Sutherland is seeking an experienced DevSecOps Engineer who will embed security into every layer of our cloud infrastructure and software delivery pipeline. Your primary responsibility is to ensure our GCP and AWS environments, Kubernetes clusters, CI/CD pipelines, and internal endpoints are secure, compliant, and hardened — without slowing down engineering velocity
Job Description
Cloud Security — Primary
Own cloud security posture management (CSPM) across GCP and AWS — continuous assessment, misconfiguration detection, and remediation tracking.
Design and enforce IAM policies, service account hygiene, least-privilege access controls, and workload identity across multi-cloud environments.
Implement VPC security controls — private service access, firewall rules, network policies, ingress/egress restrictions, and Private Google Access.
Internalise and secure service endpoints — move external-facing services to internal load balancers, private endpoints, and VPN/interconnect. Continuously audit and reduce the public attack surface.
Manage secrets hygiene — enforce Secret Manager (GCP) and AWS Secrets Manager, eliminate hardcoded credentials, and rotate secrets programmatically.
Lead cloud security incident response — triage, contain, investigate, and remediate across cloud and Kubernetes environments.
Own compliance reporting for SOC 2, HIPAA, and ISO 27001 — evidence collection, gap analysis, and control implementation.
Conduct regular threat modelling, security reviews, and architecture risk assessments.
Kubernetes Security — Primary
Don't want to miss the next one?
Subscribe to daily email alerts for roles matching your interests.