freehire launches on Product Hunt on 26 August.

Follow →

Senior DevSecOps Engineer

Summary

Build and secure GCP and Azure cloud infrastructure, automate CI/CD pipelines, and ensure compliance for a large-scale healthcare platform using Kubernetes, Terraform, and GitOps.

We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time.

Position Summary
We are seeking an experienced Sr. DevSecOps Engineer to support a large-scale, GCP-native and Azure-connected enterprise environment. The engineer will perform hands on work setting up CI/CD pipelines, GCP infrastructure provisioning, IAM and SSO management, DevSecOps compliance, observability, data integration, and production operations — collaborating daily with Security, EDP, Network, Data Governance, and application engineering teams across all GCP and Azure projects under the organization.

Key Responsibilities

GCP Infrastructure & GKE Provisioning

  • Provision and manage GCP projects, GKE namespaces and clusters, Cloud SQL, BigQuery, GCS, Cloud Composer, Dataproc, and Secret Manager

  • Configure Workload Identity Federation (WIF) and environment-specific resources across Dev, PDEV, QA, and Production

  • Validate environment readiness and coordinate PRIME and EDP provisioning requests

  • Manage infrastructure as code using Terraform; enforce IaC best practices across all environments

IAM, Service Accounts, SSO & Access Management

  • Create and manage GCP service accounts, AD groups, WIF bindings, token-creator roles, Secret Manager, Cloud SQL, and BigQuery permissions

  • Configure Ping SAML/OIDC integrations including client IDs/secrets, redirect URLs, certificates, and environment-specific SSO settings

  • Validate AD-group restrictions and login flows; coordinate access requests with application and SSO teams

  • Manage fine-grained IAM permissions aligned with least-privilege and compliance requirements

Infrastructure Troubleshooting & Production Readiness

  • Resolve issues across VPC Service Controls, Zscaler, VPN, firewall, DNS, signed URLs, Composer, Dataproc, Cloud SQL, Secret Manager, and GKE

  • Perform environment health checks, remove deployment blockers, and stabilize applications before go-live

  • Provide Tier 2/3 production support including incident triage, root cause analysis (RCA), and post-incident documentation

  • Coordinate with multiple teams across Network/VPC and Cloud teams to resolve infrastructure dependencies

CI/CD, ArgoCD & Release Enablement

  • Build, maintain, and optimize GitHub Actions workflows for application and infrastructure delivery

  • Configure ArgoCD, environment variables, and secrets; implement WIF-based deployment patterns

  • Promote common artifacts across environments; troubleshoot pipeline and ArgoCD authentication failures

  • Coordinate PR approvals and production releases; enforce branching and deployment gate standards

  • Support platform/library release management and versioning aligned with Agile delivery cadences

Observability, Monitoring & Cost Management

  • Develop Grafana and GCP-native dashboards; integrate Prometheus and infrastructure metrics

  • Configure monitoring scopes, define logging and alerting standards, and establish SLO requirements

  • Investigate missing telemetry and ensure full observability coverage across all environments

  • Enable BigQuery billing exports and project-level cost visibility; support cost optimization initiatives

Data Integration, Governance & Secure File Transfer

  • Support BigQuery datasets, views, policy tags, encryption/decryption, fine-grained access, and data quality validation

  • Coordinate EDM ingestion/egress, APIs, SFTP/SFG/WebTransport, historical data loads, and secure GCP-to-vendor transfers

  • Coordinate approvals and policy enablement with Data Governance and Privacy teams

  • Work with Data pipelines, Kafka/GCS streams, and secure data movement

Security Risk & Compliance (SRA/SRO)

  • Coordinate SRA/SRO intake and reassessments for all GCP projects

  • Collect and organize cloud, IAM, network, encryption, logging, vulnerability, and application-control evidence for Archer submissions

  • Address rejected evidence, track approvals, and ensure production-readiness compliance

