Senior GCP DevSecOps Engineer
Ref: BBBH67670_1785922205Senior GCP DevSecOps Engineer
Whitehall Resources are currently looking for a Senior GCP DevSecOps Engineer on a hybrid basis in South Yorkshire for an initial 6-month contract.
***INSIDE IR35***
Key responsibilities:
- Engineer repeatable platform and security capabilities using Infrastructure as Code (IaC), such as Terraform and/or Config Connector, following established engineering standards.
- Implement and enhance preventive security controls and guardrails centrally to improve overall cloud security posture and reduce operational risk.
- Integrate, configure, deploy and manage common cloud services across IAM, networking, logging/monitoring, operating systems and container platforms.
- Embed security into delivery pipelines by building and supporting CI/CD and continuous testing capabilities (e.g., Cloud Build, GitOps tooling such as FluxCD, Helm).
- Ensure alignment and compliance with centrally defined Cloud Security Standards and contribute to auditability through evidence, controls mapping and documentation.
- Operate within agreed change management practices, producing impact assessments where required and ensuring controlled, traceable deployments.
- Maintain high-quality operational documentation, runbooks and support procedures to enable sustainable operations and effective handover.
Essential skills and experience:
- Hands-on, demonstrable experience on GCP building and operating cloud services in production (hands-on GCP experience is essential).
- Strong experience with core GCP services; exposure to GKE, BigQuery, Cloud Build and/or Cloud Run is highly desirable.
- Expert understanding of cloud security principles and GCP-specific best practices, including IAM design, logging/monitoring, network security controls and workload security.
- Strong understanding of DevOps/SRE principles, including reliability, observability, incident response supportability and engineering for resilience.
- Proven experience implementing Infrastructure as code using Terraform (and/or Config Connector), including module design, environments, policy-driven controls and automated deployment patterns.
- Experience building and operation CI/CD and related tooling (e.g., Cloud Build, GitOps, FluxCD, Helm) with security controls embedded into delivery workflows.
- Good programming/scripting skills in at least one of: Python, Go, Bash, with practical mindset for automation and operational tooling.
- Security and compliance experience, including auditability, control evidence, configuration management and the ability to work with compliance/auditing/monitoring tooling.
- Strong communication and stakeholder management skills, with the ability to explain complex technical topics clearly to engineers and non-engineers.
- A solid understanding of risk management and proven experience ensuring compliance with relevant regulatory and internal control requirements.
- Building secure and compliant GCP capabilities using automation-first approaches.
- Implementing and operating preventive controls and guardrails at scale.
- Strong troubleshooting capability across cloud infrastructure, Kubernetes/container platforms and CI/CD pipelines.
- Ability to drive continuous improvement, simplify operational processes and resuce oil through automation.
Desirable skills:
- GCP certifications (e.g., Professional Cloud Security Engineer, Professional Cloud DevOps Engineer, Professional Cloud Architect).
- Experience operation regulated workloads in a large enterprise environment.
- Experience with container security patterns and Kubernetes hardening approaches.
- Familiarity integrating security findings and policy checks into DevSecOps workflows and reporting.
All of our opportunities require that applicants are eligible to work in the specified country/location, unless otherwise stated in the job description.
Whitehall Resources are an equal opportunities employer who value a diverse and inclusive working environment. All qualified applicants will receive consideration for employment without regard to race, religion, gender identity or expression, sexual orientation, national origin, pregnancy, disability, age, veteran status, or other characteristics.
