CVS Health logo

Senior DevSecOps Engineer

CVS Health

Galway, IRL
Full-time
Salary not listedPosted 10m ago

Real job — pulled straight from CVS Health’s careers page · Verified August 21, 2026 · No reposts.

Job description

CVS Health is hiring a Senior DevSecOps Engineer — a full-time, based in Galway, IRL role. Apply directly on CVS Health's careers page below.

Senior DevSecOps Engineer

Location: IRL - Galway

Remote Type: Hybrid

Time Type: Full time

Job Description

We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time.

Position Summary
We are seeking an experienced Sr. DevSecOps Engineer to support a large-scale, GCP-native and Azure-connected enterprise environment. The engineer will perform hands on work setting up CI/CD pipelines, GCP infrastructure provisioning, IAM and SSO management, DevSecOps compliance, observability, data integration, and production operations — collaborating daily with Security, EDP, Network, Data Governance, and application engineering teams across all GCP and Azure projects under the organization.

Key Responsibilities

GCP Infrastructure & GKE Provisioning

  • Provision and manage GCP projects, GKE namespaces and clusters, Cloud SQL, BigQuery, GCS, Cloud Composer, Dataproc, and Secret Manager

  • Configure Workload Identity Federation (WIF) and environment-specific resources across Dev, PDEV, QA, and Production

  • Validate environment readiness and coordinate PRIME and EDP provisioning requests

  • Manage infrastructure as code using Terraform; enforce IaC best practices across all environments

IAM, Service Accounts, SSO & Access Management

  • Create and manage GCP service accounts, AD groups, WIF bindings, token-creator roles, Secret Manager, Cloud SQL, and BigQuery permissions

  • Configure Ping SAML/OIDC integrations including client IDs/secrets, redirect URLs, certificates, and environment-specific SSO settings

  • Validate AD-group restrictions and login flows; coordinate access requests with application and SSO teams

  • Manage fine-grained IAM permissions aligned with least-privilege and compliance requirements

Infrastructure Troubleshooting & Production Readiness

  • Resolve issues across VPC Service Controls, Zscaler, VPN, firewall, DNS, signed URLs, Composer, Dataproc, Cloud SQL, Secret Manager, and GKE

  • Perform environment health checks, remove deployment blockers, and stabilize applications before go-live

  • Provide Tier 2/3 production support including incident triage, root cause analysis (RCA), and post-incident documentation

  • Coordinate with multiple teams across Network/VPC and Cloud teams to resolve infrastructure dependencies

CI/CD, ArgoCD & Release Enablement

  • Build, maintain, and optimize GitHub Actions workflows for application and infrastructure delivery

  • Configure ArgoCD, environment variables, and secrets; implement WIF-based deployment patterns

  • Promote common artifacts across environments; troubleshoot pipeline and ArgoCD authentication failures

  • Coordinate PR approvals and production releases; enforce branching and deployment gate standards

  • Support platform/library release management and versioning aligned with Agile delivery cadences

Observability, Monitoring & Cost Management

  • Develop Grafana and GCP-native dashboards; integrate Prometheus and infrastructure metrics

  • Configure monitoring scopes, define logging and alerting standards, and establish SLO requirements

  • Investigate missing telemetry and ensure full observability coverage across all environments

  • Enable BigQuery billing exports and project-level cost visibility; support cost optimization initiatives

Data Integration, Governance & Secure File Transfer

  • Support BigQuery datasets, views, policy tags, encryption/decryption, fine-grained access, and data quality validation

  • Coordinate EDM ingestion/egress, APIs, SFTP/SFG/WebTransport, historical data loads, and secure GCP-to-vendor transfers

  • Coordinate approvals and policy enablement with Data Governance and Privacy teams

  • Work with Data pipelines, Kafka/GCS streams, and secure data movement

Security Risk & Compliance (SRA/SRO)

  • Coordinate SRA/SRO intake and reassessments for all GCP projects

  • Collect and organize cloud, IAM, network, encryption, logging, vulnerability, and application-control evidence for Archer submissions

  • Address rejected evidence, track approvals, and ensure production-readiness compliance

  • Liaise with Security Risk team on project build phase compliance gates

Snyk, Wiz & Cloud Vulnerability Remediation

  • Review and triage Snyk Open Source, Wiz, GitHub Advanced Security, and cloud-security findings across all GCP and Azure projects

  • Identify application and repository owners; drive remediation, rescans, and false-positive reviews

  • Collect closure evidence and maintain Snyk project attribution accuracy within the GitHub org

