We are looking for a Senior Networking DevOps Engineer to own the network security layer and ingress configuration of an internal code quality platform running on GCP and Kubernetes.
The role covers GCP Cloud Armor policy management, DNS and firewall configuration, Ingress NGINX tuning, and abuse prevention — ensuring the service stays available and well-protected for a large developer community.
The work combines proactive hardening (automating Cloud Armor rules, cleaning up redundant network configurations) with reactive investigation (diagnosing rate-limit issues, tracing client IPs in proxy logs), with all changes validated on a test cluster before being applied to production.
Responsibilities
- Assess, configure, and automate GCP Cloud Armor security policies for the platform
- Investigate and tune GCP rate-based ban rules to avoid impacting legitimate CI/CD traffic
- Audit and remove redundant DNS zone and firewall configurations across GCP projects
- Diagnose and resolve NGINX Ingress configuration issues — proxy headers, log format, client IP extraction
- Implement monitoring and alerting for abuse patterns using GCP logs and platform APIs
- Modify and maintain Ingress NGINX Helm chart configuration
- Analyse GCP Cloud Logging and Splunk data to identify problematic IPs and traffic patterns
- Validate all network and infrastructure changes on the test cluster before rolling to production
- Document security rules, network configuration decisions, and operational runbooks
Requirements
- 3+ years of experience in networking and DevOps engineering
- Expertise in GCP Cloud Armor, including WAF rule authoring, rate-based banning, and policy automation
- Proficiency in GCP Cloud Logging, including log query language, HTTP load balancer and L4/L7 proxy log analysis, and log-based alerting
- Background in GCP networking, covering DNS zone management, VPC firewall policies, and firewall rule lifecycle
- Skills in Ingress NGINX configuration via values.yaml and proxy header handling
- Knowledge of Kubernetes and Helm
- Familiarity with Splunk for log queries, field extraction, and correlation
- Competency in GitHub Actions
- Excellent command of written and spoken English (B2+ level)
Nice to have
- Understanding of Terraform or OpenTofu
- Capability to work with GCP Cloud Monitoring and Google Cloud Load Balancing (including HTTP(S) Load Balancer)
- Flexibility to use Bash and jq
- Familiarity with SonarQube and SAST (Static Application Security Testing)
- Background in SecOps