Job Summary
Seeking an experienced GCP Platform Compliance and Security Consultant to embed security and compliance guardrails into GCP platform rollouts. The ideal candidate will help ensure secure-by-default onboarding, audit readiness, effective risk management, and consistent implementation of cloud security standards.
Key Responsibilities
• Translate security and compliance control requirements into technical guardrails and organizational policies.
• Define GCP security baselines, policy constraints, and platform security standards.
• Establish encryption and key management patterns across GCP environments.
• Define and enforce expectations for secrets management and secure credential handling.
• Establish logging and monitoring requirements aligned with security and compliance needs.
• Define evidence retention standards to support audit readiness.
• Drive exception handling and provide inputs for risk acceptance workflows.
• Track remediation activities and follow up on identified security and compliance gaps.
• Collaborate with cloud, security, engineering, and compliance teams to implement practical security controls.
• Support secure-by-default onboarding practices and reduce recurring compliance gaps.
• Apply a practical delivery mindset by developing implementable standards rather than documentation-only requirements.
Required Qualifications
• 5+ years of experience in cloud security, compliance, information security, or related areas.
• Strong understanding of cloud security fundamentals and security control mapping.
• Experience with GCP security guardrails, including policy constraints, IAM hardening, and logging requirements.
• Experience with GCP cloud platforms and security architecture concepts.
• Proficiency in Python for automation and security-related activities.
• Hands-on experience with Terraform and Infrastructure as Code practices.
• Strong understanding of IAM, encryption, key management, secrets handling, logging, and monitoring.
• Experience with compliance evidence management, audit readiness, and remediation tracking.
• Strong analytical, problem-solving, communication, and stakeholder management skills.
Preferred Qualifications
• Experience with threat modeling.
• Experience integrating vulnerability management processes with cloud security programs.
• Familiarity with incident response practices.
• Experience developing automated security and compliance controls using Python and Terraform.
• Experience working with enterprise cloud governance and risk management frameworks.