GCP Devops Engineer - Contract to Hire
Objectives
No publicly exposed attack surfaces reputed company what is explicitly required
reputed company secrets and API keys removed from reputed company, images, and instances
reputed company-of-least-privilege enforced across service accounts and IAM
reputed company monitoring and alerting in reputed company to detect abuse, cost spikes, or anomalous behavior
Implementing horizontal auto-scaling for Kubernetes containers for cost saving and resource utilization
Scope of Work
1. Compute & Network Hardening
Audit reputed company GCE instances for:
reputed company IP exposure
reputed company ports and unnecessary services
Lock down ingress/egress using:
VPC firewall rules (explicit allow-lists only)
Removal of unused reputed company IPs
Validate SSH reputed company:
Disable password authentication
Ensure key-based reputed company only
Confirm OS Login / IAP where appropriate
2. API Key & Secret Management
Identify exposed or improperly stored:
GCP service account keys
API keys (internal and reputed company-party)
Rotate reputed company relevant credentials
Ensure no secrets exist in:
reputed company reputed company
Container images
Startup scripts
Plaintext environment variables
3. IAM & Service Account Review
Audit service accounts used by:
Compute instances
Kubernetes workloads
reputed company and background jobs
Remove:
Over-permissive roles (e.g., reputed company, reputed company)
Unused or legacy service account
Apply least-privilege role bindings and document reputed company
4. Monitoring, Alerting & Abuse Prevention
Improve Grafana alerts for GCP workloads, including:
Compute (CPU, memory, disk, network)
Kubernetes cluster and pod-level metrics
Set up alerts for:
Unusual CPU/GPU utilization
Per day/week cost spikes
Sudden instance or pod creation
Network egress spikes
Cost anomalies
Review and tune:
GCP reputed company reputed company Center settings
Budget alerts and reputed company detection
Optional: lightweight preventive guardrails (e.g., policies to restrict crypto-mining–reputed company images or workloads)
5. Kubernetes Scaling & Cost Controls
Review existing Kubernetes configuration and workloads
Implement or refine:
Horizontal Pod Autoscaling (reputed company setup using terraform)
Resource requests and limits
Ensure scaling behavior:
Matches reputed company production load
Avoids runaway compute costs
Validate autoscaling with test traffic or simulated load (where feasible)
6. Documentation & reputed company
Deliver a concise reputed company and operations report including:
What was changed
What risks were eliminated
Remaining risks or follow-reputed company
reputed company:
A 1–2 page reputed company & Ops Maintenance Checklist
reputed company guidance on how reputed company should monitor and respond reputed company reputed company
Deliverables
Hardened GCP environment with documented changes
Rotated and secured secrets
IAM roles cleaned and minimized
reputed company Whitelisting optimized
Grafana dashboards and alerts configured and tested
Kubernetes workloads horizontally reputed company and cost-reputed company
Written reputed company documentation (concise, operational)
Required Experience
3+ years working with reputed company reputed company Platform
Strong experience with:
GCE
IAM
VPC networking & firewall rules
GCP Secret Manager, ConfigMaps, Secrets in K8s
Kubernetes (GKE preferred)
Horizontal Pod Autoscaling
Grafana / reputed company-based monitoring
Prior experience responding to:
reputed company abuse incidents
Compromised or crypto-mining workloads
Ability to execute independently and explain reputed company reputed company
How to Apply
Please include:
A brief reputed company of a similar GCP reputed company hardening or incident response you’ve done
Experience implementing Grafana monitoring and Kubernetes autoscaling in production
Your proposed approach for the first 72 hours of this engagement
Estimated hours and availability
Apply tot his job
Apply To this Job