Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
At Sonatype, we empower developers with best-in-class tools to build secure, high-quality software at scale. Our mission is to create a world where software is always secure and developers can innovate without fear. Trusted by thousands of organizations, including Fortune 500 companies, we are pioneers in software supply chain management, open-source security, and DevSecOps.
We are looking for a GCP DevOps Engineer to help us shape the future of secure software development. If you love solving complex problems, working with cloud-native platforms, and mentoring engineering teams, we would love to hear from you.
As a GCP DevOps Engineer, you will play a critical role in designing, automating, and scaling Sonatype's engineering platform and delivery systems on GCP. You will lead infrastructure and CI/CD modernization, improve reliability and security, and guide teams on platform engineering and DevOps best practices.
Why This Role Matters
This role helps create the engineering foundation that enables teams to ship securely, reliably, and quickly. You will influence how Sonatype scales its platform capabilities, improves developer experience, and advances its DevSecOps maturity on GCP.
You will work at the intersection of infrastructure, automation, security, and developer enablement, making a direct impact on product velocity and operational excellence.
Key Responsibilities
- Design, implement, and evolve GCP-based infrastructure using Infrastructure as Code with Terraform and Google Cloud deployment automation patterns.
- Build and maintain scalable CI/CD pipelines using Cloud Build, GitHub Actions, Jenkins, or equivalent platforms for application, infrastructure, and platform workloads.
- Administer and optimize GCP delivery workflows including Cloud Build triggers, Artifact Registry, source integrations, deployment approvals, and service account access patterns.
- Partner with engineering teams to improve build, release, and deployment workflows across microservices and cloud-native applications.
- Implement robust observability across systems using Google Cloud Operations Suite, Cloud Logging, Cloud Monitoring, and related telemetry tooling.
- Strengthen platform security by integrating secrets management, policy enforcement, vulnerability scanning, and least-privilege access control.
- Manage and optimize containerized environments using Kubernetes, Helm, and Google Kubernetes Engine (GKE).
- Drive reliability engineering practices including incident response, root cause analysis, SLO thinking, and automated remediation where appropriate.
- Standardize reusable templates, modules, and platform patterns that improve developer productivity and consistency.
- Mentor engineers and provide technical leadership on GCP architecture, deployment automation, release governance, and DevSecOps practices.
What We Are Looking For
- Strong experience in DevOps, platform engineering, or site reliability engineering roles supporting modern software delivery.
- Deep hands-on expertise with Google Cloud Platform, including compute, networking, IAM, storage, monitoring, and security services.
- Strong experience with GCP-native or integrated CI/CD pipeline design for multiple application stacks and deployment patterns.
- Experience with Infrastructure as Code using Terraform, Deployment Manager alternatives, or equivalent automation frameworks.
- Proficiency with containers and orchestration platforms such as Docker and Kubernetes, preferably with GKE experience.
- Experience with scripting and automation using Python, Bash, PowerShell, or similar languages.
- Solid understanding of source control workflows, package management, artifact promotion, and release strategies.
- Experience implementing observability, logging, alerting, and operational dashboards for production systems.
- Strong understanding of cloud security, IAM, secrets management, compliance controls, and secure software delivery practices.
- Excellent collaboration and communication skills, with the ability to influence technical direction across teams.
What Would Be Nice to Have
- Experience with GitHub, SonarQube, Nexus Repository, or software supply chain security tooling.
- Familiarity with multi-cloud environments and migration patterns from AWS or on-premises platforms.
- Exposure to policy-as-code, platform engineering, developer portals, or internal developer platform concepts.
- Experience supporting regulated or enterprise-scale environments with strong governance requirements.
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
More Openings at Sonatype
Explore Top Companies in this Space
Clariticloudinc
Permitting Software
Creative Chaos
Custom Software Development
Censys
Cybersecurity / Attack Surface Management / Threat Intelligence / SaaS
Conga
Software
Sonatype
View Company ProfileSonatype is a pioneering developer security and software supply chain management platform that empowers engineering and DevSecOps teams to automate open-source governance and secure their software development lifecycles. Founded in 2008 by Jason van Zyl—the creator of Apache Maven—and Brian Fox, the company originated from the development of Maven Central, the world's largest repository of Java components. Sonatype leverages deep intelligence and AI-powered automation to analyze open-source software (OSS) dependencies, identifying code vulnerabilities, license compliance risks, and malicious software before deployment. Its core product suite, led by the Nexus Platform—including Nexus Repository, Nexus Lifecycle, and Nexus Firewall—provides end-to-end visibility and continuous enforcement across CI/CD pipelines. Headquartered in Fulton, Maryland, Sonatype serves thousands of global enterprises, including major banks, technology firms, and government agencies, helping them accelerate software delivery without compromising safety or security.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.
