- Collaborate with stakeholders to define Google Cloud security architecture covering cloud identity, runtime security and security posture
- Design, document, build and maintain secure, scalable GCP infrastructure using Infrastructure as Code
- Safeguard systems, applications and data through secure access, authentication and authorisation mechanisms
- Engineer and automate GCP technical controls for continuous compliance with PCI DSS and 3DS
- Drive security infrastructure deployments across growing environments
- Perform security assessments, audits, threat modelling and architecture design reviews
- Identify and triage risks and vulnerabilities, recommend improvements and design corrective controls
- Lead incident response, including investigation and remediation of security breaches
- Support internal security awareness and training programs
- Advocate the DevSecOps mindset across technology teams
- Work closely with Information Security, Infrastructure, Security Engineering, cross-cutting, compliance and Engine Technology teams
- Take ownership of the security foundations of the Google Cloud Platform environment as the subject matter expert
Requirements
- Mature understanding of cloud security architecture, with deep expertise in GCP and a proven track record
- Experience creating a GCP landing zone, including organisation policies and VPC Service Controls
- Deep understanding of GCP IAM and its limitations
- Experience with service-oriented architecture using containers, distributed systems and immutable infrastructure on GCP, including GKE, Compute Engine, Shared VPC and Cloud SQL
- Expertise in Kubernetes, securing GKE clusters and meshes; Cilium is preferable
- Knowledge of networking best practices and RBAC implementation
- Experience with Infrastructure as Code and provisioning tools, particularly Terraform
- Experience configuring GCP-native security posture and threat management with Security Command Center
- Experience securing the software supply chain with Binary Authorization, Artifact Registry and Artifact Analysis
- Experience with Cloud KMS, Cloud External Key Manager (EKM) and Secret Manager, including cryptographic key ceremonies
- Experience with Workload Identity and Workload Identity Federation for keyless workload and CI/CD authentication
- Experience configuring and using cloud-native security logging, monitoring and detection services
- Strong programming skills in Python, Go and other languages
- In-depth knowledge of security principles, technologies, best practices, threat detection and mitigation strategies
- Knowledge of OWASP Top 10, MITRE ATT&CK Framework and social engineering tactics
- Ability to identify threats, attack vectors and vulnerabilities in systems and applications
- Ability to document security requirements from stakeholders
- Excellent problem-solving, communication and active listening skills
- Ability to identify security gaps and create risk-minimising solutions
- Proactive approach to staying updated with security threats, vulnerabilities and mitigation techniques
- Thorough understanding of incident response processes
- Desirable: network security, TCP/IP, BGP, VPNs, firewalls, WAFs, IDS/IPS and hybrid GCP/on-premise connectivity
- Desirable: data-residency and regulated-workload controls such as Assured Workloads and Access Transparency
- Desirable: NIST, SOC 2, ISO 27001 and PCI DSS experience
- Desirable: container image provenance, container runtimes and software development lifecycle security
- Desirable: secure code reviews and SAST/DAST tools
- Desirable: cryptography management
- Relevant security certifications are desirable, including ISC2 CC, CISSP, CCSP, CISM, AWS Security Specialty or GCP Professional Cloud Security Engineer
- CKA and CKS qualifications are a plus
- The posting states aptitude and attitude are valued over specific qualifications; no minimum educational credential is required
Core Competencies
Demonstrates expertise in Google Cloud security architecture, including the design and implementation of secure, scalable infrastructure using Infrastructure as Code. Proficient in risk assessment, incident response, and compliance with security standards such as PCI DSS.
Highest-signal resume keywords
- Google Cloud Platform (GCP) Security Architecture
- Infrastructure as Code (Terraform)
- Kubernetes Security (GKE)
- Security Compliance (PCI DSS, NIST)
- Incident Response Management
ATS Optimization Keywords
Hard Skills
- Cloud Security Architecture
- GCP IAM
- Service-Oriented Architecture
- Threat Modelling
- Security Logging and Monitoring
- Python Programming
- Go Programming
- RBAC Implementation
- Cloud KMS
- Binary Authorization
Soft Skills
- Problem-Solving
- Communication
- Active Listening
- Proactive Approach
- Collaboration
Certifications & Qualifications
- CISSP
- CCSP
- CISM
- GCP Professional Cloud Security Engineer
- CKA
- CKS
Industry Keywords
- PCI DSS
- OWASP Top 10
- MITRE ATT&CK Framework
- SOC 2
- ISO 27001
- Network Security
- Hybrid GCP Connectivity
- Data Residency Controls
- Secure Code Reviews
- Cryptography Management
Tools & Technologies
- Terraform
- Security Command Center
- Cloud External Key Manager (EKM)
- Secret Manager
- Workload Identity Federation