Security Engineering SME (Google Cloud Platform Vulnerability & Compliance)

Remote • Posted 10 hours ago • Updated 6 hours ago
Contract W2
6 Months
No Travel Required
Remote
Depends on Experience
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • GCP
  • security

Summary

Security Engineering SME (Google Cloud Platform Vulnerability & Compliance)

Location: US Remote

Experience Level: Senior (7+ years)

Role Overview

The Lead Security Engineer is the primary technical lead responsible for the end-to-end engineering and automation of the FedRAMP Key Security Indicator (KSI) initiative. This role bridges the gap between regulatory compliance and hands-on cloud engineering. The Lead Engineer will design automated cloud controls, manage Google Cloud Platform security vulnerability pipelines, and guide a technical team in deploying solutions that ensure continuous monitoring and secure architectures across Google Cloud Platform (Google Cloud Platform).

Key Responsibilities

• Technical Leadership & Translation: Lead discovery workshops to deconstruct FedRAMP KSIs and NIST SP 800-53 controls, translating high-level compliance mandates into binary, automatable technical specifications.

• Vulnerability Management & Pipelines: Oversee and implement VM vulnerability scanning (AutoVM, Tenable, Qualys, Nessus), container image scanning (Artifact Registry / Drydock), and static/dynamic analysis tools.

• Automation & Scripting: Analyze Google Cloud Asset Inventory (CAI) schemas and oversee the authoring and testing of Common Expression Language (CEL) evaluation rules to define precise Pass/Fail criteria for cloud controls.

• Pipeline & Telemetry Architecture: Design, deploy, and troubleshoot log agents (Fluentbit/Vector) and Cloud Logging sinks to ensure 100% telemetry coverage across container nodes, VMs, and control-plane APIs.

• Identity & Access Management (IAM): Architect and enforce least-privilege IAM bindings, service accounts, and VPC Service Controls across the Google Cloud Platform environment.

• Validation & Deployment: Test logic against synthetic resources in sandbox environments to minimize false positives, manage codebase version control (Git/Piper), and support progressive deployment rollouts.

• Cross-Functional Collaboration: Act as the technical bridge for the project, supporting gap analyses and providing engineering evidence to Governance teams and 3PAO assessors.

 

Qualifications & Requirements

• Experience: 7+ years in Cloud Security Engineering, DevSecOps, or Infrastructure Security, with proven experience as a Lead/Senior Engineer managing FedRAMP (Moderate/High) security vulnerability implementations.

• Cloud Platform Expertise: Strong, hands-on background in Google Cloud Platform (Google Cloud Platform), specifically with Cloud Asset Inventory (CAI), Security Command Center (SCC), IAM, Cloud Audit Logs, and Cloud Storage.

• Scripting & Languages: Advanced proficiency in Common Expression Language (CEL). Working knowledge of Python, Go, or Rego/OPA.

• Vulnerability Tooling: Practical experience configuring and automating vulnerability and container scanning tools in a large-scale cloud environment.

• Systems & Infrastructure: Experience with Google Cloud infrastructure and container orchestration (Kubernetes/GKE/Borg).

• Compliance Knowledge: Strong familiarity with automated control evaluation for NIST SP 800-53 Rev 5, CIS Benchmarks, and FedRAMP Continuous Monitoring (ConMon).

• Education: Bachelor’s or Master’s degree in Computer Science, Information Technology, Cybersecurity, or equivalent practical experience.

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10118140
  • Position Id: 9097165
  • Posted 10 hours ago
Contact the job poster
Praveen Boddam

Praveen Boddam

RapidIT, Inc Recruiter @ RapidIT, Inc
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Remote

•

Today

Contract, Third Party

$56 - $56

Remote or New Jersey

•

Today

Easy Apply

Third Party, Contract

Remote

•

30+d ago

Easy Apply

Full-time

140,000 - 170,000

Remote

•

24d ago

Full-time

USD 208,000.00 - 312,000.00 per year

Search all similar jobs