About the company
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a DevSecOps SR - GCP based in Brazil.
Responsibilities
- Design, implement, maintain, and continuously improve cloud infrastructure and platform services on Google Cloud Platform.
- Administer and evolve Kubernetes environments using GKE, as well as Cloud Run and other managed cloud services.
- Build reusable Terraform modules and establish infrastructure-as-code standards that support scalable and consistent environments.
- Define and implement secure patterns for networking, IAM, Service Accounts, Workload Identity, secrets management, and environment segregation.
- Apply least-privilege principles and security controls across cloud infrastructure, container images, workloads, and runtime environments.
- Establish secure deployment mechanisms between CI/CD pipelines and production workloads, supporting reliable software delivery.
- Implement and improve infrastructure and service observability through metrics, logs, tracing, dashboards, and alerts.
- Support engineering teams in defining SLIs, SLOs, alerting strategies, capacity planning, and operational reliability practices.
- Automate infrastructure provisioning, configuration management, and recurring operational activities using appropriate scripting and programming tools.
- Investigate incidents, perform root-cause analysis, and implement corrective measures to prevent recurring failures.
- Monitor platform costs, capacity, availability, performance, and operational risks, identifying opportunities for optimization.
- Document infrastructure standards, architectural decisions, security practices, and operational procedures while guiding engineering teams toward safe and effective cloud usage.
Requirements
- Proven hands-on experience with Google Cloud Platform in production environments.
- Strong knowledge of GKE and Kubernetes, including the operation and security of containerized workloads.
- Solid experience with Terraform and infrastructure-as-code practices.
- Strong understanding of IAM, Service Accounts, Workload Identity, Secret Manager, and cloud security principles.
- Practical experience with GCP networking, including VPCs, firewalls, DNS, and load balancing.
- Experience with Docker and deploying and operating containerized applications.
- Experience with observability, monitoring, alerting, incident response, and troubleshooting of production environments.
- Knowledge of high availability, scalability, backup strategies, disaster recovery, and reliability engineering.
- Experience automating infrastructure and operational tasks with Bash, Python, Go, or similar technologies.
- Strong understanding of DevSecOps principles applied to infrastructure, cloud environments, and application runtime.
- Experience with Cloud SQL, Pub/Sub, Memorystore, or Artifact Registry is a plus.
- Familiarity with Datadog, OpenTelemetry, Policy as Code tools such as OPA or Gatekeeper, and Kubernetes hardening is desirable.
- Knowledge of SBOMs, image signing, software supply-chain security, FinOps, and cloud cost optimization is an advantage.
- Experience working in financial, regulated, or audit-intensive environments is valued.
- Relevant Google Cloud certifications, such as Professional Cloud DevOps Engineer or Professional Cloud Architect, are a plus.
- Strong autonomy, analytical thinking, problem-solving ability, and a proactive approach to improving technical environments.
Conditions
- Meal or food allowance.
- Discounts on courses, universities, and language institutions.
- Access to an internal online learning platform with free, regularly updated courses and certificates.
- Mentoring opportunities.
- Benefits and discounts for medical consultations and examinations.
- Health insurance.
- Dental insurance.
- Discounts and special offers at a range of partner establishments.
- Travel benefits and discounts.
- Pet care benefits.
- Remote work opportunity in Brazil.