Overview
We are looking for a Senior Networking DevOps Engineer to own the network security layer and ingress configuration of an internal code quality platform running on GCP and Kubernetes.
The role covers GCP Cloud Armor policy management, DNS and firewall configuration, Ingress NGINX tuning, and abuse prevention — ensuring the service stays available and well-protected for a large developer community.
The work combines proactive hardening (automating Cloud Armor rules, cleaning up redundant network configurations) with reactive investigation (diagnosing rate-limit issues, tracing client IPs in proxy logs), with all changes validated on a test cluster before being applied to production.
- Assess, configure, and automate GCP Cloud Armor security policies for the platform
- Investigate and tune GCP rate-based ban rules to avoid impacting legitimate CI/CD traffic
- Audit and remove redundant DNS zone and firewall configurations across GCP projects
- Diagnose and resolve NGINX Ingress configuration issues — proxy headers, log format, client IP extraction
- Implement monitoring and alerting for abuse patterns using GCP logs and platform APIs
- Modify and maintain Ingress NGINX Helm chart configuration
- Analyse GCP Cloud Logging and Splunk data to identify problematic IPs and traffic patterns
- Validate all network and infrastructure changes on the test cluster before rolling to production
- Document security rules, network configuration decisions, and operational runbooks
- 3+ years of experience in networking and DevOps engineering
- Expertise in GCP Cloud Armor, including WAF rule authoring, rate-based banning, and policy automation
- Proficiency in GCP Cloud Logging, including log query language, HTTP load balancer and L4/L7 proxy log analysis, and log-based alerting
- Background in GCP networking, covering DNS zone management, VPC firewall policies, and firewall rule lifecycle
- Skills in Ingress NGINX configuration via values.yaml and proxy header handling
- Knowledge of Kubernetes and Helm
- Familiarity with Splunk for log queries, field extraction, and correlation
- Competency in GitHub Actions
- Excellent command of written and spoken English (B2+ level)
- Delivering innovative solutions to industry leaders, making a global impact
- Enjoyable working environment, whether it is the vibrant office or the comfort of your home
- Opportunity to work abroad for up to two months per year
- Relocation opportunities within our offices in 55+ countries
- Corporate and social events
- Leadership development, career advising, soft skills and well-being programs
- Certifications, including GCP, Azure and AWS
- Unlimited access to EPAM's internal learning database
- Free English classes with certified teachers
- Participation in the Employee Stock Purchase Plan
- Monetary bonuses for engaging in the referral program
- Comprehensive medical & family care package
- Four trust days per year for personal needs
- Discounts for fitness clubs
- Benefits package (hotels, restaurants, stores and services)
- Understanding of Terraform or OpenTofu
- Capability to work with GCP Cloud Monitoring and Google Cloud Load Balancing (including HTTP(S) Load Balancer)
- Flexibility to use Bash and jq
- Familiarity with SonarQube and SAST (Static Application Security Testing)
- Background in SecOps
- DevOps
- Cloud
- GitHub Actions
- Google Cloud Armor
- Google Cloud Logging
- Kubernetes
- nginx
- Bash
- Google Cloud Load Balancing
- Helm
- SAST (Static Application Security Testing)
- SecOps
- SonarQube
- Terraform
✨ Our intelligent job search engine discovered this job and republished it for your convenience.
Please be aware that the job information may be incorrect or incomplete. The job announcement remains the property of its original publisher. To view the original job and its full details, please visit the job's URL on the owner’s page.
Please clearly mention that you have heard of this job opportunity on https://ijob.am.

