> Markdown version of [/jobs/ext/1349608-senior-security-engineer-gcp](https://www.wearedevelopers.com/jobs/ext/1349608-senior-security-engineer-gcp). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Engineer- GCP - **Company:** Dentsply Sirona - **Location:** York, PA, United States - **Experience:** Expert - **Salary:** $130,000.0 - $150,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Cloud Computing Security, Cloud Engineering, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Information Systems, Continuous Integration, Query Languages, Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), Key Management, Network Security, Network Segmentation, Parsing, Performance Tuning, Role-Based Access Control, Security Information and Event Management, Software Vulnerability Management, Data Logging, Scripting, Google Cloud, Cloud Platform System, Data Ingestion, Delivery Pipeline, Information Technology, Terraform, Devsecops, Security Orchestration, Automation & Response - **Published:** July 19, 2026 - **Apply:** https://www.juju.com/job/00000000ghksye ## About the Role + Bachelor's degree (or higher) in Cybersecurity, Computer Science, Information Systems, Engineering, or related field (or equivalent practical experience) Experience + 7+ years of professional experience in cybersecurity, including signifcant hands-on experience in cloud security architecture and engineering + 3+ years securing Google Cloud Platform (GCP) environments across identity, network security, encryption, and logging/monitoring + Hands-on experience administering or engineering detections in a modern SIEM (Google Security Operations/Chronicle preferred; comparable SIEM acceptable) + Proven track record partnering with cloud platform teams and application teams to deliver security improvements through engineering, automation, and standards Key Skills & Knowledge + Strong grounding in cloud security architecture: least privilege, defense-in-depth, secure network design, encryption, and secure delivery practices + Practical knowledge of GCP security capabilities (IAM, org/policy guardrails, security posture management concepts, logging/monitoring, key management/encryption) + Security automation and infrastructure-as-code experience (Terraform or equivalent) and scripting (Python or equivalent) + Detection engineering fundamentals: log onboarding, parsing/normalization, query languages, alert tuning, and dashboarding + Threat modeling, security review, and risk translation into pragmatic engineering requirements + Strong communication and ability to coordinate across multiple technical teams Certifications Preferred (globally recognized) + Google Professional Cloud Security Engineer (highly relevant) + CSSP and/or CISSP + Relevant GIAC certifications aligned to cloud/IR/detection engineering (e.g. incident response/threat detection), or equivalent credentials ## Description The Senior Google Cloud Security Engineer is a senior-level individual contributor within Dentsply Sirona's Security Architecture and Engineering organization. This role partners closely with the Google Cloud Platform (GCP) engineering and operations teams and Security stakeholders to help design, implement, and continuously improve secure-by-default cloud foundations and security controls that enable business delivery while reducing risk. This position leads security architecture and engineering initiatives that strengthen the confidentiality, integrity, availability, and resilience of GCP workloads and data through guardrails, automation, and clear security patterns that scale. In addition, the role owns day-to-day administration and ongoing maturity of the SecOps SIEM (Google Security Operations / Chronicle), including log onboarding, detection engineering, tuning, and operational reporting in partnership with Security Operations and Incident Response. This is a hybrid role that will require you to be based out of our Charlotte, NC or York,PA office. Role Scope Includes: + Defining and implementing secure GCP reference architectures (landing zone, org/policy guardrails, identity, network segmentation, encryption, logging) and reusable security patterns. + Engineering preventive and detective controls using automation and infrastructure-as-code (guardrails, baselines, continuous configuration enforcement). + Coordinating with platform and application teams to integrate security into CI/CD pipelines and deployment workflows (including workload/container security). + Owning SecOps SIEM administration and detection engineering: log onboarding, parsing/normalization, rule development, tuning, dashboards, and alerting. + Driving cloud security risk reduction through security reviews, threat modeling, and remediation of critical findings across GCP services. + Contributing to audit readiness and control evidence for cloud controls (access management, logging, encryption, vulnerability management). Cloud Security Architecture & Engineering + Partner with the Google Cloud team to design secure cloud architectures, including IAM/least privilege, network security, encryption, secrets management, and logging/monitoring standards. + Define and maintain GCP security reference architectures and guardrails aligned to enterprise security policies and industry frameworks (e.g., risk management and control objectives). + Lead threat modeling and architecture risk reviews for new GCP services, platforms, and major migrations; document decisions and required controls/compensations. Security Engineering, Automation & DevSecOps + Engineer scalable security controls using automation and infrastructure-as-code (baseline policies, configuration validation, continuous compliance checks). + Integrate security controls into CI/CD (policy checks, IaC validation, secrets detection, artifact/image scanning) to enable secure delivery with minimal friction. + Develop reusable security modules, patterns, and documentation that drive consistent adoption across teams. SecOps SIEM Ownership (Google Security Operations / Chronicle) + Administer and mature the SecOps SIEM platform: data ingestion, log onboarding, parsing/normalization, content management, and access controls. + Lead detection engineering: build, tune, and maintain high-fidelity detections and analytics based on threat intelligence and observed attacker techniques; reduce false positives through iterative tuning. + Develop dashboards and reporting to support SOC performance, cloud visibility, and executive-level risk insights. + Partner with Incident Response/Threat Hunting/Cloud Engineering to investigate cloud events and improve telemetry and detections. Risk Reduction, Compliance & Continuous Improvement + Drive remediation of critical/high cloud findings by coordinating with owners, validating fixes, and ensuring controls remain effective over time. + Support internal and external audits by producing evidence for cloud control operation (logging, access governance, encryption, vulnerability management, change control). + Contribute to security standards, patterns, and runbooks; participate in lessons learned and resilience readiness improvements. Success Measures (examples) + Increase GCP log coverage in the SIEM (priority log sources onboarded; improved parsing/normalization quality). + Improve detection quality (signal-to-noise ratio through tuning; timely deployment of new detections for emerging threats). + Reduce critical cloud security findings over time through guardrails, automation, and effective remediation partnership. + Improve time-to-visibility for new GCP projects/workloads by delivering reusable secure patterns and automation. Stretch Goal (beyond KPIs) + Deliver a secure-by-default GCP landing zone + standardized security blueprint adopted broadly for new workloads, with measurable reduction in repeat security findings and faster, safer onboarding of new cloud projects. ## Related Videos - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Data Engineer Salary UK](https://www.wearedevelopers.com/magazine/253-data-engineer-salary-uk)