Senior DevSecOps Engineer
SigmaSoftware2
Posted: March 10, 2026
Interested in this position?
Create a free account to apply with AI-powered matching
Quick Summary
We are looking for a security-focused DevOps engineer to take ownership of a GCP-native environment, responsible for auditing infrastructure, implementing secrets management, and driving SOC2 & ISO 27001 certification.
Job Description
We are looking for a security-focused DevOps engineer to take ownership of a GCP-native environment. Your immediate mandate is to audit our infrastructure, implement secrets management across 25+ DBs, and drive the technical controls for our SOC2 & ISO 27001 certification.
• CI/CD & Release Automation: Manage and optimize our Jenkins pipelines integrated with Bitbucket. Reduce build times, automate deployments, and ensure smooth rollouts to production
• Environment Management: Architect and provision isolated Staging and QA environments on GKE. Automate the spin-up/tear-down of ephemeral environments to unblock feature testing
• Observability: Own the Datadog implementation. Configure dashboards, APM tracing, and alert policies to monitor system health, latency, and uptime across our Cloud and Device stacks
• Compliance Automation (Drata): Drive our SOC2 and ISO 27001 readiness using Drata. Automate evidence collection, manage infrastructure access reviews, and close compliance gaps
• GCP Security & Hardening: Secure our GKE clusters, manage VPC firewalls/networking, and lock down CloudDNS/Nginx ingress points
• Pipeline Security: Shift security left by integrating vulnerability scanning into the pipeline (scanning Docker/GCR images) and managing secrets via Vault
• DB Operations: Automate backup schedules, disaster recovery drills, and access controls for our fleet of MySQL and BigQuery datasets
• Expert-level knowledge of GCP (specifically GKE, GCR, and IAM)
• Experience with cloud security and taking a system through SOC2 or ISO 27001 audits
• Strong Infrastructure-as-Code skills (Terraform)
• Fluent English