Our client is strengthening its cloud‑security posture as part of a wider digital‑transformation programme across regulated financial services. As a Cloud Security Engineer, you will design, implement and maintain secure cloud environments, primarily on Google Cloud Platform, ensuring compliance with internal security standards, European regulations and German supervisory requirements.
You will work closely with platform engineering, IAM, compliance, and risk teams to ensure cloud workloads remain secure, resilient and auditable.
Key Responsibilities
- Cloud Security Architecture — contribute to secure design patterns, guardrails and reference architectures for GCP workloads.
- IAM Engineering — implement least‑privilege access, identity federation, service accounts, workload identity and role governance.
- Security Command Center — configure SCC, manage findings, integrate with SIEM and drive remediation.
- Terraform Security — build secure IaC modules, enforce policy-as-code (OPA/Sentinel), and ensure consistent deployment of security controls.
- Kubernetes/GKE Security — secure clusters, workloads, network policies, admission controllers and runtime protection.
- Implement VPC Service Controls, private service access, secure networking patterns and segmentation.
- Integrate cloud telemetry into the institution’s SIEM and threat‑detection tooling.
- Support CSPM/CNAPP tooling and continuous posture management.
- Conduct threat modelling, security reviews and risk assessments for new cloud workloads.
- Work with compliance teams to ensure alignment with GDPR/DSGVO, BSI C5, NIS2, and internal financial‑sector security frameworks.
- Drive automation of security controls, remediation workflows and compliance reporting.
Required Skills & Experience
- 4–8 years in cloud security engineering.
- Strong hands‑on experience with GCP security services, IAM, SCC, VPC SC, KMS, Cloud Armor, Secret Manager.
- Proficiency with Terraform, CI/CD pipelines and secure IaC patterns.
- Solid understanding of Kubernetes/GKE security, container hardening and runtime protection.
- Experience integrating cloud logs and findings into SIEM platforms (Splunk, Chronicle, QRadar, etc.).
- Familiarity with Zero Trust principles and implementation in cloud environments.
- Strong understanding of European and German regulatory requirements for cloud workloads (GDPR/DSGVO, BSI C5, NIS2, KRITIS).
- Ability to work with cross‑functional teams (risk, compliance, platform, architecture).
- Fluency in English; German language skills are beneficial but not mandatory.
Nice to Have
- Experience with multi‑cloud security (AWS/Azure) in regulated environments.
- Knowledge of financial‑sector frameworks (BAIT, MaRisk, EBA guidelines).
- Exposure to Sovereign Cloud concepts or regulated cloud landing zones.
- Certifications: GCP Professional Cloud Security Engineer, CISSP, CCSP, CISM, Terraform Associate.