We are looking for a Lead Security Cloud Engineer - GCP to design and run secure Google Cloud Platform services that align security needs with business outcomes. You will deliver professional services and technical consulting, guiding secure cloud strategies, automation, and compliant deployments across teams.
Responsibilities
- Implement secure policies and services on Google Cloud Platform
- Assess and reduce security threats using SIEM tools such as Google SecOps and WiZ
- Define security strategy with the CISO and Security Engineers to satisfy governance requirements
- Enforce regulatory controls and support compliance requirements alongside SOC or SecOps teams
- Configure resource hierarchies, set boundary protection, and secure communications through Identity and Access Management (IAM) and Workload Identity Federation (WIF)
- Deploy network security defenses, ensure data protection, and use observability tools for threat detection and management
- Apply AI agents to automate, accelerate, and de-risk complex security and infrastructure deployment tasks
- Enable secure landing zones and data and AI foundations, establishing perimeters for user-to-agent, agent-to-agent, and agent-to-services communication
- Drive security-focused digital transformation using Infrastructure as Code for compliance-driven deployment of security foundations
- Operate secure containerized workloads via Google Kubernetes Engine and secure the software CI/CD and DevSecOps pipelines
- Collaborate with stakeholders to align technical requirements with business objectives
Requirements
- 5+ years of experience implementing secure policies and services, ideally on Google Cloud Platform
- Expertise in security threat analysis and mitigation using SIEM tools such as Google SecOps, WiZ, and similar tools
- Background supporting security strategy definition and partnering with CISOs and Security Engineers on governance requirements
- Experience enforcing regulatory controls and supporting compliance requirements with SOC or SecOps teams
- Deep understanding of Identity and Access Management, resource hierarchies, boundary protection, secure communications, and Workload Identity Federation best practices
- Hands-on proficiency implementing Cloud Firewall, Cloud Armor, and VPC, along with data protection and Security Command Center for threat detection
- Proven ability to leverage AI agents to automate and de-risk security and infrastructure deployment tasks
- Solid expertise in secure landing zones and data and AI foundations for user-to-agent, agent-to-agent, and agent-to-services communication perimeters
- Practical skills with Terraform for compliance-driven security deployments, Google Kubernetes Engine security best practices, and securing CI/CD and DevSecOps pipelines
- Proven track record in Professional Services and Technical Consulting with strong communication, collaboration, and negotiation skills
- English proficiency at B2 (Upper-Intermediate) level or higher
Nice to have
- Google Professional Cloud Security Engineer certification
- Google Professional Cloud Architect certification
- Google Professional Security Operations Engineer certification