Senior Cloud Security Engineer, GCP

Jobtailor

Greater London

On-site

GBP 90,000 - 130,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Jobtailor seeks a seasoned Cloud Security Engineer to design and maintain secure, scalable GCP infrastructure using Infrastructure as Code. You will own cloud security architecture, identity and access controls, and continuous compliance.

Lead incident response, threat modelling and architecture reviews, and collaborate with Information Security, Infrastructure and Engineering teams to deploy secure, auditable solutions. Strong GCP/Kubernetes security and Terraform skills are essential.

Qualifications

  • Extensive experience in Google Cloud security architecture.
  • Proven track record in GCP landing zone design and governance.
  • Deep knowledge of GCP IAM and its limitations.
  • Experience with IaC tooling, especially Terraform.
  • Strong incident response, risk assessment and threat modelling skills.
  • Familiarity with PCI DSS, NIST, SOC 2, ISO 27001 standards.

Responsibilities

  • Define and implement GCP security architecture and IAM controls.
  • Design, document, and maintain secure GCP infrastructure using IaC.
  • Lead incident response and remediation efforts.
  • Assess risks, conduct threat modelling and architecture reviews.
  • Coordinate security with Information Security, Infra and Eng teams.
  • Ensure PCI DSS readiness and ongoing security compliance.

Skills

GCP security
IAM management
Kubernetes security
Threat modelling
Incident response
Security auditing

Education

CISSP
CCSP
CISM
GCP Professional Cloud Security Engineer
AWS Security Specialty

Tools

Terraform
GKE
Cloud KMS
Artifact Registry
Binary Authorization
Security Command Center
VPC Service Controls
Shared VPC
RBAC
Cloud Logging
Monitoring

Job description

  • Help keep infrastructure secure and compliant and staff safe and productive
  • Define Google Cloud security architecture covering cloud identity, runtime security and security posture
  • Design, document, build and maintain secure, scalable GCP infrastructure using Infrastructure as Code
  • Safeguard systems, applications and data through secure access, authentication and authorisation mechanisms
  • Engineer and automate GCP technical controls for continuous compliance with PCI DSS and 3DS
  • Drive security infrastructure deployments across growing environments
  • Perform security assessments, audits, threat modelling and architecture design reviews
  • Identify and triage risks and vulnerabilities, and design corrective security controls
  • Lead incident response, including investigation and remediation of security breaches
  • Support security awareness and training programs
  • Advocate the DevSecOps mindset across technology teams
  • Collaborate with Information Security, Infrastructure and Engine Technology teams
Requirements
  • Mature understanding of cloud security architecture, with deep expertise in GCP and a proven track record
  • Experience creating a GCP landing zone, including organisation policies and VPC Service Controls
  • Deep understanding of GCP IAM and its limitations
  • Experience with service-oriented architecture using containers, distributed systems and immutable infrastructure on GCP, including GKE, Compute Engine, Shared VPC and Cloud SQL
  • Expertise in Kubernetes, securing GKE clusters and meshes; Cilium preferable
  • Networking best practices and RBAC implementation
  • Experience with Infrastructure as Code and provisioning tools, particularly Terraform
  • Experience configuring GCP-native security posture and threat management with Security Command Center
  • Experience securing the software supply chain with Binary Authorization, Artifact Registry and Artifact Analysis
  • Experience with Cloud KMS, Cloud External Key Manager, Secret Manager and cryptographic key ceremonies
  • Experience with Workload Identity and Workload Identity Federation
  • Experience configuring cloud-native security logging, monitoring and detection services
  • Strong programming skills in Python, Go and other languages
  • In-depth knowledge of security principles, technologies, best practices, threat detection and mitigation strategies
  • Knowledge of OWASP Top 10, MITRE ATT&CK Framework and social engineering tactics
  • Ability to identify threats, attack vectors and vulnerabilities
  • Ability to document security requirements
  • Excellent problem-solving, communication and active listening skills
  • Ability to identify security gaps and create risk‑minimising solutions
  • Proactive approach to staying updated with security threats and vulnerabilities
  • Thorough understanding of the incident response process
  • Desirable: network security, TCP/IP, BGP, VPNs, firewalls, WAFs, IDS/IPS and hybrid GCP/on‑premise connectivity
  • Desirable: Assured Workloads and Access Transparency
  • Desirable: NIST, SOC 2, ISO 27001 and PCI DSS experience
  • Desirable: container provenance, Sigstore, Notary, container runtimes and software development lifecycle security
  • Desirable: SAST/DAST and secure code reviews
  • Desirable: cryptography management
  • Desirable: ISC2 CC, CISSP, CCSP, CISM, AWS Security Specialty or GCP Professional Cloud Security Engineer certifications
Core Competencies

