Design and enforce Rego policy-as-code for GCP, integrate security into GCP CI/CD pipelines, implement IaC with Terraform, perform GCP security assessments and incident response, and drive GCP-specific security best practices across teams.
Job Description:
We are seeking a skilled and experienced DevSecOps Engineer with a strong specialization in Google Cloud Platform (GCP) to join our dynamic team. In this role, you will play a pivotal role in ensuring the security and integrity of our software development processes on GCP. Your expertise in GCP, Rego policies, and Terraform will be instrumental in building a secure and efficient development pipeline.
Responsibilities:
- Develop, implement, and maintain Rego policies to enforce security controls and compliance standards within our GCP infrastructure and applications.
- Collaborate with development and operations teams to integrate security into the GCP-focused CI/CD pipeline, ensuring security checks and scans are automated and seamlessly incorporated.
- Leverage your GCP expertise to architect and implement secure microservices and containerized applications, ensuring compliance with GCP security best practices.
- Design and implement infrastructure-as-code (IaC) using Terraform to define and manage GCP resources securely and efficiently.
- Perform thorough security assessments on GCP environments, utilizing GCP-specific security tools and technologies, to identify and address potential vulnerabilities.
- Conduct threat modeling and risk assessments for GCP deployments, designing effective security solutions tailored to GCP services.
- Collaborate with cross-functional teams to respond to GCP-specific security incidents promptly, conduct root cause analysis, and implement corrective actions.
- Stay current with GCP advancements, industry security trends, and best practices, sharing knowledge and insights with team members.
- Drive a culture of security awareness specific to GCP environments, ensuring security considerations are integrated throughout development.
Requirements:
- Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent experience).
- Proven experience as a DevSecOps Engineer with a strong focus on GCP
- Expertise in Rego policies and policy-as-code practices especially with implementation in GCP. THIS IS AN ABSOLUTE MUST
- In-depth understanding of GCP services, security controls, and best practices.
- Proficiency in using GCP-specific security tools, vulnerability scanners, and penetration testing tools.
- Experience with Wiz and its integration for continuous security monitoring in GCP environments.
- Strong experience with infrastructure-as-code (IaC) using Terraform for GCP resource provisioning and management.
- Familiarity with CI/CD pipelines and automation tools (e.g., Jenkins, GitLab CI/CD) with GCP integrations.
- Solid knowledge of GCP security frameworks, standards, and compliance requirements.
- Strong understanding of container security in GCP and experience securing microservices.
- Excellent communication and collaboration skills, with a proven ability to work effectively in cross-functional teams.
- Relevant GCP certifications such as Google Professional DevOps Engineer, Google Professional Cloud Security Engineer, or similar certifications are highly advantageous.
If you're enthusiastic about combining your GCP expertise, Rego policies knowledge, and Terraform skills to shape a secure GCP development environment, we invite you to join our team and drive our GCP-focused software security initiatives forward.
Same Posting Description for Internal and External Candidates
Similar Jobs
AdTech • Cloud • Digital Media • Information Technology • News + Entertainment • App development
Build high-fidelity prototypes and interactive experiences across web, mobile, and TV platforms. Develop internal tools, Figma plugins, shared frameworks, APIs, and AI-powered utilities that improve design workflows. Collaborate with designers, engineers, product managers, and researchers, integrate live or simulated data, iterate based on feedback, and mentor other design engineers. The role emphasizes front-end engineering, interaction design, rapid experimentation, emerging technologies, and streaming media experiences.
Top Skills:
Adobe Creative SuiteAntigravityApacheAugmentAWSAzureClaude CodeCloudflareCodexContentfulCSSCursorFigmaFigma ApiFigma PluginsFirebaseGCPGitGitGraphQLHTMLJavaScriptLightningjsMixpanelNext.JsNode.jsProgressive Web AppsReactReact NativeSwiftSwiftuiTypescriptVercelXcode
Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
Lead strategic identity security engagements across EMEA, advising executive stakeholders on risk, regulation, governance, access controls, and operational priorities. Shape complex sales opportunities, define identity roadmaps, facilitate executive workshops, align business and technical teams, and translate identity programs into measurable outcomes. The role requires influencing C-level decisions, working through ambiguity, partnering with sales and delivery teams, and representing SailPoint at industry events.
Top Skills:
Cloud SecurityIdentity And Access Management (Iam)Identity Security
Big Data • Cloud • Healthtech • Software • Big Data Analytics
Lead complex engagements in Life Sciences Consulting, managing project teams and relationships, driving strategy and financial outcomes, while fostering a culture of excellence in the team.
Top Skills:
AIBusiness ConsultingDataSaaSVeeva Products
What you need to know about the Manchester Tech Scene
Home to a £5 billion digital ecosystem, including MediaCity, which consists of major players like the BBC, ITV and Ericsson, Manchester is one of the U.K.'s top digital tech hubs, at the forefront of advancements in film, television and emerging sectors like as e-sports, while also fostering a community of professionals dedicated to pushing creative and technological boundaries.

.png)

