> Markdown version of [/jobs/ext/2077569-gcp-cloud-security-engineer](https://www.wearedevelopers.com/jobs/ext/2077569-gcp-cloud-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # GCP Cloud Security Engineer - **Company:** Insight Global - **Location:** Fairfax County, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Microsoft Access, Amazon Web Services, Audit Trail, Automation of Tests, BigQuery, Cloud Computing, Cloud Computing Security, DDoS Mitigation, Federated Identity Management, Github, Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), OpenID, Runbook, Security Information and Event Management, Data Logging, Cloud-native Network Functions (CNF), Google Cloud, Software Security, Multi-Cloud, Amazon Virtual Private Cloud (VPC), Containerization, Kubernetes, Cloudflare, Cloud Migration, Firewall Services Module, Terraform, Splunk - **Published:** August 16, 2026 - **Apply:** https://dejobs.org/x/x/4A065A49169D46F6B898C4C800491208/job/ ## About the Role * 5+ years of hands-on experience in Google Cloud Platform (GCP) security engineering * Deep expertise with GCP IAM (service accounts, Workload Identity Federation, organization policies) * Experience implementing and managing VPC Service Controls (VPC-SC) including perimeters, access levels, and egress policies * Proficiency with Cloud Audit Logs, Security Command Center, and Cloud Logging * Hands-on experience with credential management and migration from service account keys to Workload Identity Federation * Strong infrastructure-as-code skills (Terraform or Deployment Manager) * Experience with GCP networking security (VPCs, firewall rules, Private Google Access, Private Service Connect) * Familiarity with organization policy constraints and preventive guardrails * Ability to write automation scripts (Python, Go, or similar) * Experience working in multi-project GCP environments with organizational hierarchy * Strong written and verbal communication skills; ability to produce operational playbooks and runbooks * Familiarity with Kubernetes (GKE) security and AKS audit logging - Google Cloud Professional Cloud Security Engineer certification * Experience enforcing VPC Service Controls in production with documented egress allowlists * Hands-on experience migrating workloads from static service account keys to Workload Identity Federation / OIDC * Familiarity with SIEM integration and detection engineering on GCP (Chronicle, Splunk, or similar) * Experience with GCP data-plane controls (BigQuery, GCS, Secret Manager access restrictions) * Prior work in a staff augmentation or consulting engagement model * Experience in regulated or high-security environments (SOC 2, FedRAMP, or similar) * Familiarity with GitHub OIDC integration for GCP Workload Identity * Experience building reusable security patterns, IaC modules, and migration playbooks for enterprise-wide adoption ## Description We are seeking experienced Cloud Security Engineers to support the implementation of critical cloud security initiatives across AWS and Google Cloud Platform (GCP) environments. This role is highly hands-on and focused on building, deploying, automating, and operationalizing security controls across a large-scale multi-cloud ecosystem. The ideal candidate has deep expertise in cloud-native security, identity and access management, infrastructure-as-code, Kubernetes security, logging and detection engineering, and cloud network security. This is an engineering-focused role requiring practitioners who can implement solutions, write code, automate controls, and partner closely with platform and application teams. Responsibilities Design, implement, and automate cloud security controls across AWS and GCP environments, with a focus on identity security, cloud infrastructure protection, and attack surface reduction. Implement modern authentication and authorization solutions, including IAM, OIDC, workload identity federation, service accounts, and role-based access controls, while leading efforts to eliminate long-lived credentials and adopt short-lived identities. Develop and enforce cloud security guardrails, data perimeter protections, default-deny access models, and security policies that reduce unauthorized access, lateral movement, and data exposure risks across multi-cloud environments. Build infrastructure-as-code and automation solutions to support security deployment, credential management, compliance reporting, monitoring, and policy enforcement at scale. Enable, integrate, and maintain cloud audit logging, monitoring, SIEM pipelines, security detections, and incident response capabilities across AWS, GCP, Kubernetes, GitHub, and related platforms. Develop detections and automated response mechanisms for credential abuse, anomalous activity, unauthorized access attempts, and potential data exfiltration events. Secure Kubernetes and containerized environments by implementing hardened configurations, secure deployment patterns, access controls, and cloud-native security best practices. Design and implement security protections for internet-facing applications and infrastructure, including Cloudflare WAF, DDoS protection, secure ingress patterns, and private-by-default cloud architectures. Identify, assess, and remediate security vulnerabilities, exposed cloud resources, insecure network paths, and application security risks through proactive testing, monitoring, and validation activities. Partner closely with cloud, platform, infrastructure, and application engineering teams to implement security solutions, support cloud migrations, establish operational playbooks, and improve the overall security posture of large-scale cloud environments. We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/. ## Related Videos - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [CI/CD with Github Actions](https://www.wearedevelopers.com/videos/856-ci-cd-with-github-actions) - [Best Practices for Using GitHub Secrets](https://www.wearedevelopers.com/videos/1214-best-practices-for-using-github-secrets) ## Related Articles - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)