  • Enforce secure handling of credentials, PII/PHI, service-account keys, and internal endpoints

  • Submit and track DevSecOps Ecosystem requests for vulnerability review and reporting scope corrections

Technical Project Status, Risk & Dependency Coordination

  • Track Key DevOps milestones for projects e.g. Jira ticket, RAID items, security dependencies, environment readiness, and external blockers

  • Provide leadership updates on delivery status, risks, and technical blockers

BAU DevOps & Cross-Team Engineering Support

  • Provide continuous daily support for GCP deployments, SSO, IAM, networking, Data Portal, application access, and production incidents

  • Conduct technical working sessions and onboard developers to platform tooling and processes

  • Coordinate across Teams, Security, Network, Data Governance, and application teams to resolve cross-functional dependencies

  • Mentor junior engineers and enforce DevOps and security best practices across the team


Required Qualifications

  • 8+ years of experience in DevOps, platform, or SRE roles in enterprise environments

  • 5+ years hands-on experience with GCP (GKE, Cloud Build, Cloud Run, Cloud SQL, BigQuery, GCS, Composer, Dataproc, Secret Manager, IAM, VPC)

  • 5+ years designing and managing CI/CD pipelines using GitHub Actions, Jenkins, or GitLab CI

  • 3+ years managing infrastructure as code with Terraform across multi-environment GCP deployments

  • Hands-on experience with ArgoCD or equivalent GitOps tooling for Kubernetes-based deployments

  • Proficiency in Workload Identity Federation (WIF) and GCP service account management

  • Experience configuring Ping Identity SAML/OIDC SSO integrations in enterprise environments

  • Hands-on experience with Snyk Open Source and/or Wiz for vulnerability management and remediation

  • Experience managing GCP IAM, AD groups, fine-grained BigQuery permissions, and Secret Manager

  • Strong proficiency in Python and Bash scripting for automation and infrastructure tooling

  • Experience with Kubernetes (GKE), Docker, and container-native deployment patterns

  • Proficiency in Prometheus, Grafana, and GCP-native monitoring and logging tools

  • Experience with VPC Service Controls, VPN, firewall rules, and DNS in GCP environments

  • Familiarity with BigQuery data governance including policy tags, encryption, and fine-grained access controls

  • Experience with secure file transfer protocols (SFTP, SFG, WebTransport) and data pipelines

  • Experience with RITM/REQ workflows for infrastructure and access request management

  • Familiarity with GRC process for evidence collection and submission



Preferred Qualifications

  • GCP Professional DevOps Engineer or equivalent cloud certification (AWS, Azure)

  • Experience operating within large-scale GitHub organizations including repo permissions and Snyk project attribution

  • Familiarity with Azure environments in addition to GCP

  • Experience in healthcare, insurance, or regulated industry environments (HIPAA, SOX compliance awareness)

  • Experience with Agile ceremonies — sprint planning, standups, retrospectives

  • Experience with Cloud Composer (Airflow), or Dataproc in production environments

  • Strong verbal and written communication skills; ability to engage effectively with technical and non-technical stakeholders

  • Comfortable navigating ambiguous ownership situations across large, matrixed organizations

  • Ability to manage multiple concurrent projects and priorities in a fast-paced enterprise environment

  • Strong cross-functional collaboration skills — able to coordinate across Security, EDP, Network, Data Governance, and application teams simultaneously

  • Experience liaising with third-party vendors and system owners for external system integrations


Education

  • Bachelor's degree preferred/specialized training/relevant professional qualification.

Pay Range

The typical pay range for this role is:

€50,000.00 - €125,000.00

We anticipate the application window for this opening will close on: 30/09/2026

Get Senior DevSecOps Engineer jobs like this

New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.

Email me new jobs
Flexport logo

Senior Software Engineer, Customs

Amsterdam, Netherlands
✓ From careers page· just now
Flexport logo

Senior Software Engineer, Applied AI

Amsterdam, Netherlands
✓ From careers page· just now
CVS Health logo

Senior Software Development Engineer

IRL - Galway
✓ From careers page· 9m ago
Morgan Stanley logo

Senior Security Architect Specialist

Montreal, QC
✓ From careers page· 12m ago

Frequently asked questions

How do I apply for Senior DevSecOps Engineer at CVS Health?

You can view the full description and apply for Senior DevSecOps Engineer at CVS Health on EchoJobs: https://echojobs.io/job/cvs-health-senior-devsecops-engineer-7dy4e.