Senior Networking DevOps Engineer

Epam Systems — Armenia · Posted ~3 hours ago

Senior Full-time Remote

Skills

GCP Kubernetes GCP Cloud Armor DNS firewall configuration Ingress NGINX network security rate limiting proxy logs DevOps automation Cloud Armor NGINX firewalls

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A senior networking DevOps role focused on securing and operating a cloud-native platform at scale. You will manage cloud security policies, DNS, firewalls, ingress traffic, rate limiting, and proxy-level diagnostics, while automating protections and validating infrastructure changes before production rollout. The position is fully remote within the country.

Highlights

Fully remote role with the flexibility to work from anywhere in the country. Offers ownership of critical network security, opportunities to automate and harden infrastructure, and hands-on work across cloud, Kubernetes, and production reliability.

Description

We are looking for a Senior Networking DevOps Engineer to own the network security layer and ingress configuration of an internal code quality platform running on GCP and Kubernetes. The role covers GCP Cloud Armor policy management, DNS and firewall configuration, Ingress NGINX tuning, and abuse prevention — ensuring the service stays available and well-protected for a large developer community. The work combines proactive hardening (automating Cloud Armor rules, cleaning up redundant network configurations) with reactive investigation (diagnosing rate-limit issues, tracing client IPs in proxy logs), with all changes validated on a test cluster before being applied to production. This is a fully remote position that offers you the flexibility to work from any location in Armenia, whether it's your home or well-equipped offices in Yerevan or Gyumri. Responsibilities Assess, configure, and automate GCP Cloud Armor security policies for the platformInvestigate and tune GCP rate-based ban rules to avoid impacting legitimate CI/CD trafficAudit and remove redundant DNS zone and firewall configurations across GCP projectsDiagnose and resolve NGINX Ingress configuration issues — proxy headers, log format, client IP extractionImplement monitoring and alerting for abuse patterns using GCP logs and platform APIsModify and maintain Ingress NGINX Helm chart configurationAnalyse GCP Cloud Logging and Splunk data to identify problematic IPs and traffic patternsValidate all network and infrastructure changes on the test cluster before rolling to productionDocument security rules, network configuration decisions, and operational runbooks Requirements 3+ years of experience in networking and DevOps engineeringExpertise in GCP Cloud Armor, including WAF rule authoring, rate-based banning, and policy automationProficiency in GCP Cloud Logging, including log query language, HTTP load balancer and L4/L7 proxy log analysis, and log-based alertingBackground in GCP networking, covering DNS zone management, VPC firewall policies, and firewall rule lifecycleSkills in Ingress NGINX configuration via values.yaml and proxy header handlingKnowledge of Kubernetes and HelmFamiliarity with Splunk for log queries, field extraction, and correlationCompetency in GitHub ActionsExcellent command of written and spoken English (B2+ level) Nice to have Understanding of Terraform or OpenTofuCapability to work with GCP Cloud Monitoring and Google Cloud Load Balancing (including HTTP(S) Load Balancer)Flexibility to use Bash and jqFamiliarity with SonarQube and SAST (Static Application Security Testing)Background in SecOps We offer We connect like-minded peopleDelivering innovative solutions to industry leaders, making a global impactEnjoyable working environment, whether it is the vibrant office or the comfort of your homeOpportunity to work abroad for up to two months per yearRelocation opportunities within our offices in 55+ countriesCorporate and social eventsWe invest in your growthLeadership development, career advising, soft skills and well-being programsCertifications, including GCP, Azure and AWSUnlimited access to EPAM's internal learning databaseFree English classes with certified teachersWe cover it allParticipation in the Employee Stock Purchase PlanMonetary bonuses for engaging in the referral programComprehensive medical & family care packageFour trust days per year for personal needsDiscounts for fitness clubsBenefits package (hotels, restaurants, stores and services) EPAM is global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and ambitious startups. With over thirty years of expertise in custom software, product and platform engineering, we empower our clients to become AI-Native enterprises, driving measurable value from innovation and digital investments.