Demonstrates expertise in Google Cloud security architecture, including the design and maintenance of secure, scalable GCP infrastructure using Infrastructure as Code. Proficient in incident response, risk assessment, and implementing security controls to ensure compliance with standards such as PCI DSS.

Highest-signal resume keywords
  • Google Cloud Security Architecture
  • Infrastructure as Code
  • GCP IAM Management
  • Kubernetes Security
  • Security Compliance Audits
ATS Optimization Keywords
Hard Skills
  • Python Programming
  • Go Programming
  • Terraform
  • GKE Security
  • Cloud KMS
  • Security Command Center
  • RBAC Implementation
  • Threat Modelling
  • Incident Response
  • VPC Service Controls
Soft Skills
  • Problem-Solving
  • Communication
  • Active Listening
Certifications & Qualifications
  • CISSP
  • CCSP
  • CISM
  • GCP Professional Cloud Security Engineer
  • AWS Security Specialty
Industry Keywords
  • PCI DSS
  • NIST
  • SOC 2
  • ISO 27001
  • OWASP Top 10
  • MITRE ATT&CK Framework
  • Network Security
  • Threat Detection
  • Cryptography Management
  • Container Security
Tools & Technologies
  • GCP
  • Cloud SQL
  • Shared VPC
  • Binary Authorization
  • Artifact Registry
  • Secret Manager
  • Security Logging
  • Monitoring Services
  • IDS/IPS
  • WAFs
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Cloud Security Engineer, GCP
Staff Cloud Security Engineer, GCP

Jobtailor • Greater London

On-site
GBP 90,000 - 140,000
Staff Cloud Security Engineer, GCP
Staff Cloud Security Engineer, GCP

Jobtailor • Greater London

On-site
GBP 90,000 - 140,000
Senior Infrastructure Engineer – GCP
Senior Infrastructure Engineer – GCP

Jobtailor • Greater London

On-site
GBP 110,000 - 150,000
Staff Infrastructure Engineer – GCP
Staff Infrastructure Engineer – GCP

Jobtailor • Greater London

On-site
GBP 90,000 - 130,000
Public Cloud Assistant Infrastructure Engineer
Public Cloud Assistant Infrastructure Engineer

Jobtailor • Leeds

On-site
GBP 42,000 - 68,000
Senior GCP DevSecOps Engineer
Senior GCP DevSecOps Engineer

TESTQ Technologies LTD. • Sheffield

On-site
GBP 75,000 - 110,000
Read more
Read more

Experis • Sheffield

On-site
GBP 80,000 - 110,000
GCP DevSecOps Engineer
GCP DevSecOps Engineer

HCLTech • Sheffield

On-site
GBP 70,000 - 110,000
GCP Cloud Engineer
GCP Cloud Engineer

DELTACLASS TECHNOLOGY SOLUTIONS LIMITED • Leeds

On-site
GBP 70,000 - 90,000
Cyber Security Engineer
Cyber Security Engineer

Jobtailor • Greater London

Hybrid
GBP 70,000 - 110,000