Job Summary:
We are seeking a Senior GCP Security Engineer with 5+ years of cloud security experience, primarily focused on Google Cloud Platform. The role will own security architecture and implementation end-to-end, including designing security guardrails, developing Terraform infrastructure, integrating security controls into CI/CD pipelines, and partnering with engineering teams to ensure resources are secure by default. The position requires deep hands-on experience securing GCP environments, GKE workloads, Vertex AI and AI/ML pipelines, enterprise identities, and native GCP security services. Familiarity with AWS and Azure is preferred.
Key Responsibilities:
• Design and implement end-to-end security architecture and guardrails across GCP environments.
• Develop and maintain Terraform modules and infrastructure automation, including state management.
• Integrate security controls into Harness or equivalent CI/CD pipelines.
• Partner with engineering teams to implement secure-by-default cloud resources and architectures.
• Secure GCP services and workloads using IAM, VPC Service Controls, Cloud Armor, KMS, Secret Manager, DLP, and Security Command Center (SCC).
• Secure Kubernetes and GKE environments, including Pod Security Admission, network policies, Workload Identity, and Binary Authorization.
• Govern identities and access for non-human identities and workloads using ICAM and related enterprise identity platforms.
• Implement and maintain security controls for Vertex AI workloads, LLM APIs, training data, and AI/ML pipelines.
• Configure and manage Elastic SIEM for log ingestion, detection engineering, alert management, and threat correlation.
• Integrate security monitoring and controls with SCC, Cribl Stream, Elasticsearch, and other relevant security and observability platforms.
• Identify, investigate, and respond to cloud security threats and incidents.
• Develop and implement policy-as-code controls to enforce security and compliance requirements.
• Collaborate with engineering and technology teams to assess security risks and implement appropriate mitigation strategies.
• Support security architecture and implementation across AI agent frameworks and RAG-based solutions.
Required Qualifications:
• 5+ years of experience in cloud security, with the majority of experience focused on GCP environments.
• Deep hands-on experience with GCP security services, including IAM, VPC Service Controls, Cloud Armor, KMS, Secret Manager, DLP, and SCC.
• Strong experience with Elastic SIEM, including log ingestion, detection engineering, alert management, and threat correlation.
• Production-level Terraform experience, including module development, infrastructure automation, and state management.
• Experience integrating security controls into CI/CD pipelines using Harness or equivalent platforms.
• Strong knowledge of Kubernetes and GKE security, including Pod Security Admission, network policies, Workload Identity, and Binary Authorization.
• Hands-on experience with ICAM or enterprise identity platforms for governing non-human identities and workload access.
• Practical knowledge of AI/ML security, including Vertex AI workload protection, LLM API governance, and training data security.
• Strong understanding of cloud security architecture, identity and access management, threat detection, and security automation.
Preferred Qualifications:
• Google Professional Cloud Security Engineer or Professional Cloud Architect certification.
• Experience with policy-as-code tools such as OPA/Rego, Sentinel, or Checkov.
• Familiarity with AWS security services, including IAM, GuardDuty, and SCPs.
• Experience with multi-cloud security architectures.
• Experience with Cribl Stream or similar log routing technologies integrated with Elasticsearch.
• Understanding of compliance-driven security requirements, including NY DFS 23 NYCRR 500, NAIC, NIST CSF, CIS Benchmarks, and ISO 27001.
• Working knowledge of enterprise identity platforms such as SailPoint, CyberArk, Ping Identity, Active Directory, and LDAP.
• Experience securing AI agent frameworks such as LangChain or Vertex AI Agent Builder.
• Familiarity with Azure security services and environments.
• Experience with GCP services including Vertex AI, BigQuery, Cloud Run, and Certificate Manager.