  • Liaise with Security Risk team on project build phase compliance gates

Snyk, Wiz & Cloud Vulnerability Remediation

  • Review and triage Snyk Open Source, Wiz, GitHub Advanced Security, and cloud-security findings across all GCP and Azure projects

  • Identify application and repository owners; drive remediation, rescans, and false-positive reviews

  • Collect closure evidence and maintain Snyk project attribution accuracy within the GitHub org

  • Enforce secure handling of credentials, PII/PHI, service-account keys, and internal endpoints

  • Submit and track DevSecOps Ecosystem requests for vulnerability review and reporting scope corrections

Technical Project Status, Risk & Dependency Coordination

  • Track Key DevOps milestones for projects e.g. Jira ticket, RAID items, security dependencies, environment readiness, and external blockers

  • Provide leadership updates on delivery status, risks, and technical blockers

BAU DevOps & Cross-Team Engineering Support

  • Provide continuous daily support for GCP deployments, SSO, IAM, networking, Data Portal, application access, and production incidents

  • Conduct technical working sessions and onboard developers to platform tooling and processes

  • Coordinate across Teams, Security, Network, Data Governance, and application teams to resolve cross-functional dependencies

  • Mentor junior engineers and enforce DevOps and security best practices across the team


Required Qualifications

  • 8+ years of experience in DevOps, platform, or SRE roles in enterprise environments

  • 5+ years hands-on experience with GCP (GKE, Cloud Build, Cloud Run, Cloud SQL, BigQuery, GCS, Composer, Dataproc, Secret Manager, IAM, VPC)

  • 5+ years designing and managing CI/CD pipelines using GitHub Actions, Jenkins, or GitLab CI

  • 3+ years managing infrastructure as code with Terraform across multi-environment GCP deployments

  • Hands-on experience with ArgoCD or equivalent GitOps tooling for Kubernetes-based deployments

  • Proficiency in Workload Identity Federation (WIF) and GCP service account management

  • Experience configuring Ping Identity SAML/OIDC SSO integrations in enterprise environments

  • Hands-on experience with Snyk Open Source and/or Wiz for vulnerability management and remediation

  • Experience managing GCP IAM, AD groups, fine-grained BigQuery permissions, and Secret Manager

  • Strong proficiency in Python and Bash scripting for automation and infrastructure tooling

  • Experience with Kubernetes (GKE), Docker, and container-native deployment patterns

  • Proficiency in Prometheus, Grafana, and GCP-native monitoring and logging tools

  • Experience with VPC Service Controls, VPN, firewall rules, and DNS in GCP environments

  • Familiarity with BigQuery data governance including policy tags, encryption, and fine-grained access controls

  • Experience with secure file transfer protocols (SFTP, SFG, WebTransport) and data pipelines

  • Experience with ServiceNow RITM/REQ workflows for infrastructure and access request management

  • Familiarity with GRC process for evidence collection and submission



Preferred Qualifications

  • GCP Professional DevOps Engineer or equivalent cloud certification (AWS, Azure)

  • Experience operating within large-scale GitHub organizations including repo permissions and Snyk project attribution

  • Familiarity with Azure environments in addition to GCP

  • Experience in healthcare, insurance, or regulated industry environments (HIPAA, SOX compliance awareness)

  • Experience with Agile ceremonies — sprint planning, standups, retrospectives

  • Experience with Cloud Composer (Airflow), or Dataproc in production environments

  • Strong verbal and written communication skills; ability to engage effectively with technical and non-technical stakeholders

  • Comfortable navigating ambiguous ownership situations across large, matrixed organizations

  • Ability to manage multiple concurrent projects and priorities in a fast-paced enterprise environment

  • Strong cross-functional collaboration skills — able to coordinate across Security, EDP, Network, Data Governance, and application teams simultaneously

  • Experience liaising with third-party vendors and system owners for external system integrations


Education

  • Bachelor's degree preferred/specialized training/relevant professional qualification.

Pay Range

The typical pay range for this role is:

€50,000.00 - €125,000.00

We anticipate the application window for this opening will close on: 30/09/2026

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available