DevSecOps Engineer

Undisclosed

Sheffield

On-site

GBP 52,000 - 87,000

Full time

35 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Undisclosed is seeking a Contract Cloud Security Engineer to build and operate a GCP foundation platform, implementing IaC with Terraform and Config Connector, and embedding security controls across delivery pipelines.

You will work on security governance, risk management and modern CI/CD practices, ensuring compliant, auditable deployments and thorough runbooks for handover.

Qualifications

  • Hands-on GCP production experience with core services.
  • Experience with GKE, BigQuery, Cloud Build or Cloud Run is highly desirable.
  • Strong cloud security principles and IAM design.

Responsibilities

  • Build, deploy and manage components of the client’s GCP foundation platform using Google Cloud services and automation-first engineering practices.
  • Engineer repeatable platform and security capabilities using Infrastructure as Code (IaC), such as Terraform and Config Connector.
  • Implement and enhance preventive security controls and guardrails to improve cloud security posture and reduce operational risk.
  • Integrate, configure, deploy and manage common cloud services across IAM, networking, logging/monitoring, operating systems and container platforms.
  • Embed security into delivery pipelines by building and supporting CI/CD and continuous testing capabilities (e.g., Cloud Build, GitOps tooling such as FluxCD, Helm).
  • Ensure alignment and compliance with centrally defined Cloud Security Standards and contribute to auditability through evidence, controls mapping and documentation.
  • Operate within agreed change management practices, producing impact assessments and ensuring controlled deployments.
  • Maintain high-quality operational documentation, runbooks and support procedures for sustainable operations and handover.

Skills

GCP expertise
DevOps mindset
Stakeholder communication
Risk management
Security governance
Python/Go scripting

Tools

GKE
BigQuery
Cloud Run
Terraform
Config Connector
FluxCD
Helm
Cloud Build

Job description

Duration: contract to run until 31/07/2027

Rate: up to £473.80 p/d Umbrellainside IR35

Key responsibilities will include:
  • Build, deploy and manage components of the client’s GCP foundation platform using Google Cloud services (e.g., GKE, BigQuery, Cloud Build, Cloud Run) and automation-first engineering practices.
  • Engineer repeatable platform and security capabilities using Infrastructure as Code (IaC), such as Terraform and/or Config Connector, following established engineering standards.
  • Implement and enhance preventive security controls and guardrails centrally to improve overall cloud security posture and reduce operational risk.
  • Integrate, configure, deploy and manage common cloud services across IAM, networking, logging/monitoring, operating systems and container platforms.
  • Embed security into delivery pipelines by building and supporting CI/CD and continuous testing capabilities (e.g., Cloud Build, GitOps tooling such as FluxCD, Helm).
  • Ensure alignment and compliance with centrally defined Cloud Security Standards and contribute to auditability through evidence, controls mapping and documentation.
  • Operate within agreed change management practices, producing impact assessments where required and ensuring controlled, traceable deployments.
  • Maintain high-quality operational documentation, runbooks and support procedures to enable sustainable operations and effective handover.
What you need to have to succeed in this role:
The ideal candidate for this role will have the following experience and capabilities:
  • Hands‑on, demonstrable experience on GCP building and operating cloud services in production (hands‑on GCP experience is essential).
  • Strong experience with core GCP services; exposure to GKE, BigQuery, Cloud Build and/or Cloud Run is highly desirable.
  • Expert understanding of cloud security principles and GCP‑specific best practices, including IAM design, logging/monitoring, network security controls and workload security.
  • Strong understanding of DevOps/SRE principles, including reliability, observability, incident response supportability and engineering for resilience.
  • Proven experience implementing Infrastructure as code using Terraform (and/or Config Connector), including module design, environments, policy‑driven controls and automated deployment patterns.
  • Experience building and operation CI/CD and related tooling (e.g., Cloud Build, GitOps, FluxCD, Helm) with security controls embedded into delivery workflows.
  • Good programming/scripting skills in at least one of: Python, Go, Bash, with practical mindset for automation and operational tooling.
  • Security and compliance experience, including auditability, control evidence, configuration management and the ability to work with compliance/auditing/monitoring tooling.
  • Strong communication and stakeholder management skills, with the ability ot explain complex technical topics clearly to engineers and non‑engineers.
  • A solid understanding of risk management and proven experience ensuring compliance with relevant regulatory and internal control requirements.
Essential skills:
  • Building secure and compliant GCP capabilities using automation-first approaches.
  • Implementing and operating preventive controls and guardrails at scale.
  • Strong troubleshooting capability across cloud infrastructure, Kubernetes/container platforms and CI/CD pipelines.
  • Ability to drive continuous improvement, simplify operational processes and resuce oil through automation.
  • GCP certifications (e.g., Professional Cloud Security Engineer, Professional Cloud DevOps Engineer, Professional Cloud Architect).
  • Experience operation regulated workloads in a large enterprise environment.
  • Experience with container security patterns and Kubernetes hardening approaches.
  • Familiarity integrating security findings and policy checks into DevSecOps workflows and reporting.

All profiles will be reviewed against the required skills and experience. Due to the high number of applications we will only be able to respond to successful applicants in the first instance. We thank you for your interest and the time taken to apply!

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Read more
Read more

Experis • Sheffield

On-site
GBP 80,000 - 110,000
GCP DevOps Engineer
GCP DevOps Engineer

your Jared • Sheffield

Hybrid
GBP 111,000 - 138,000
Remote work
Contract Inside IR35
Senior DevOps Engineer
Senior DevOps Engineer

ML • Greater London

Hybrid
GBP 70,000 - 95,000
Cloud Security Engineer
Cloud Security Engineer

Experis • Knutsford

Hybrid
GBP 111,000 - 122,000
GCP DevSecOps Engineer
GCP DevSecOps Engineer

HCLTech • Sheffield

On-site
GBP 70,000 - 110,000
DevSecOps Engineering Lead CGEMJP00346044
DevSecOps Engineering Lead CGEMJP00346044

Experis - ManpowerGroup • Greater London

Hybrid
Senior DevOps Engineer - GCP
Senior DevOps Engineer - GCP

VANRATH • Stockport

Hybrid
GBP 74,000 - 92,000
Hybrid work
Google Cloud Platform Architect
Google Cloud Platform Architect

Deloitte - Recruitment • Glasgow

On-site
GBP 90,000 - 101,000
DevSecOps Engineer, London, Hybrid, Up to £90k base, Fintech, GCP
DevSecOps Engineer, London, Hybrid, Up to £90k base, Fintech, GCP

Space Executive • Greater London

Hybrid
GBP 81,000 - 99,000
Senior GCP DevSecOps Engineer
Senior GCP DevSecOps Engineer

TESTQ Technologies LTD. • Sheffield

On-site
GBP 75,000 - 110,000