TELECOMMUTE Sr. Google Cloud Platform Security Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+24 more
Job description
Looking for a Senior Google Cloud Platform Security Engineer who lives on Google Cloud Platform and can own the security architecture end-to-end, not just advise on it. You will design guardrails, write Terraform, integrate with Harness CI/CD pipelines, and partner with engineering teams to ensure every resource deployed is secure by default. This role is Google Cloud Platform-first. Familiarity with AWS and Azure is a plus, but your day-to-day will be deep in Google Cloud: securing GKE workloads, governing AI pipelines on Vertex AI, managing identities via ICAM, and using native Google Cloud Platform security services to detect and respond to threats.
Requirements
- 5+ years of experience in cloud security, with the majority focused on Google Cloud Platform environments.
- Deep hands-on experience with Google Cloud Platform security services including IAM, VPC Service Controls, Cloud Armor, KMS, Secret Manager, DLP, and SCC.
- Strong Elastic SIEM experience including log ingestion, detection engineering, alert management, and threat correlation.
- Production-level Terraform experience including module development, infrastructure automation, and state management.
- Experience integrating security controls into CI/CD pipelines using Harness or equivalent platforms.
- Strong knowledge of Kubernetes and GKE security including pod security admission, network policies, Workload Identity, and Binary Authorization.
- Hands-on experience with ICAM or enterprise identity platforms governing non-human identities and workload access.
- Practical knowledge of AI/ML security including Vertex AI workload protection, LLM API governance, and training data security., * Google Professional Cloud Security Engineer or Professional Cloud Architect certification.
- Experience with policy-as-code tooling such as OPA/Rego, Sentinel, or Checkov.
- Familiarity with AWS security services including IAM, GuardDuty, SCPs, and multi-cloud security architectures.
- Experience with Cribl Stream or similar log routing technologies integrated with Elasticsearch.
- Understanding of compliance-driven security requirements including NY DFS 23 NYCRR 500, NAIC, NIST CSF, CIS Benchmarks, and ISO 27001.
- Working knowledge of enterprise identity platforms including SailPoint, CyberArk, Ping Identity, Active Directory, and LDAP.
- Experience securing AI agent frameworks such as LangChain or Vertex AI Agent Builder.
Primary Technology Stack:
- Google Cloud Platform: Vertex AI, GKE, Cloud Armor, KMS, SCC, DLP, Secret Manager, Certificate Manager, BigQuery, Cloud Run
- Infrastructure as Code: Terraform (required), Harness CI/CD, ICAM
- Identity: Google Cloud Platform Workload Identity Federation, service account governance, ICAM, SailPoint, CyberArk, Ping Identity, Active Directory, LDAP
- AI/ML: Vertex AI Agent Builder, Gemini APIs, BigQuery ML, RAG pipelines
- Secondary: AWS (IAM, GuardDuty, Bedrock), Azure (familiarity acceptable)
- Observability: Elastic SIEM (primary), SCC, Cribl Stream, Elasticsearch
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 138 - Are you secure about this?
Dev Digest 120 - Apple and peers
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
Dev Digest 134 - Where pixels sing?