At a Glance
- Tasks: Develop and maintain security policies for GCP, ensuring a secure development pipeline.
- Company: Join a dynamic tech team focused on innovative cloud security solutions.
- Benefits: Competitive salary, flexible working options, and opportunities for professional growth.
- Other info: Collaborative environment with a strong focus on security awareness and career advancement.
- Why this job: Make a real impact on software security while working with cutting-edge technologies.
- Qualifications: Experience in DevSecOps, GCP, Rego policies, and Terraform is essential.
The predicted salary is between 60000 - 80000 £ per year.
We are seeking a skilled and experienced DevSecOps Engineer with a strong specialization in Google Cloud Platform (GCP) to join our dynamic team. In this role, you will play a pivotal role in ensuring the security and integrity of our software development processes on GCP. Your expertise in GCP, Rego policies, and Terraform will be instrumental in building a secure and efficient development pipeline.
Responsibilities
- Develop, implement, and maintain Rego policies to enforce security controls and compliance standards within our GCP infrastructure and applications.
- Collaborate with development and operations teams to integrate security into the GCP-focused CI/CD pipeline, ensuring security checks and scans are automated and seamlessly incorporated.
- Leverage your GCP expertise to architect and implement secure microservices and containerized applications, ensuring compliance with GCP security best practices.
- Design and implement infrastructure-as-code (IaC) using Terraform to define and manage GCP resources securely and efficiently.
- Perform thorough security assessments on GCP environments, utilizing GCP-specific security tools and technologies, to identify and address potential vulnerabilities.
- Conduct threat modeling and risk assessments for GCP deployments, designing effective security solutions tailored to GCP services.
- Collaborate with cross-functional teams to respond to GCP-specific security incidents promptly, conduct root cause analysis, and implement corrective actions.
- Stay current with GCP advancements, industry security trends, and best practices, sharing knowledge and insights with team members.
- Drive a culture of security awareness specific to GCP environments, ensuring security considerations are integrated throughout development.
Requirements
- Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent experience).
- Proven experience as a DevSecOps Engineer with a strong focus on GCP.
- Expertise in Rego policies and policy-as-code practices especially with implementation in GCP. THIS IS AN ABSOLUTE MUST.
- In-depth understanding of GCP services, security controls, and best practices.
- Proficiency in using GCP-specific security tools, vulnerability scanners, and penetration testing tools.
- Experience with Wiz and its integration for continuous security monitoring in GCP environments.
- Strong experience with infrastructure-as-code (IaC) using Terraform for GCP resource provisioning and management.
- Familiarity with CI/CD pipelines and automation tools (e.g., Jenkins, GitLab CI/CD) with GCP integrations.
- Solid knowledge of GCP security frameworks, standards, and compliance requirements.
- Strong understanding of container security in GCP and experience securing microservices.
- Excellent communication and collaboration skills, with a proven ability to work effectively in cross-functional teams.
- Relevant GCP certifications such as Google Professional DevOps Engineer, Google Professional Cloud Security Engineer, or similar certifications are highly advantageous.
If you're enthusiastic about combining your GCP expertise, Rego policies knowledge, and Terraform skills to shape a secure GCP development environment, we invite you to join our team and drive our GCP-focused software security initiatives forward.
Code Engineer - Security, GCP, Rego Policies - London, UK employer: Photon
Contact Detail:
Photon Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Code Engineer - Security, GCP, Rego Policies - London, UK
✨Network Like a Pro
Get out there and connect with folks in the industry! Attend meetups, webinars, or even local tech events. The more people you know, the better your chances of landing that dream job.
✨Show Off Your Skills
Don’t just talk about your experience; demonstrate it! Create a portfolio showcasing your GCP projects, Rego policies, and Terraform implementations. This will give potential employers a clear view of what you can bring to the table.
✨Ace the Interview
Prepare for those interviews by brushing up on common DevSecOps questions and scenarios. Practice explaining your thought process when tackling security challenges in GCP. Confidence is key!
✨Apply Through Our Website
Make sure to apply directly through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are proactive about joining our team.
We think you need these skills to ace Code Engineer - Security, GCP, Rego Policies - London, UK
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights your experience with GCP, Rego policies, and Terraform. We want to see how your skills align with the role, so don’t be shy about showcasing relevant projects or achievements!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you’re passionate about DevSecOps and how your expertise can help us enhance our GCP security. Keep it engaging and personal!
Showcase Your Projects: If you've worked on any GCP-related projects, especially involving security, make sure to mention them. We love seeing real-world applications of your skills, so include links or descriptions of your work!
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it’s super easy!
How to prepare for a job interview at Photon
✨Know Your GCP Inside Out
Make sure you brush up on your Google Cloud Platform knowledge. Be ready to discuss specific GCP services, security controls, and best practices. Familiarise yourself with the latest advancements in GCP, as this will show your enthusiasm and commitment to staying current in the field.
✨Master Rego Policies
Since expertise in Rego policies is a must, prepare to explain how you've implemented these in past projects. Bring examples of how you've enforced security controls and compliance standards using Rego, and be ready to discuss any challenges you faced and how you overcame them.
✨Showcase Your Terraform Skills
Be prepared to talk about your experience with infrastructure-as-code using Terraform. Highlight specific projects where you've defined and managed GCP resources securely. If possible, share insights on how you've integrated Terraform into CI/CD pipelines to enhance security.
✨Communicate Effectively
Strong communication skills are key, especially when collaborating with cross-functional teams. Practice articulating your thoughts clearly and concisely. Prepare to discuss how you've worked with development and operations teams to integrate security into the GCP-focused CI/CD pipeline.