top of page

Senior DevOps Engineer - Cloud Platform & Security (GCP)

About the Role

Cloud foundation for a multi-brand e-commerce group · full-time · reports to the Development Manager — AI & Technology Transformation


The role


This is a build role, not a ticket queue. Today, parts of the estate still run on legacy self-managed hosting

and single-machine setups; access and security are managed informally; delivery practices vary by

project. You will inherit a documented company — a partner-endorsed technology roadmap, a written

platform architecture, and decision records — and a funded mandate to replace all of that with

infrastructure the company can scale on.


What you will do


Build the governed GCP foundation — project and environment structure, IAM with least privilege,

service accounts, secret management, logging, monitoring and alerting, budgets and cost discipline.

GCP (BigQuery, Cloud Run) is the company cloud; you make it governable.


Migrate production workloads onto company cloud — including the AI agent runtime — off single-

person and single-machine dependencies and legacy self-managed servers, without disrupting the

live daily workflows the team depends on.


Own cloud security — one accurate, current access map (no unknown admins), secrets handling,

audit logging, network posture, backup and disaster recovery with tested restores, and incident-

response basics the team can actually follow.


Build the SDLC end to end — CI/CD on the company’s GitHub organizations, environment strategy

(dev / staging / production), branch and release discipline, automated testing integration with QA,

and AI-assisted code review in the pipeline. The team ships across four Shopify storefronts and

internal services; you give them one disciplined way to do it.


Stand up and operate the AI platform’s infrastructure — the containerized agent runtime, a self-

hosted open-source agent memory service (Docker + PostgreSQL on GCP, with a managed Cloud

SQL path), and, as the platform matures, a model gateway for per-agent cost attribution and

budgets.


Support the data platform’s operations — access, cost, and monitoring posture for the BigQuery

warehouse, alongside the data engineer who owns its content.


Document as you go — infrastructure as code as the primary documentation, plus runbooks the

rest of the team can operate from.


What we are looking for


5+ years in DevOps / platform / infrastructure engineering, with production systems you built and

operated yourself.


Deep GCP experience — this is a must: IAM and access governance, Cloud Run (or equivalent

container platforms), Secret Manager, Cloud Monitoring and Logging, cost management; BigQuery

operations a strong plus.


AWS experience as well — we run on GCP, but we want an engineer fluent in more than one cloud

who chooses tools on merit.


Cloud security depth: least-privilege design, secrets and key management, audit logging, network

security, backup/DR. You treat security as an enabler designed in from day one — not a gate bolted

on later.


SDLC construction from scratch: you have built CI/CD pipelines, environment strategies, and

release processes where none existed — and brought a team along with you.


Infrastructure as code (Terraform or similar) and solid Linux administration — part of the current

estate is hand-managed servers you will be retiring.


Scripting fluency (Python and/or Bash) and comfort with Docker and containerized workloads.


Working proficiency in English. Knowledge of Armenian is a bonus. (The engineering team is

Armenian and Russian speaking. Documentation and company leadership work in English).


A bonus, not a requirement: exposure to LLM/AI platforms or agent infrastructure, e-commerce or

Shopify context, workflow tools (n8n), Looker.


Apply to: marko@apexteamhiring.com

bottom of page