We are seeking an experienced GCP Cloud Security Engineer to embed security and compliance controls into a large-scale Google Cloud rollout. This role will focus on establishing secure-by-default and audit-ready cloud environments by translating security and compliance requirements into practical technical guardrails.
The ideal candidate will have hands-on experience with GCP security, Python, Terraform, IAM, organizational policies, encryption, logging, and compliance controls . This person should be comfortable working across security, cloud infrastructure, engineering, compliance, and application teams.
Key Responsibilities
- Design and implement security and compliance guardrails for GCP environments .
- Translate security, regulatory, and control requirements into practical technical standards and cloud guardrails.
- Define and maintain GCP Organization Policies , policy constraints, and security baselines.
- Establish secure IAM practices, including least-privilege access and identity hardening.
- Define encryption and key management patterns for cloud workloads.
- Establish requirements and standards for secrets management and sensitive information handling .
- Define cloud logging, monitoring, alerting, and evidence-retention requirements.
- Ensure security controls generate appropriate evidence to support internal and external audits.
- Partner with engineering and infrastructure teams to integrate security controls into the GCP onboarding process.
- Develop and maintain security infrastructure and guardrails using Terraform .
- Use Python for automation, validation, reporting, and security-related operational tasks.
- Manage security exceptions and provide inputs into risk acceptance workflows .
- Track remediation activities and follow up on outstanding security and compliance gaps.
- Identify opportunities to reduce onboarding rework by establishing repeatable and standardized security patterns.
- Collaborate with security, compliance, cloud engineering, and application teams to ensure security requirements are practical and implementable.
Required Qualifications
- 5+ years of experience in cloud security, cybersecurity, infrastructure security, or related disciplines.
- Strong hands-on experience with Google Cloud Platform (GCP) security .
- Strong understanding of cloud security fundamentals and security control mapping.
- Experience implementing or defining GCP security guardrails .
- Strong understanding of:
- Policy constraints
- Logging and monitoring requirements
- Security baselines
- Experience translating compliance and security requirements into technical controls .
- Experience with Terraform and Infrastructure as Code.
- Experience with Python for automation or security tooling.
- Understanding of encryption and cloud key management concepts.
- Experience defining or implementing secrets management practices.
- Strong understanding of security evidence collection, documentation, and audit readiness.
- Experience with security exception management, risk tracking, and remediation processes.Ability to develop implementable security standards , rather than documentation-only policies.
Nice-to-Have Skills
- Threat modeling experience.
- Vulnerability management integration.
- Experience with cloud security posture management.
- Experience integrating security controls into CI/CD or DevSecOps processes.
- Familiarity with enterprise compliance frameworks and control libraries.
- Experience supporting large-scale cloud migration or GCP rollout programs.
Success Measures
- Reduction in security and compliance control gaps.
- Faster response to internal and external audit requests.
- Increased adoption of standardized security guardrails.
- Faster remediation of identified vulnerabilities and control deficiencies.
- Consistent implementation of secure-by-default GCP environments