> Markdown version of [/jobs/ext/172798-senior-associate-senior-ai-platform-security-engineer](https://www.wearedevelopers.com/jobs/ext/172798-senior-associate-senior-ai-platform-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Associate - Senior AI Platform Security Engineer - **Company:** New York, Inc. - **Location:** New York, NY, United States - **Experience:** Expert - **Salary:** $124,000.0 - $177,000.0 - **Contract:** Permanent contract - **Skills:** Training Data, Active Directory, Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Audit Trail, Microsoft Azure, BigQuery, Cloud Computing, Cloud Computing Security, Cyber Security, Computer Networks, Continuous Integration, Data Governance, Data Retention, Elasticsearch, Identity and Access Management, Intrusion Detection and Prevention, Lightweight Directory Access Protocols (LDAP), Network Segmentation, Ping (Networking Utility), Kusto Query Language, Search Technologies, Security Information and Event Management, Systems Integration, Software Vulnerability Management, Policy as Code, Google Cloud, Software Modules, Data Ingestion, Cyberark, Large Language Models, Multi-Cloud, Amazon Virtual Private Cloud (VPC), Containerization, AI Platforms, Kubernetes, Infrastructure Automation Frameworks, Machine Learning Operations, Virtual Agents, CIS Benchmarks, SailPoint, Terraform, Virtual Private Clouds, Service Stack - **Published:** May 22, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=e60c5181689227fe ## About the Role Do you have experience in Virtual Private Clouds?, * 5+ years of experience in cloud security, with the majority focused on GCP environments. * Deep hands-on experience with GCP security services including IAM, VPC Service Controls, Cloud Armor, KMS, Secret Manager, DLP, and SCC. * Strong Elastic SIEM experience including log ingestion, detection engineering, alert management, and threat correlation. * Production-level Terraform experience including module development, infrastructure automation, and state management. * Experience integrating security controls into CI/CD pipelines using Harness or equivalent platforms. * Strong knowledge of Kubernetes and GKE security including pod security admission, network policies, Workload Identity, and Binary Authorization. * Hands-on experience with ICAM or enterprise identity platforms governing non-human identities and workload access. * Practical knowledge of AI/ML security including Vertex AI workload protection, LLM API governance, and training data security., * Google Professional Cloud Security Engineer or Professional Cloud Architect certification. * Experience with policy-as-code tooling such as OPA/Rego, Sentinel, or Checkov. * Familiarity with AWS security services including IAM, GuardDuty, SCPs, and multi-cloud security architectures. * Experience with Cribl Stream or similar log routing technologies integrated with Elasticsearch. * Understanding of compliance-driven security requirements including NY DFS 23 NYCRR 500, NAIC, NIST CSF, CIS Benchmarks, and ISO 27001. * Working knowledge of enterprise identity platforms including SailPoint, CyberArk, Ping Identity, Active Directory, and LDAP. * Experience securing AI agent frameworks such as LangChain or Vertex AI Agent Builder. Primary Technology Stack: * GCP: Vertex AI, GKE, Cloud Armor, KMS, SCC, DLP, Secret Manager, Certificate Manager, BigQuery, Cloud Run * Infrastructure as Code: Terraform (required), Harness CI/CD, ICAM * Identity: GCP Workload Identity Federation, service account governance, ICAM, SailPoint, CyberArk, Ping Identity, Active Directory, LDAP * AI/ML: Vertex AI Agent Builder, Gemini APIs, BigQuery ML, RAG pipelines * Secondary: AWS (IAM, GuardDuty, Bedrock), Azure (familiarity acceptable) * Observability: Elastic SIEM (primary), SCC, Cribl Stream, Elasticsearch ## Description We are looking for a Senior AI Platform Security Engineer who lives on GCP and can own the security architecture end-to-end, not just advise on it. You will design guardrails, write Terraform, integrate with Harness CI/CD pipelines, and partner with engineering teams to ensure every resource deployed is secure by default. This role is GCP-first. Familiarity with AWS and Azure is a plus, but your day-to-day will be deep in Google Cloud: securing GKE workloads, governing AI pipelines on Vertex AI, managing identities via ICAM, and using native GCP security services to detect and respond to threats., * Own the deployment and configuration of GCP-native security services including Cloud Armor, Certificate Manager, Cloud KMS, Secret Manager, and Cloud DLP integrated with Elastic SIEM for centralized detection and response. * Build and maintain detective controls, custom EQL/KQL threat detection rules, and alerting pipelines within Elastic SIEM using GCP log sources ingested through Beats or Elastic Agent. * Define and enforce organization-wide Security Command Center (SCC) findings policies, remediation workflows, and SLA management processes., * Develop scalable reference architectures and security blueprints for IAM, network segmentation, and data protection across GCP projects. * Write and maintain production-grade Terraform modules implementing security controls as code. * Integrate Terraform workflows into Harness CI/CD pipelines using ICAM-governed service accounts and workload identity controls. * Partner with engineering teams to operationalize security architecture decisions into implemented controls and standards., * Define and implement policy-as-code guardrails using OPA, Sentinel, Checkov, or equivalent tooling. * Integrate security gates into CI/CD pipelines including secrets scanning, pre-deployment policy validation, and post-deployment drift detection. * Enforce least-privilege service account policies and workload identity federation across all deployment stages., * Establish GKE security standards including pod security admission, network policies, Workload Identity, Binary Authorization, and container image scanning. * Define requirements for admission controllers, runtime protection tooling, and Kubernetes hardening standards. * Own vulnerability management processes for containerized environments, including CVE tracking and remediation coordination., * Use AI-enabled CSPM tooling to analyze security telemetry, identify systemic risks, and automate remediation guidance. * Embed security controls into AI/ML workflows including audit logging, data governance, and model output monitoring. * Automate detection and response playbooks using Elastic SIEM case management and SOAR tooling., * Enable and secure Google AI services including Vertex AI pipelines, Gemini APIs, and BigQuery ML workloads. * Design scalable architectures for LLM-based applications including RAG pipelines, vector search, grounding strategies, and orchestration frameworks. * Establish secure patterns for AI agents, memory and state management, session isolation, and data retention controls. * Implement monitoring and guardrails for AI systems in production including prompt injection protection, output filtering, and anomaly detection. ## Related Videos - [Shipping Faster with Less: Render on Cloud Hosting, AI Workloads, and the Future of DevOps](https://www.wearedevelopers.com/videos/1894-shipping-faster-with-less-render-on-cloud-hosting-ai-workloads-and-the-future-of-devops) - [Data Science in Retail](https://www.wearedevelopers.com/videos/586-data-science-in-retail) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Making Data Warehouses fast. A developer's story.](https://www.wearedevelopers.com/videos/302-making-data-warehouses-fast-a-developer-s-story) - [Implementing Feature Environments with AWS and Terraform](https://www.wearedevelopers.com/videos/531-implementing-feature-environments-with-aws-and-terraform) - [The Private AI Platform: Why Agentic Apps Need a Private Application Platform](https://www.wearedevelopers.com/videos/100162-the-private-ai-platform-why-agentic-apps-need-a-private-application-platform) ## Related Articles - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)