About the Role
We are looking for an experienced Senior Cloud Platform / DevSecOps Engineer to design, automate, secure, and operate enterprise-grade cloud platforms. You will own infrastructure from architecture and Infrastructure-as-Code through deployment, security, observability, operations, and disaster recovery. This is a hands-on role for someone who can work independently, troubleshoot complex platform issues, and collaborate closely with application, data, security, and infrastructure teams.
Key Responsibilities
- Design and manage cloud infrastructure with declarative IaC, using reusable versioned modules, Git-based environment configurations, peer reviews, and testing. Implement organizational hierarchy, policy-as-code, RBAC, privileged access management, enterprise landing zones, directory services, application registrations, service identities, and OIDC/workload identity federation
- Design enterprise networking, including hub-and-spoke topologies, network firewalls, private DNS and service connectivity, dedicated hybrid connectivity gateways, WAF with L7 load balancing, and secure cloud/on-premises segmentation. Manage DNS, edge security, zero-trust access, tunneling, and global load balancing through IaC
- Design and operate private managed Kubernetes clusters (CNI, node pools, workload identity, storage drivers), with package manager deployments, automated certificate lifecycle management, and troubleshooting across workloads, networking, storage, and ingress
- Administer source control, access controls, and branch protections. Build CI/CD pipelines, self-hosted autoscaling runners, and container build/release pipelines. Deploy through GitOps with promotion across dev, test, staging, and production, and secure secrets management in pipelines
- Manage and automate container registries, secrets and key management, relational and NoSQL databases, and data lake/object storage with private connectivity, plus backup, migration, and data movement tooling. Implement monitoring with open telemetry standards, centralized logging, dashboards, alerts, tracing, and metrics, and perform root cause analysis. Implement Kubernetes backup/restore, database point-in-time recovery, DR validation, restore testing, and recovery runbooks to meet RPO and RTO
- Integrate security across infrastructure and pipelines, with automated scanning for IaC, SAST, SCA, and container images, Kubernetes policy-as-code admission controls, WAF, and least-privilege access. Automate with shell scripting and/or PowerShell, cloud CLIs, Kubernetes CLI tooling, Git, and IaC and package manager CLIs
Required Skills & Experience
- 7+ years in Cloud Engineering, Platform Engineering, DevOps, or SRE roles
- Strong hands-on experience with at least one major public cloud platform
- Advanced IaC expertise, including modular design and multi-environment management
- Strong knowledge of cloud governance and enterprise landing-zone concepts
- Hands-on experience with managed Kubernetes and container orchestration
- Strong CI/CD and GitOps experience
- Good understanding of enterprise networking and security
- Strong experience with cloud identity and access management
- Experience with observability, monitoring, and production troubleshooting
- Hands-on experience with security scanning and DevSecOps practices
- Experience operating production-grade platforms in enterprise environments
Preferred Experience
- Professional cloud certifications (architect, DevOps, or security tracks)
- Kubernetes certifications (administrator, developer, or security specialist)
- Experience supporting large, regulated, or mission-critical environments
- Experience working with globally distributed engineering teams
- Experience with enterprise data platforms and cloud migration programs