About this role
We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time. Position Summary We are seeking an experienced Sr. DevSecOps Engineer to support a large-scale, GCP-native and Azure-connected enterprise environment. The engineer will perform hands on work setting up CI/CD pipelines, GCP infrastructure provisioning, IAM and SSO management, DevSecOps compliance, observability, data integration, and production operations — collaborating daily with Security, EDP, Network, Data Governance, and application engineering teams across all GCP and Azure projects under the organization.
Key Responsibilities
GCP Infrastructure & GKE Provisioning
• Provision and manage GCP projects, GKE namespaces and clusters, Cloud SQL, BigQuery, GCS, Cloud Composer, Dataproc, and Secret Manager
• Configure Workload Identity Federation (WIF) and environment-specific resources across Dev, PDEV, QA, and Production
• Validate environment readiness and coordinate PRIME and EDP provisioning requests
• Manage infrastructure as code using Terraform; enforce IaC best practices across all environments
IAM, Service Accounts, SSO & Access Management
• Create and manage GCP service accounts, AD groups, WIF bindings, token-creator roles, Secret Manager, Cloud SQL, and BigQuery permissions
• Configure Ping SAML/OIDC integrations including client IDs/secrets, redirect URLs, certificates, and environment-specific SSO settings
• Validate AD-group restrictions and login flows; coordinate access requests with application and SSO teams
• Manage fine-grained IAM permissions aligned with least-privilege and compliance requirements
Infrastructure Troubleshooting & Production Readiness
• Resolve issues across VPC Service Controls, Zscaler, VPN, firewall, DNS, signed URLs, Composer, Dataproc, Cloud SQL, Secret Manager, and GKE
• Perform environment health checks, remove deployment blockers, and stabilize applications before go-live
• Provide Tier 2/3 production support including incident triage, root cause analysis (RCA), and post-incident documentation
• Coordinate with multiple teams across Network/VPC and Cloud teams to resolve infrastructure dependencies
CI/CD, ArgoCD & Release Enablement
• Build, maintain, and optimize GitHub Actions workflows for application and infrastructure delivery
• Configure ArgoCD, environment variables, and secrets; implement WIF-based deployment patterns
• Promote common artifacts across environments; troubleshoot pipeline and ArgoCD authentication failures
• Coordinate PR approvals and production releases; enforce branching and deployment gate standards
• Support platform/library release management and versioning aligned with Agile delivery cadences
Observability, Monitoring & Cost Management
• Develop Grafana and GCP-native dashboards; integrate Prometheus and infrastructure metrics
• Configure monitoring scopes, define logging and alerting standards, and establish SLO requirements
• Investigate missing telemetry and ensure full observability coverage across all environments
• Enable BigQuery billing exports and project-level cost visibility; support cost optimization initiatives
Data Integration, Governance & Secure File Transfer
• Support BigQuery datasets, views, policy tags, encryption/decryption, fine-grained access, and data quality validation
• Coordinate EDM ingestion/egress, APIs, SFTP/SFG/WebTransport, historical data loads, and secure GCP-to-vendor transfers
• Coordinate approvals and policy enablement with Data Governance and Privacy teams
• Work with Data pipelines, Kafka/GCS streams, and secure data movement
Security Risk & Compliance (SRA/SRO)
• Coordinate SRA/SRO intake and reassessments for all GCP projects
• Collect and organize cloud, IAM, network, encryption, logging, vulnerability, and application-control evidence for Archer submissions
• Address rejected evidence, track approvals, and ensure production-readiness compliance
• Liaise with Security Risk team on project build phase compliance gates
Snyk, Wiz & Cloud Vulnerability Remediation
• Review and triage Snyk Open Source, Wiz, GitHub Advanced Security, and cloud-security findings across all GCP and Azure projects
• Identify application and repository owners; drive remediation, rescans, and false-positive reviews
• Collect closure evidence and maintain Snyk project attribution accuracy within the GitHub org
• Enforce secure handling of credentials, PII/PHI, service-account keys, and internal endpoints
• Submit and track DevSecOps Ecosystem requests for vulnerability review and reporting scope corrections
Technical Project Status, Risk & Dependency Coordination
• Track Key DevOps milestones for projects e.g. Jira ticket, RAID items, security dependencies, environment readiness, and external blockers
• Provide leadership updates on delivery status, risks, and technical blockers
BAU DevOps & Cross-Team Engineering Support
• Provide continuous daily support for GCP deployments, SSO, IAM, networking, Data Portal, application access, and production incidents
• Conduct technical working sessions and onboard developers to platform tooling and processes
• Coordinate across Teams, Security, Network, Data Governance, and application teams to resolve cross-functional dependencies
• Mentor junior engineers and enforce DevOps and security best practices across the team
Required Qualifications
• 8+ years of experience in DevOps, platform, or SRE roles in enterprise environments
• 5+ years hands-on experience with GCP (GKE, Cloud Build, Cloud Run, Cloud SQL, BigQuery, GCS, Composer, Dataproc, Secret Manager, IAM, VPC)
• 5+ years designing and managing CI/CD pipelines using GitHub Actions, Jenkins, or GitLab CI
• 3+ years managing infrastructure as code with Terraform across multi-environment GCP deployments
• Hands-on experience with ArgoCD or equivalent GitOps tooling for Kubernetes-based deployments
• Proficiency in Workload Identity Federation (WIF) and GCP service account management
• Experience configuring Ping Identity SAML/OIDC SSO integrations in enterprise environments
• Hands-on experience with Snyk Open Source and/or Wiz for vulnerability management and remediation
• Experience managing GCP IAM, AD groups, fine-grained BigQuery permissions, and Secret Manager
• Strong proficiency in Python and Bash scripting for automation and infrastructure tooling
• Experience with Kubernetes (GKE), Docker, and container-native deployment patterns
• Proficiency in Prometheus, Grafana, and GCP-native monitoring and logging tools
• Experience with VPC Service Controls, VPN, firewall rules, and DNS in GCP environments
• Familiarity with BigQuery data governance including policy tags, encryption, and fine-grained access controls
• Experience with secure file transfer protocols (SFTP, SFG, WebTransport) and data pipelines
• Experience with ServiceNow RITM/REQ workflows for infrastructure and access request management
• Familiarity with GRC process for evidence collection and submission
Preferred Qualifications
• GCP Professional DevOps Engineer or equivalent cloud certification (AWS, Azure)
• Experience operating within large-scale GitHub organizations including repo permissions and Snyk project attribution
• Familiarity with Azure environments in addition to GCP
• Experience in healthcare, insurance, or regulated industry environments (HIPAA, SOX compliance awareness)
• Experience with Agile ceremonies — sprint planning, standups, retrospectives
• Experience with Cloud Composer (Airflow), or Dataproc in production environments
• Strong verbal and written communication skills; ability to engage effectively with technical and non-technical stakeholders
• Comfortable navigating ambiguous ownership situations across large, matrixed organizations
• Ability to manage multiple concurrent projects and priorities in a fast-paced enterprise environment
• Strong cross-functional collaboration skills — able to coordinate across Security, EDP, Network, Data Governance, and application teams simultaneously
• Experience liaising with third-party vendors and system owners for external system integrations
Education
• Bachelor's degree preferred/specialized training/relevant professional qualification.
Pay Range The typical pay range for this role is: €50,000.00 - €125,000.00 We anticipate the application window for this opening will close on: 30/09/2026