At a Glance
- Tasks: Design and maintain secure cloud infrastructure for national security operations using GCP and Kubernetes.
- Company: Join a leading tech firm focused on defence and national security.
- Benefits: Competitive salary, loyalty pension, private medical insurance, and generous leave policies.
- Other info: Enjoy professional development opportunities and a supportive work culture.
- Why this job: Make a real impact on the UK's digital infrastructure while working with cutting-edge technology.
- Qualifications: Experience in GCP, Kubernetes, and UK Defence environments required.
The predicted salary is between 63000 - 77000 £ per year.
We are seeking a Senior Cloud Platform Engineer with deep expertise in Google Cloud Platform (GCP), Kubernetes, and High-Assurance UK Defence environments. In this role, you will design, deploy, and maintain mission-critical, sovereign cloud infrastructure for sensitive national security operations. You will operate at the intersection of modern cloud-native software engineering and strict defense compliance—building automated, air-gapped platforms using Google Distributed Cloud air-gapped (GDC air-gapped) and GKE Enterprise capable of supporting tactical edge analytics and disconnected containerised workloads.
Key Responsibilities
- Sovereign Infrastructure as Code (IaC): Design, build, and maintain enterprise-grade GCP environments and Sovereign Landing Zones using Terraform and Ansible.
- Kubernetes Orchestration: Manage, scale, and secure production GKE and GKE Enterprise clusters in air-gapped or low-bandwidth environments.
- High-Assurance Security Architecture: Implement Zero-Trust network topologies, Private Google Access, Service Controls, and IAM policies aligned with NCSC Cloud Security Principles, JSP 604, and MoD Secure by Design (SbD) frameworks.
- Air-Gapped & Edge Deployments: Operate fully disconnected, sovereign cloud nodes (GDC air-gapped) and handle offline artifact management (e.g., container image mirroring, local Helm repositories, offline Terraform providers).
- DevSecOps & Policy-as-Code: Build secure CI/CD pipelines incorporating container scanning, cryptographic image signing, secret management (Vault/GCP KMS), and automated policy enforcement (OPA/Gatekeeper).
- Data Sovereignty & Isolation: Configure private interconnects, network firewalls, and outbound-only proxies to guarantee strict data sovereignty and prevent data exfiltration.
Required Experience
- Defence & High-Assurance Context: Active UK SC Clearance, ideally MoD Developed Vetting or eligibility for DV. Proven experience delivering cloud platforms within UK Defence (MoD, CSOC, DE&S), Intelligence, or National Security environments. Working knowledge of UK Government Security Classifications (OFFICIAL-SENSITIVE / SECRET / TOP SECRET), NCSC guidelines, and JSP 604 accreditation loops.
- GCP & Infrastructure Automation: 3+ years of production experience operating Google Cloud Platform (GCP). Expertise in Terraform for declarative infrastructure management. Deep understanding of GCP networking (VPC Service Controls, Cloud Interconnect, Private Service Connect, Cloud NAT, DNS).
- Containerisation & Kubernetes: Production experience administering GKE / GKE Enterprise. Hands-on experience with container security, Service Mesh (Istio), and admission controllers (OPA/Gatekeeper or Kyverno). Experience managing air-gapped software deployments where continuous internet connectivity is absent.
Desirable Qualifications
- Certifications: GCP Professional Cloud Architect, GCP Professional Cloud Security Engineer, or Certified Kubernetes Administrator (CKA).
- Experience with Google Distributed Cloud air-gapped (GDC air-gapped) hardware appliances or edge deployments.
- Familiarity with event streaming (Kafka, Cloud Pub/Sub) in low-bandwidth, intermittent, or limited (DIL) connectivity scenarios.
- Background in Armed Forces technical branches, tactical C4ISR systems, or specialised defence consultancies.
Competitive Pay: Salaries reviewed annually to ensure they reflect your performance and market value.
Loyalty Pension: We invest in your future. Starting at a 5% employer contribution, we increase this by 0.5% every year after your third anniversary, up to a maximum of 8%.
Protection: Comprehensive Group Life Assurance for peace of mind.
Purpose & Culture
- Real Impact: Work on mission-critical projects that secure and improve the UK's digital infrastructure.
- Autonomy: A culture that empowers you to make decisions, prototype rapidly, and iterate towards success.
- Service & Community: We support those who serve. 10 paid days for Reservist Military Service.
Work / Life Balance
- Time Off: 25 days annual leave + Bank Holidays, with the flexibility to Buy/Sell additional days to suit your lifestyle.
- Giving back: 2 paid volunteering days per year.
Development & Growth
- Master Your Craft: Fully funded professional certifications (AWS, GCP, Agile, etc.) supported by 5 days paid study leave.
- Expand Your Horizons: An additional £500 annual "Personal Choice" fund to learn whatever inspires you—work-related or not.
- Support: Access to 1-2-1 professional coaching and team training to accelerate your career.
Health & Balance
- Premium Health: Vitality Private Medical Insurance (includes Apple Watch, gym discounts, and rewards).
- Flexibility: Genuine hybrid working with a WFH equipment allowance to perfect your home setup.
Wellbeing: Cycle to Work scheme and a commitment to sustainable, healthy working practices.
Senior Cloud Platform Engineer employer: Zaizi
Zaizi is an excellent employer for those looking to make a meaningful impact in government services through design. With a strong focus on professional development, competitive pay, and a supportive hybrid work culture, employees are encouraged to grow their skills while collaborating with a talented team. The opportunity to mentor fellow designers further enriches the experience, making Zaizi a rewarding place to advance your career.