Senior Networking DevOps Engineer
Indexed description
The role covers GCP Cloud Armor policy management, DNS and firewall configuration, Ingress NGINX tuning, and abuse prevention — ensuring the service stays available and well-protected for a large developer community.
The work combines proactive hardening (automating Cloud Armor rules, cleaning up redundant network configurations) with reactive investigation (diagnosing rate-limit issues, tracing client IPs in proxy logs), with all changes validated on a test cluster before being applied to production.
To discover more about Cloud practice at EPAM Georgia, visit this page.
Experience the freedom of remote work from anywhere in Georgia, whether from the comfort of your home, our modern offices in Tbilisi and Batumi or a coworking space in Kutaisi.
Responsibilities
- Assess, configure, and automate GCP Cloud Armor security policies for the platform
- Investigate and tune GCP rate-based ban rules to avoid impacting legitimate CI/CD traffic
- Audit and remove redundant DNS zone and firewall configurations across GCP projects
- Diagnose and resolve NGINX Ingress configuration issues — proxy headers, log format, client IP extraction
- Implement monitoring and alerting for abuse patterns using GCP logs and platform APIs
- Modify and maintain Ingress NGINX Helm chart configuration
- Analyse GCP Cloud Logging and Splunk data to identify problematic IPs and traffic patterns
- Validate all network and infrastructure changes on the test cluster before rolling to production
- Document security rules, network configuration decisions, and operational runbooks
- 3+ years of experience in networking and DevOps engineering
- Expertise in GCP Cloud Armor, including WAF rule authoring, rate-based banning, and policy automation
- Proficiency in GCP Cloud Logging, including log query language, HTTP load balancer and L4/L7 proxy log analysis, and log-based alerting
- Background in GCP networking, covering DNS zone management, VPC firewall policies, and firewall rule lifecycle
- Skills in Ingress NGINX configuration via values.yaml and proxy header handling
- Knowledge of Kubernetes and Helm
- Familiarity with Splunk for log queries, field extraction, and correlation
- Competency in GitHub Actions
- Excellent command of written and spoken English (B2+ level)
- Understanding of Terraform or OpenTofu
- Capability to work with GCP Cloud Monitoring and Google Cloud Load Balancing (including HTTP(S) Load Balancer)
- Flexibility to use Bash and jq
- Familiarity with SonarQube and SAST (Static Application Security Testing)
- Background in SecOps
- We connect like-minded people
- Delivering innovative solutions to industry leaders, making a global impact
- Enjoyable working environment, whether it is the vibrant office or the comfort of your own home
- Opportunity to work abroad for up to two months per year
- Relocation opportunities within our offices in 55+ countries
- Corporate and social events
- We invest in your growth
- Leadership development, career advising, soft skills and well-being programs
- Certifications, including GCP, Azure and AWS
- Unlimited access to EPAM's internal learning database
- Free English classes with certified teachers
- We cover it all
- Participation in the Employee Stock Purchase Plan
- Monetary bonuses for engaging in the referral program
- Comprehensive medical & family care package
- Five trust days per year (sick leave without a medical certificate)
- Benefits package (sports activities, a variety of stores and services)
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search