, and iterate towards successService & Community: We support those who serve.
10 paid days for Reservist Military Service
Work / Life Balance
Time Off: 25 days annual leave + Bank Holidays, with the flexibility to Buy/Sell additional days to suit your lifestyleGiving back: 2 paid volunteering days per year
Development & Growth
Master Your Craft: Fully funded professional certifications (AWS, GCP, Agile, etc.) supported by 5 days paid study leaveExpand Your Horizons: An additional £500 annual "Personal Choice" fund to learn whatever inspires you—work-related or notSupport: Access to 1-2-1 professional coaching and team training to accelerate your career
Health & Balance
Premium Health: Vitality Private Medical Insurance (includes Apple Watch, gym discounts, and rewards)Flexibility: Genuine hybrid working with a WFH equipment allowance to perfect your home setupWellbeing: Cycle to Work scheme and a commitment to sustainable, healthy working practices