Live opening · Posted 2 days ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
SourceFuse is looking for a seasoned Senior DevSecOps / Cloud Infrastructure Engineer with 6+ years of experience to join our team. You will be responsible for hardening GCP environments, automating security guardrails, and optimizing infrastructure for security, reliability, performance, cost, and compliance.
Working closely with engineering teams, you will bridge the gap between development, security, and operations—ensuring that our cloud security posture keeps pace with rapid product growth.
Key Responsibilities:
Security and Compliance - Proactively identify, prioritize, and remediate vulnerabilities, excessive permissions, exposed services, and infrastructure misconfigurations across a footprint of more than 3,000 GCP resources.
Infrastructure Hardening - Implement and manage security controls across IAM, service accounts, Organization Policies, VPC firewall policies, Cloud Armor, VPC Service Controls, Secret Manager, and Cloud Load Balancing.
Cloud Governance - Establish scalable guardrails across GCP organizations, folders, projects, Shared VPCs, and environments. Enforce least-privilege access, secure resource provisioning, encryption, audit logging, and policy compliance.
Operational Excellence - Investigate complex production issues using Cloud Logging, Cloud Monitoring, Cloud Audit Logs, Error Reporting, and distributed tracing. Lead root-cause analysis and implement long-term corrective actions.
Infrastructure as Code - Maintain and evolve cloud infrastructure using Terraform and Google Cloud Infrastructure Manager, ensuring environments are repeatable, secure, reviewable, and version-controlled.
Performance and Cost Optimization - Monitor and tune data services such as Cloud Storage, Firestore, Bigtable, Cloud SQL for MySQL, Memorystore for Redis, and Elasticsearch, along with compute platforms including Compute Engine, GKE, Cloud Run, App Engine, and Cloud Run
functions.
DevSecOps Automation - Integrate infrastructure validation, vulnerability detection, container scanning, secrets detection, policy enforcement, and compliance checks into CI/CD pipelines.
Continuous Improvement - Champion “security by design” and strengthen the organization’s practices around threat modelling, secure architecture, incident response, observability, and production readiness.
Required Technical Skills:
Google Cloud Expertise - Deep, hands-on experience with the following services and capabilities:
● Compute and orchestration: Compute Engine, Managed Instance Groups, GKE, Cloud Run, App Engine, and Cloud Run functions
● Data and storage: Cloud Storage, Firestore, Bigtable, Cloud SQL for MySQL, Memorystore for Redis, and Elasticsearch or Elastic Cloud on Google Cloud
● Networking: VPC, Shared VPC, Private Service Connect, Cloud DNS, Cloud NAT, Cloud CDN, and Cloud Load Balancing
● Security: IAM, service accounts, Organization Policy Service, Cloud Armor, VPC firewall policies, VPC Service Controls, Secret Manager, Cloud KMS, and Cloud Audit Logs
● Observability: Cloud Logging, Cloud Monitoring, Error Reporting, Cloud Trace, and log-based metrics and alerts
● Infrastructure as Code: Advanced Terraform experience, including reusable modules, state management, policy validation, and automated deployment workflows
Cloud Architecture - Strong understanding of IaaS, PaaS, SaaS, serverless, containerized, and distributed-system architectures.
GCP Resource Hierarchy - Experience designing and operating GCP organizations, folders, projects, billing accounts, Shared VPCs, and centralized security controls at scale.
Cloud Architecture - Strong understanding of IaaS, PaaS, SaaS, serverless, containerized, and distributed-system architectures.
Troubleshooting - Expert-level proficiency in log analysis, performance monitoring, incident response, and root-cause analysis across distributed production systems.
Security Mindset - Strong understanding of least privilege, zero-trust principles, defense in depth, secrets management, vulnerability management, supply-chain security, and secure software delivery.
Problem-Solving - A proactive engineer who can operate effectively in high-stakes production environments, balance security with delivery speed, and stay current with evolving cloud threats and defensive practices.
Preferred Qualifications:
Container Security - Strong experience with Docker and Kubernetes, including GKE security, Workload Identity Federation, network policies, admission controls, pod security, and secure container image management.
Google Cloud Security Tooling - Experience with Security Command Center, Event Threat Detection, Container Threat Detection, Cloud IDS, Artifact Analysis, Binary Authorization, Sensitive Data Protection, and Google Security Operations.
Third-Party Security Platforms - Experience with tools such as Orca Security, CrowdStrike, Wiz, Snyk, Prisma Cloud, or equivalent vulnerability and cloud-security posture management platforms.
CI/CD and Software Supply Chain - Experience integrating security
controls into Cloud Build, Cloud Deploy, GitHub Actions, GitLab CI, Jenkins, or similar delivery pipelines.
Policy as Code -Experience with tools such as Open Policy Agent, Gatekeeper, Terraform validation, or organization-level policy enforcement.
Compliance - Experience supporting security or compliance frameworks such as ISO 27001, SOC 2, PCI DSS, GDPR, or equivalent standards.
Work arrangement
No
More openings worth a look
Recently tracked roles with full details and direct application links.