Job Summary
The Engineer II Premium (Cloud Security Consultant) will focus on assessing the security of GCP-based conversational AI, telephony, API, and backend integration architectures. The role will evaluate data security and privacy controls across cloud and hybrid environments, identify AI-specific and customer data risks, implement security policies and monitoring controls, and provide findings with risk ratings, gaps, and remediation recommendations.
Key Responsibilities
• Assess end-to-end architecture from data security and privacy perspectives.
• Review security controls for GCP Shared VPC, interconnects, service accounts, IAM, and network segmentation.
• Implement Sentinel policies to enforce encryption and data access standards.
• Implement database activity monitoring and blocking rules in GCP.
• Assess AI-specific risks, including prompt and context leakage, model input and output handling, and knowledge store access.
• Produce findings reports containing risk ratings, identified gaps, and remediation recommendations.
• Review data flows across GCP service projects, virtual agents and conversational AI, telephony platforms, API proxies, Datastore, BigQuery, Cloud Storage, and on-premises systems of record.
• Identify and implement controls to prevent customer data exposure.
• Assess and implement controls for PII handling.
• Implement and assess encryption controls for data in transit and at rest.
• Assess secrets and key management, including user and non-human identity authentication.
• Implement and assess database activity logging, monitoring, and auditability.
• Assess and support data retention and deletion controls.
• Conduct threat modeling and architecture risk reviews.
Required Qualifications
• Strong experience in cloud security architecture, preferably with Google Cloud Platform.
• Hands-on experience with GCP IAM, VPC, Shared VPC, Cloud Run, GKE, BigQuery, Cloud Storage, Datastore/Firestore, Cloud KMS, and Secret Manager.
• Experience assessing data protection controls for PII, PCI, or regulated customer data.
• Knowledge of API security, including OAuth, mTLS, token handling, gateways, and service-to-service authentication.
• Familiarity with network security, private connectivity, firewalls, segmentation, and hybrid cloud interconnects.
• Understanding of logging, SIEM integration, audit trails, and security monitoring.
• Experience with threat modeling and architecture risk assessments.
Preferred Qualifications
• Experience with conversational AI and virtual agent platforms.
• Knowledge of telephony/SIP integrations and contact center platforms.
• Experience with PCI DSS, NIST, ISO 27001, SOC 2, or financial services security standards.
• Familiarity with AI data governance, model safety, and Generative AI security risks.