> Markdown version of [/jobs/ext/2007315-google-professional-cloud-security-engineer](https://www.wearedevelopers.com/jobs/ext/2007315-google-professional-cloud-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Google Professional Cloud Security Engineer - **Company:** Snyk Limited - **Location:** United States - **Experience:** Expert - **Salary:** $170,000.0 - $205,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Artificial Intelligence, Amazon Web Services, Audit Trail, Cloud Computing, Cloud Computing Security, Cyber Security, Computer Networks, Continuous Integration, Data Control, Information Leak Prevention, Identity and Access Management, Information Systems Security Architecture Professional, Python (Programming Language), Key Management, Network Segmentation, Open Source Technology, Role-Based Access Control, Phishing, Security Information and Event Management, Data Logging, Google Cloud, Large Language Models, Multi-Agent Systems, Software Security, Multi-Cloud, Amazon Virtual Private Cloud (VPC), AI Platforms, Information Technology, Terraform, Ddos, Devsecops - **Published:** August 9, 2026 - **Apply:** https://www.dice.com/job-detail/d614472f-a4fc-4fae-b391-060c6e272348 ## About the Role * 8+ years in security engineering, including at least 4 focused specifically on securing cloud environments at production scale. * Expert level AWS security and strong working knowledge of Google Cloud Platform. You can reason about IAM policy evaluation, organization level guardrails, network and VPC design, key management and encryption, and logging architecture without reaching for the documentation. * Deep, hands-on cloud IAM expertise. Designing least privilege models across multi-account and multi-project estates, right-sizing over-permissioned roles without breaking production, and managing non-human identities, workload identity federation, and secrets at scale. * An attacker's understanding of cloud. You know how cloud environments actually get compromised (credential and token abuse, IAM privilege escalation chains, metadata and workload identity abuse, exposed storage and services, CI/CD and supply chain paths) and you design controls against those paths rather than against a checklist. * Real ownership of an enterprise CSPM or CNAPP platform. Onboarding accounts, tuning signal to noise, building remediation workflows, and holding the line on posture metrics over time. * Infrastructure as code and genuine coding ability. Terraform, Python or Go. * Kubernetes security in the cloud. RBAC, service accounts and token handling, admission control, workload identity, network policy, and container runtime posture. * Practical experience applying AI to engineering work. You have built something real with LLM APIs or agent frameworks, and you understand AI specific risk (prompt injection, over-permissioned agents and tools, untrusted tool and MCP servers, data leakage) well enough to design controls for it. * Enterprise identity platform security. Hands-on with a major IdP: policy design, federation, phishing resistant authentication, privileged access, and access review. * Cloud detection fundamentals. Cloud provider audit logs and native threat detection services, what good cloud detection logic looks like, and how cloud telemetry lands and gets queried in a SIEM. * Strong written communication and stakeholder influence. * Bachelor's degree in computer science, information security, or information technology, or equivalent practical experience. We'd be Lucky if You * Have worked in the DevSecOps, cloud security, or AI industry, or have defended a security product company. * Have built agentic security tooling, MCP servers, or internal AI platforms, and have well formed opinions about where they should and should not be trusted. * Have done cloud incident response or cloud threat hunting on a real intrusion. * Have contributed to open source cloud security tooling, or published research on cloud attack techniques. * Have led a cloud migration or a multi-cloud consolidation and lived with the security consequences. * Have worked in a FedRAMP, NIST 800-53, or similar regulated cloud environment. * Hold relevant security certifications. None are required, but they are welcomed. Examples include: + CISSP (Certified Information Systems Security Professional) + CCSP (Certified Cloud Security Professional) + SANS / GIAC: GPCS (Public Cloud Security), GCLD (Cloud Security Essentials), GCSA (Cloud Security Automation), GCFR (Cloud Forensics Responder), GDSA (Defensible Security Architecture), Google Cloud PlatformN (Cloud Penetration Tester) ## Description * Building AI and agentic automation for security work. Using LLMs and agents to automate posture remediation, access reviews, cloud evidence gathering, and investigation enrichment. Turning repeatable expert judgment into tooling the whole team can run. * Securing Snyk's AI adoption. Establishing the controls for internal AI and agent use: permissions and blast radius for autonomous agents, tool and MCP server trust, third party AI risk review, and the identity and data boundaries AI systems operate within. * Securing the cloud infrastructure behind Snyk's AI capabilities. IAM, network segmentation, and data controls for the accounts, model workloads, and pipelines that power our AI features. * Strengthening cloud detection and response. Making sure cloud control plane and workload telemetry produces detections that fire on real attacker behaviour, and acting as the cloud subject matter expert during incidents. * Defending the edge. WAF and DDoS posture, plus cloud deception coverage that catches an intruder early. * Partnering across teams. Working with Platform and Infrastructure Engineering, Product Security, and Compliance to land controls through influence rather than mandate. This includes supporting the cloud controls in our public sector environment, which is a smaller part of the role. * Raising the team's cloud ceiling. Mentoring engineers, acting as an escalation point for complex cloud investigations, and taking part in the EntSec on-call rotation. ## Related Videos - [WeAreDevelopers LIVE - Chrome for Sale? Comet - the upcoming perplexity browser Stealing and leaking](https://www.wearedevelopers.com/videos/1331-wearedevelopers-live-chrome-for-sale-comet-the-upcoming-perplexity-browser-stealing-and-leaking) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)