This is a hands-on engineering position focused on implementing cloud security controls, managing identity and access, investigating security incidents, remediating vulnerabilities and misconfigurations, and strengthening the overall security posture of Google Cloud Platform environments.
-
Implement, configure, and manage security controls across enterprise Google Cloud Platform (Google Cloud Platform) environments.
-
Secure Google Cloud Platform services including IAM, service accounts, workload identity, networking, logging, monitoring, encryption, and security policies.
-
Implement and maintain least-privilege access, RBAC, service-account governance, workload identity, and privileged-access controls.
-
Monitor Google Cloud Platform environments for security threats, suspicious activities, vulnerabilities, and configuration issues.
-
Perform end-to-end Incident Response, including investigation, triage, containment, remediation, root-cause analysis, and post-incident activities.
-
Analyze cloud security logs, alerts, and telemetry to identify and investigate potential security incidents.
-
Identify and remediate cloud vulnerabilities, security misconfigurations, excessive permissions, and security-control gaps.
-
Work with Google Security Command Center, Cloud Logging, Cloud Monitoring, and Organization Policies.
-
Implement security controls for VPCs, firewall policies, private connectivity, network segmentation, and workload protection.
-
Conduct cloud security assessments, configuration reviews, threat analysis, and remediation activities.
-
Collaborate with Cloud, DevOps, Infrastructure, Application, and Security Operations teams.
-
Support security automation and integration of cloud security controls into engineering and operational processes.
-
Participate in security investigations and provide technical recommendations to prevent recurrence.
-
Support enterprise identity and privileged-access integrations using technologies such as Okta and CyberArk.
-
8+ years of overall IT/Security experience, with strong recent experience in Cloud Security Engineering.
-
Strong hands-on experience securing Google Cloud Platform (Google Cloud Platform) environments.
-
Deep understanding of Google Cloud Platform IAM, service accounts, workload identity, Organization Policies, Security Command Center, Cloud Logging, and Cloud Monitoring.
-
Hands-on cloud network security experience including VPCs, firewall rules/policies, private connectivity, and network segmentation.
-
Strong hands-on Incident Response experience within cloud or enterprise environments.
-
Experience investigating security alerts, analyzing logs, determining root causes, and implementing remediation.
-
Strong understanding of IAM, least privilege, RBAC, federation, privileged access, encryption, and secrets management.
-
Experience identifying and remediating cloud security vulnerabilities and misconfigurations.
-
Understanding of Zero Trust and cloud security architecture principles.
-
Ability to collaborate with technical teams during security incidents and drive issues through resolution.
-
Hands-on Okta experience including SSO, MFA, federation, SAML/OIDC, identity integrations, and user lifecycle management.
-
Experience with CyberArk for Privileged Access Management (PAM), credential vaulting, privileged-account management, and access controls.
-
Experience with SIEM/SOAR platforms and security monitoring.
-
Experience with Terraform / Infrastructure-as-Code (IaC) and cloud security automation.
-
Scripting experience using Python, PowerShell, Bash, or similar technologies.
-
Experience securing Kubernetes/GKE environments.
-
Knowledge of security standards and frameworks such as NIST, CIS Benchmarks, SOC 2, and ISO 27001.
-
Relevant certifications in Google Cloud Platform, Cloud Security, CISSP, CyberArk, or Okta.