Search by job, company or skills

Senior Cloud Platform / DevSecOps Engineer

Senior Cloud Platform / DevSecOps Engineer

MP Dominic & Co
Early Applicant
Quick Apply
  • Posted 5 hours ago
  • Be among the first 10 applicants

Job Description

Role Overview

We are looking for an experienced Senior Cloud Platform / DevSecOps Engineer to design,

automate, secure, and operate enterprise-grade cloud platforms for Foresight Edge and its clients.

The role requires strong hands-on capability across Infrastructure-as-Code, cloud governance

and identity, networking, Kubernetes, CI/CD and GitOps, security controls, observability,

backup/DR, and cloud PaaS and data services.

The successful candidate should be comfortable owning infrastructure from architecture and

Infrastructure-as-Code through deployment, security, observability, operations, and

disaster recovery.

This is a hands-on engineering role suited for someone who can operate independently,

troubleshoot complex platform issues, and work closely with application, data, analytics,

security, and client infrastructure teams.

Key Responsibilities

Cloud Infrastructure & Infrastructure-as-Code

Design, build, and manage cloud infrastructure using Terraform (Terragrunt or similar

orchestration tools an advantage).

Develop reusable, well-documented modules and patterns, leveraging

verified/community modules where appropriate.

Maintain environment-specific infrastructure configurations using Git-based workflows.

Drive Infrastructure-as-Code standards, peer reviews, testing, and automation.

Cloud Governance & Identity

Implement and manage cloud governance controls, including:

o Management group / account hierarchy

o Policy-as-code and compliance guardrails

o Role-based access control (RBAC)

o Privileged access management (e.g. Azure PIM)

Design secure enterprise landing zones and subscription/account structures.

Manage identity and access using Microsoft Entra ID (or equivalent) — groups, app

registrations, service principals, and enterprise applications.

Implement OIDC and workload identity federation for passwordless automation and

workloads.

Cloud Networking

Design and support enterprise cloud networking, including:

o Hub-and-spoke network topologies

o Cloud firewalls and network security groups

o Private DNS

o Private Link / Private Endpoints

o Hybrid connectivity (ExpressRoute, VPN gateways)

o Application gateways and Web Application Firewalls (WAF)

Implement secure network segmentation and connectivity across cloud and on-premises

environments.

Troubleshoot routing, DNS, firewall, and private connectivity issues.

Kubernetes & Container Platform Engineering

Design and operate secure, private Kubernetes clusters (AKS preferred; EKS/GKE also

relevant).

Configure cluster networking (CNI), node pools, workload identity, ingress, and

storage/CSI drivers.

Implement Kubernetes security, scaling, resilience, and operational best practices.

Package and deploy applications and platform components using Helm.

Manage certificate lifecycle using tools such as cert-manager.

Troubleshoot Kubernetes workloads, networking, storage, ingress, and cluster-level

issues.

CI/CD, GitOps & Developer Platform

Administer source control platforms (e.g. GitHub) — organisations, repositories, access

controls, and branch protections.

Develop and maintain CI/CD pipelines using GitHub Actions, Azure DevOps, or similar

tools.

Configure and operate self-hosted build runners/agents where required.

Implement container build, scanning, and release pipelines.

Deploy and manage workloads through GitOps tooling such as ArgoCD or Flux.

Establish promotion strategies across development, test, staging, and production

environments.

Implement secure secrets and configuration management within CI/CD workflows.

Cloud PaaS & Data Platform Services

Hands-on experience managing and automating cloud services such as:

Container registries and secrets/key management (e.g. Azure Container Registry, Key

Vault)

Managed relational databases (e.g. PostgreSQL, SQL Server)

NoSQL / document databases (e.g. Cosmos DB, MongoDB)

Data lake and object storage (e.g. ADLS Gen2, Blob Storage)

Data integration and streaming services supporting analytics workloads (e.g. Data

Factory, Kafka, Spark-based platforms)

PaaS networking and Private Endpoints

Backup, migration, and data movement tooling

Support data migration activities and the infrastructure required for enterprise data and analytics

workloads.

