Skip To Main Content
backBack to Search

Senior Network DevOps Engineer

Remote in Latvia, Republic of Lithuania
DevOps& 13 others
hot
Looking for something else?

Find a vacancy that works for you. Send us your CV to receive a personalized offer.

Find me a job

We are looking for a Senior Network DevOps Engineer to own the network security layer and ingress configuration of SAP's internal SonarQube platform, running on GCP and Kubernetes. This role covers GCP Cloud Armor policy management, DNS and firewall configuration, Ingress NGINX tuning, and abuse prevention, ensuring the service remains available and well-protected for thousands of developers across SAP. The work combines proactive hardening, such as automating Cloud Armor rules and cleaning up redundant network configurations, with reactive investigation, including diagnosing rate-limit false positives and tracing missing client IPs in proxy logs. All changes are validated on a test cluster before being applied to production.

Responsibilities
  • Assess, configure, and automate GCP Cloud Armor security policies for the SonarQube platform
  • Investigate and tune GCP rate-based ban rules to prevent false positives affecting legitimate CI/CD traffic
  • Audit and remove redundant DNS zone and firewall configurations across GCP projects
  • Diagnose and resolve NGINX Ingress configuration issues, including proxy headers, log format, and client IP extraction
  • Implement monitoring and alerting for abuse patterns using GCP logs and the SonarQube API
  • Modify and maintain Ingress NGINX Helm chart configuration
  • Analyze GCP Cloud Logging and Splunk data to identify problematic IPs and traffic patterns
  • Validate all network and infrastructure changes on the test cluster before deploying to production
  • Document security rules, network configuration decisions, and operational runbooks
Requirements
  • 5+ years of experience in network engineering, DevOps, or cloud infrastructure roles
  • Expertise in GCP, including Cloud Armor, WAF rule authoring, rate-based banning, and policy automation
  • Proficiency in GCP Cloud Logging, covering log query language, HTTP load balancer, and L4/L7 proxy log analysis
  • Knowledge of GCP networking, including DNS zone management, VPC firewall policies, and firewall rule lifecycle
  • Familiarity with Ingress NGINX configuration via values.yaml and proxy header handling
  • Skills in Kubernetes and Helm
  • Competency in Splunk, including log queries, field extraction, and correlation
  • Proficiency in English at a B2+ level
Nice to have
  • Familiarity with Terraform or OpenTofu
  • Knowledge of GCP Cloud Monitoring
  • Skills in Bash and jq
  • Understanding of GCP HTTP(S) Load Balancer