Supporting secure Google Cloud architecture patterns across identity, network, logging/monitoring, and data protection domains (IAM, policies, encryption, boundary controls).
Partnering with the Google Cloud team to implement guardrails and engineering improvements aligned to best practices and compliance needs.
Assisting with SecOps SIEM operations including onboarding log sources, supporting detections, and helping improve investigation workflows.
Producing clear documentation, diagrams, and runbooks that make controls repeatable and auditable.
Assist in implementing and maintaining secure configurations across Google Cloud environments, focusing on least privilege access, resource hierarchy/policies, and workload protection patterns.
Support security design reviews for new/changed cloud services and applications (e.g., networking changes, service accounts, logging requirements).
Help deploy and validate baseline security controls such as encryption, key management practices, and secure network boundary protections (e.g., segmentation and perimeter controls where applicable).
Contribute to Infrastructure-as-Code (IaC) security hygiene by reviewing and improving cloud configurations for repeatability and reduced drift (tooling used by the platform team).
Help operationalize cloud security monitoring by ensuring audit and security telemetry is available and usable for investigations (visibility, alert context, and log quality).
Support vulnerability and configuration findings triage by partnering with engineering teams to validate issues and track remediation progress.
Assist with SIEM data onboarding efforts: coordinate with system owners, validate ingestion, and support normalization/correlation readiness.
Support detection content lifecycle activities such as documentation updates, basic tuning support, and reporting on alert quality (false positives/noise reduction).
Help build repeatable processes for log source onboarding and SIEM content management (runbooks, checklists, dashboards, and metrics).
Partner with SecOps stakeholders to improve investigation workflows and ensure SIEM capabilities are aligned to operational needs (search, context, and investigation views).
Maintain security documentation (control narratives, diagrams, standards) and contribute to “secure-by-default” enablement content for engineering teams.
Coordinate with cloud engineering, Security Architecture, and SecOps teams to plan and execute small-to-medium security initiatives.
Requirements
Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or related field (or equivalent practical experience).
0–3 years of experience in cybersecurity engineering, cloud engineering, security operations, or related technical internships/rotations.
Exposure to at least one cloud platform (Google Cloud preferred) with understanding of core security concepts (IAM, networking, logging/monitoring, encryption).