Если вы раньше входили через Google, сбросьте пароль для своей Gmail-почты через кнопку «Забыли пароль?» на экране входа. Затем войдите по email и новому паролю.
Если аккаунта ещё нет, зарегистрируйтесь с Gmail-почтой, после подтверждения почты мы предложим задать пароль.
Что нового
Загружаю обновления...
Что нового
Загружаю обновления...
Работа найдется быстрее с подпискойКандидат найдётся быстрее с подпиской
Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме
описание
EPAM develops enterprise software products, open source solutions, and accelerators. Its internal code quality platform runs on GCP and Kubernetes and serves a large developer community.
задачи
Own the network security layer and ingress configuration of an internal code quality platform running on GCP and Kubernetes;
Assess, configure, and automate GCP Cloud Armor security policies for the platform;
Investigate and tune GCP rate-based ban rules to avoid impacting legitimate CI/CD traffic;
Audit and remove redundant DNS zone and firewall configurations across GCP projects;
Diagnose and resolve NGINX Ingress configuration issues, including proxy headers, log format, and client IP extraction;
Implement monitoring and alerting for abuse patterns using GCP logs and platform APIs;
Modify and maintain Ingress NGINX Helm chart configuration;
Analyse GCP Cloud Logging and Splunk data to identify problematic IPs and traffic patterns;
Validate all network and infrastructure changes on the test cluster before rolling to production;
Document security rules, network configuration decisions, and operational runbooks.
требования
3+ Years of experience in networking and DevOps engineering;
Expertise in GCP Cloud Armor, including WAF rule authoring, rate-based banning, and policy automation;
Proficiency in GCP Cloud Logging, including log query language, HTTP load balancer and L4/L7 proxy log analysis, and log-based alerting;
Background in GCP networking, covering DNS zone management, VPC firewall policies, and firewall rule lifecycle;
Skills in Ingress NGINX configuration via values.yaml and proxy header handling;
Knowledge of Kubernetes and Helm;
Familiarity with Splunk for log queries, field extraction, and correlation;
Competency in GitHub Actions;
Excellent command of written and spoken English (B2+ level);
Nice to have: Understanding of Terraform or OpenTofu, capability to work with GCP Cloud Monitoring and Google Cloud Load Balancing including HTTP(S) Load Balancer, flexibility to use Bash and jq, familiarity with SonarQube and SAST (Static Application Security Testing), background in SecOps.