☁️cloudjobboard
← All roles
CVS Health logo

CVS Health

Senior DevSecOps Engineer

📍 IRL - GalwayOn-siteFull-timePosted 6 days ago

Apply now →

We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time.

Position Summary

We are seeking an experienced Sr. DevSecOps Engineer to support a large-scale, GCP-native and Azure-connected enterprise environment. The engineer will perform hands on work setting up CI/CD pipelines, GCP infrastructure provisioning, IAM and SSO management, DevSecOps compliance, observability, data integration, and production operations — collaborating daily with Security, EDP, Network, Data Governance, and application engineering teams across all GCP and Azure projects under the organization.

Key Responsibilities

GCP Infrastructure & GKE Provisioning

  • Provision and manage GCP projects, GKE namespaces and clusters, Cloud SQL, BigQuery, GCS, Cloud Composer, Dataproc, and Secret Manager
  • Configure Workload Identity Federation (WIF) and environment-specific resources across Dev, PDEV, QA, and Production
  • Validate environment readiness and coordinate PRIME and EDP provisioning requests
  • Manage infrastructure as code using Terraform; enforce IaC best practices across all environments

IAM, Service Accounts, SSO & Access Management

  • Create and manage GCP service accounts, AD groups, WIF bindings, token-creator roles, Secret Manager, Cloud SQL, and BigQuery permissions
  • Configure Ping SAML/OIDC integrations including client IDs/secrets, redirect URLs, certificates, and environment-specific SSO settings
  • Validate AD-group restrictions and login flows; coordinate access requests with application and SSO teams
  • Manage fine-grained IAM permissions aligned with least-privilege and compliance requirements

Infrastructure Troubleshooting & Production Readiness

  • Resolve issues across VPC Service Controls, Zscaler, VPN, firewall, DNS, signed URLs, Composer, Dataproc, Cloud SQL, Secret Manager, and GKE
  • Perform environment health checks, remove deployment blockers, and stabilize applications before go-live
  • Provide Tier 2/3 production support including incident triage, root cause analysis (RCA), and post-incident documentation
  • Coordinate with multiple teams across Network/VPC and Cloud teams to resolve infrastructure dependencies

CI/CD, ArgoCD & Release Enablement

  • Build, maintain, and optimize GitHub Actions workflows for application and infrastructure delivery
  • Configure ArgoCD, environment variables, and secrets; implement WIF-based deployment patterns
  • Promote common artifacts across environments; troubleshoot pipeline and ArgoCD authentication failures
  • Coordinate PR approvals and production releases; enforce branching and deployment gate standards
  • Support platform/library release management and versioning aligned with Agile delivery cadences

Observability, Monitoring & Cost Management

  • Develop Grafana and GCP-native dashboards; integrate Prometheus and infrastructure metrics
  • Configure monitoring scopes, define logging and alerting standards, and establish SLO requirements
  • Investigate missing telemetry and ensure full observability coverage across all environments
  • Enable BigQuery billing exports and project-level cost visibility; support cost optimization initiatives

Data Integration, Governance & Secure File Transfer

  • Support BigQuery datasets, views, policy tags, encryption/decryption, fine-grained access, and data quality validation
  • Coordinate EDM ingestion/egress, APIs, SFTP/SFG/WebTransport, historical data loads, and secure GCP-to-vendor transfers
  • Coordinate approvals and policy enablement with Data Governance and Privacy teams
  • Work with Data pipelines, Kafka/GCS streams, and secure data movement

Security Risk & Compliance (SRA/SRO)

  • Coordinate SRA/SRO intake and reassessments for all GCP projects
  • Collect and organize cloud, IAM, network, encryption, logging, vulnerability, and application-control evidence for Archer submissions
  • Address rejected evidence, track approvals, and ensure production-readiness compliance
  • Liaise with Security Risk team on project build phase compliance gates

