TELECOMMUTE Sr. Google Cloud Platform Security Engineer

StevenDouglas
United States
7 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Training Data Active Directory Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Microsoft Azure BigQuery Cloud Computing Cloud Computing Security Cyber Security Computer Networks Continuous Integration
+24 more
Elasticsearch Federated Identity Management Identity and Access Management Intrusion Detection and Prevention Lightweight Directory Access Protocols (LDAP) Ping (Networking Utility) Security Information and Event Management Systems Integration Policy as Code Google Cloud Software Modules Data Ingestion Cyberark Large Language Models Multi-Cloud Amazon Virtual Private Cloud (VPC) Kubernetes Infrastructure Automation Frameworks Machine Learning Operations Virtual Agents CIS Benchmarks SailPoint Terraform Service Stack

Job description

Looking for a Senior Google Cloud Platform Security Engineer who lives on Google Cloud Platform and can own the security architecture end-to-end, not just advise on it. You will design guardrails, write Terraform, integrate with Harness CI/CD pipelines, and partner with engineering teams to ensure every resource deployed is secure by default. This role is Google Cloud Platform-first. Familiarity with AWS and Azure is a plus, but your day-to-day will be deep in Google Cloud: securing GKE workloads, governing AI pipelines on Vertex AI, managing identities via ICAM, and using native Google Cloud Platform security services to detect and respond to threats.

Requirements

  • 5+ years of experience in cloud security, with the majority focused on Google Cloud Platform environments.
  • Deep hands-on experience with Google Cloud Platform security services including IAM, VPC Service Controls, Cloud Armor, KMS, Secret Manager, DLP, and SCC.
  • Strong Elastic SIEM experience including log ingestion, detection engineering, alert management, and threat correlation.
  • Production-level Terraform experience including module development, infrastructure automation, and state management.
  • Experience integrating security controls into CI/CD pipelines using Harness or equivalent platforms.
  • Strong knowledge of Kubernetes and GKE security including pod security admission, network policies, Workload Identity, and Binary Authorization.
  • Hands-on experience with ICAM or enterprise identity platforms governing non-human identities and workload access.
  • Practical knowledge of AI/ML security including Vertex AI workload protection, LLM API governance, and training data security., * Google Professional Cloud Security Engineer or Professional Cloud Architect certification.
  • Experience with policy-as-code tooling such as OPA/Rego, Sentinel, or Checkov.
  • Familiarity with AWS security services including IAM, GuardDuty, SCPs, and multi-cloud security architectures.
  • Experience with Cribl Stream or similar log routing technologies integrated with Elasticsearch.
  • Understanding of compliance-driven security requirements including NY DFS 23 NYCRR 500, NAIC, NIST CSF, CIS Benchmarks, and ISO 27001.
  • Working knowledge of enterprise identity platforms including SailPoint, CyberArk, Ping Identity, Active Directory, and LDAP.
  • Experience securing AI agent frameworks such as LangChain or Vertex AI Agent Builder.

Primary Technology Stack:

  • Google Cloud Platform: Vertex AI, GKE, Cloud Armor, KMS, SCC, DLP, Secret Manager, Certificate Manager, BigQuery, Cloud Run
  • Infrastructure as Code: Terraform (required), Harness CI/CD, ICAM
  • Identity: Google Cloud Platform Workload Identity Federation, service account governance, ICAM, SailPoint, CyberArk, Ping Identity, Active Directory, LDAP
  • AI/ML: Vertex AI Agent Builder, Gemini APIs, BigQuery ML, RAG pipelines
  • Secondary: AWS (IAM, GuardDuty, Bedrock), Azure (familiarity acceptable)
  • Observability: Elastic SIEM (primary), SCC, Cribl Stream, Elasticsearch

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

2:30 min

Leveraging BigQuery ML for scalable SQL-based segmentation experiments

Julian Joseph · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:32 min

Overview of Terraform and Terraform Cloud features

Devlin Duldulao · LIVE

3:27 min

Explaining query execution overhead and caching limitations in BigQuery

Adnan Rahic · JS Congress

Videos

See all

Related articles

See all