Observability & Operations

Implement end-to-end monitoring using tools such as:

o OpenTelemetry

o Grafana / Prometheus

o Azure Monitor / Log Analytics (KQL)

Build dashboards, alerts, and operational health monitoring.

Implement distributed tracing, metrics, and centralised logging.

Perform root cause analysis for platform and application incidents.

Continuously improve platform reliability, performance, and availability.

Backup, Restore & Disaster Recovery

Implement Kubernetes backup and restore using tools such as Velero.

Configure database Point-in-Time Recovery (PITR) and backup policies.

Design and validate backup, recovery, and disaster-recovery processes.

Conduct restore testing and document recovery runbooks.

Ensure workloads meet required RPO and RTO objectives.

Security & DevSecOps

Integrate security controls across infrastructure and deployment pipelines.

Work with security scanning tools (e.g. Snyk, Trivy, Checkov, SonarQube) across:

o IaC scanning

o SAST

o Software Composition Analysis (SCA)

o Container image security

Implement Kubernetes policy enforcement using tools such as OPA/Gatekeeper or

Kyverno.

Configure and manage application and network security, including WAF rules.

Apply least-privilege access, secure secret handling, identity-based authentication, and

policy-driven governance.

Support compliance with client and industry requirements in regulated sectors (e.g.

finance, healthcare, public sector).

DNS, Edge & Application Access

Manage DNS and edge services (e.g. Cloudflare, Azure Front Door, Azure DNS) through

Terraform, including:

o DNS zones and records

o Secure tunnels and zero-trust application access

o Edge WAF and DDoS protection

o Global load balancing

Automate DNS and edge-security configuration through Infrastructure-as-Code.

Troubleshoot DNS resolution, certificates, edge connectivity, and application access.

Automation & Scripting

Strong hands-on capability with:

Bash and/or PowerShell (Python an advantage)

Cloud CLIs (e.g. Azure CLI)

kubectl and Helm CLI

Git

Terraform CLI

Use scripting and automation to reduce manual operational tasks and improve platform

consistency.

Required Skills & Experience

7+ years of experience in Cloud Engineering, Platform Engineering, DevOps, or SRE

roles.

Strong hands-on experience with at least one major cloud platform — Microsoft Azure

preferred; AWS or Google Cloud also valued.

Advanced Terraform / Infrastructure-as-Code expertise.

Strong knowledge of cloud governance and enterprise landing-zone concepts.

Hands-on Kubernetes experience in production (AKS, EKS, or GKE).

Strong CI/CD and GitOps experience.

Good understanding of enterprise networking and security.

Strong experience with cloud identity and access management (e.g. Entra ID).

Experience with observability, monitoring, and production troubleshooting.

Hands-on experience with security scanning and DevSecOps practices.

Experience operating production-grade platforms in enterprise environments.

Preferred Experience

Cloud certifications such as:

o Azure Solutions Architect Expert / Azure DevOps Engineer Expert / Azure

Security Engineer

o AWS Solutions Architect / DevOps Engineer – Professional

o Google Professional Cloud Architect / DevOps Engineer

Kubernetes certifications such as CKA / CKAD / CKS.

Experience supporting large, regulated, or mission-critical environments.

Experience in a consulting or client-facing delivery environment.

Experience with enterprise data and analytics platforms and cloud migration

programmes.

Experience working with globally distributed engineering teams.

Personal Attributes

Strong ownership mindset.

Excellent troubleshooting and problem-solving capability.

Comfortable working independently in complex, multi-client environments.

Able to communicate clearly with engineering, security, architecture, business, and client

stakeholders.

Strong focus on automation, security, reliability, and operational excellence.

If you are interested please share your updated CV to [Confidential Information]

More Info

Job Type:
Function:
Employment Type:

Key Skills

Platform Engineering

Infrastructure as Cod

CI/CD

About Company

We are a India government aproved overseas recruitment consultant .We have representative/associate offices in UAE ,kuwait,UK , Singapore

visit us at http://www.mpdservices.co.in