Snyk, Wiz & Cloud Vulnerability Remediation

  • Review and triage Snyk Open Source, Wiz, GitHub Advanced Security, and cloud-security findings across all GCP and Azure projects
  • Identify application and repository owners; drive remediation, rescans, and false-positive reviews
  • Collect closure evidence and maintain Snyk project attribution accuracy within the GitHub org
  • Enforce secure handling of credentials, PII/PHI, service-account keys, and internal endpoints
  • Submit and track DevSecOps Ecosystem requests for vulnerability review and reporting scope corrections

Technical Project Status, Risk & Dependency Coordination

  • Track Key DevOps milestones for projects e.g. Jira ticket, RAID items, security dependencies, environment readiness, and external blockers
  • Provide leadership updates on delivery status, risks, and technical blockers

BAU DevOps & Cross-Team Engineering Support

  • Provide continuous daily support for GCP deployments, SSO, IAM, networking, Data Portal, application access, and production incidents
  • Conduct technical working sessions and onboard developers to platform tooling and processes
  • Coordinate across Teams, Security, Network, Data Governance, and application teams to resolve cross-functional dependencies
  • Mentor junior engineers and enforce DevOps and security best practices across the team

Required Qualifications

  • 8+ years of experience in DevOps, platform, or SRE roles in enterprise environments
  • 5+ years hands-on experience with GCP (GKE, Cloud Build, Cloud Run, Cloud SQL, BigQuery, GCS, Composer, Dataproc, Secret Manager, IAM, VPC)
  • 5+ years designing and managing CI/CD pipelines using GitHub Actions, Jenkins, or GitLab CI
  • 3+ years managing infrastructure as code with Terraform across multi-environment GCP deployments
  • Hands-on experience with ArgoCD or equivalent GitOps tooling for Kubernetes-based deployments
  • Proficiency in Workload Identity Federation (WIF) and GCP service account management
  • Experience configuring Ping Identity SAML/OIDC SSO integrations in enterprise environments
  • Hands-on experience with Snyk Open Source and/or Wiz for vulnerability management and remediation
  • Experience managing GCP IAM, AD groups, fine-grained BigQuery permissions, and Secret Manager
  • Strong proficiency in Python and Bash scripting for automation and infrastructure tooling
  • Experience with Kubernetes (GKE), Docker, and container-native deployment patterns
  • Proficiency in Prometheus, Grafana, and GCP-native monitoring and logging tools
  • Experience with VPC Service Controls, VPN, firewall rules, and DNS in GCP environments
  • Familiarity with BigQuery data governance including policy tags, encryption, and fine-grained access controls
  • Experience with secure file transfer protocols (SFTP, SFG, WebTransport) and data pipelines
  • Experience with ServiceNow RITM/REQ workflows for infrastructure and access request management
  • Familiarity with GRC process for evidence collection and submission

Preferred Qualifications

  • GCP Professional DevOps Engineer or equivalent cloud certification (AWS, Azure)
  • Experience operating within large-scale GitHub organizations including repo permissions and Snyk project attribution
  • Familiarity with Azure environments in addition to GCP
  • Experience in healthcare, insurance, or regulated industry environments (HIPAA, SOX compliance awareness)
  • Experience with Agile ceremonies — sprint planning, standups, retrospectives
  • Experience with Cloud Composer (Airflow), or Dataproc in production environments
  • Strong verbal and written communication skills; ability to engage effectively with technical and non-technical stakeholders
  • Comfortable navigating ambiguous ownership situations across large, matrixed organizations
  • Ability to manage multiple concurrent projects and priorities in a fast-paced enterprise environment
  • Strong cross-functional collaboration skills — able to coordinate across Security, EDP, Network, Data Governance, and application teams simultaneously
  • Experience liaising with third-party vendors and system owners for external system integrations

Education

  • Bachelor's degree preferred/specialized training/relevant professional qualification.

Pay Range

The typical pay range for this role is:

Applying takes you straight to CVS Health's own posting — no middlemen, no reposts.

Apply at CVS Health

Similar roles