Staff Cloud Security Engineer, GCP

Jobtailor

Greater London

On-site

GBP 90,000 - 140,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Jobtailor seeks a highly skilled Google Cloud security architect to own the security foundations of GCP environments in a mature cloud setup.

You will collaborate with stakeholders to define secure architectures, build scalable IaC-backed infrastructure, and drive continuous security across growing environments while leading incident response and threat modelling.

Qualifications

  • Deep expertise in Google Cloud security architecture.
  • Experience with GCP IAM and its limitations.
  • Strong coding skills in Python and Go.

Responsibilities

  • Collaborate with stakeholders to define Google Cloud security architecture.
  • Design, document, build and maintain secure GCP infrastructure using IaC.
  • Lead incident response and remediation of security breaches.
  • Drive security deployments across growing environments.
  • Engage in threat modelling, audits and architecture reviews.

Job description

  • Collaborate with stakeholders to define Google Cloud security architecture covering cloud identity, runtime security and security posture
  • Design, document, build and maintain secure, scalable GCP infrastructure using Infrastructure as Code
  • Safeguard systems, applications and data through secure access, authentication and authorisation mechanisms
  • Engineer and automate GCP technical controls for continuous compliance with PCI DSS and 3DS
  • Drive security infrastructure deployments across growing environments
  • Perform security assessments, audits, threat modelling and architecture design reviews
  • Identify and triage risks and vulnerabilities, recommend improvements and design corrective controls
  • Lead incident response, including investigation and remediation of security breaches
  • Support internal security awareness and training programs
  • Advocate the DevSecOps mindset across technology teams
  • Work closely with Information Security, Infrastructure, Security Engineering, cross-cutting, compliance and Engine Technology teams
  • Take ownership of the security foundations of the Google Cloud Platform environment as the subject matter expert
Requirements
  • Mature understanding of cloud security architecture, with deep expertise in GCP and a proven track record
  • Experience creating a GCP landing zone, including organisation policies and VPC Service Controls
  • Deep understanding of GCP IAM and its limitations
  • Experience with service-oriented architecture using containers, distributed systems and immutable infrastructure on GCP, including GKE, Compute Engine, Shared VPC and Cloud SQL
  • Expertise in Kubernetes, securing GKE clusters and meshes; Cilium is preferable
  • Knowledge of networking best practices and RBAC implementation
  • Experience with Infrastructure as Code and provisioning tools, particularly Terraform
  • Experience configuring GCP-native security posture and threat management with Security Command Center
  • Experience securing the software supply chain with Binary Authorization, Artifact Registry and Artifact Analysis
  • Experience with Cloud KMS, Cloud External Key Manager (EKM) and Secret Manager, including cryptographic key ceremonies
  • Experience with Workload Identity and Workload Identity Federation for keyless workload and CI/CD authentication
  • Experience configuring and using cloud-native security logging, monitoring and detection services
  • Strong programming skills in Python, Go and other languages
  • In-depth knowledge of security principles, technologies, best practices, threat detection and mitigation strategies
  • Knowledge of OWASP Top 10, MITRE ATT&CK Framework and social engineering tactics
  • Ability to identify threats, attack vectors and vulnerabilities in systems and applications
  • Ability to document security requirements from stakeholders
  • Excellent problem-solving, communication and active listening skills
  • Ability to identify security gaps and create risk-minimising solutions
  • Proactive approach to staying updated with security threats, vulnerabilities and mitigation techniques
  • Thorough understanding of incident response processes
  • Desirable: network security, TCP/IP, BGP, VPNs, firewalls, WAFs, IDS/IPS and hybrid GCP/on-premise connectivity
  • Desirable: data-residency and regulated-workload controls such as Assured Workloads and Access Transparency
  • Desirable: NIST, SOC 2, ISO 27001 and PCI DSS experience
  • Desirable: container image provenance, container runtimes and software development lifecycle security
  • Desirable: secure code reviews and SAST/DAST tools
  • Desirable: cryptography management
  • Relevant security certifications are desirable, including ISC2 CC, CISSP, CCSP, CISM, AWS Security Specialty or GCP Professional Cloud Security Engineer
  • CKA and CKS qualifications are a plus
  • The posting states aptitude and attitude are valued over specific qualifications; no minimum educational credential is required
Core Competencies

Demonstrates expertise in Google Cloud security architecture, including the design and implementation of secure, scalable infrastructure using Infrastructure as Code. Proficient in risk assessment, incident response, and compliance with security standards such as PCI DSS.

Highest-signal resume keywords
  • Google Cloud Platform (GCP) Security Architecture
  • Infrastructure as Code (Terraform)
  • Kubernetes Security (GKE)
  • Security Compliance (PCI DSS, NIST)
  • Incident Response Management
ATS Optimization Keywords
Hard Skills
  • Cloud Security Architecture
  • GCP IAM
  • Service-Oriented Architecture
  • Threat Modelling
  • Security Logging and Monitoring
  • Python Programming
  • Go Programming
  • RBAC Implementation
  • Cloud KMS
  • Binary Authorization
Soft Skills
  • Problem-Solving
  • Communication
  • Active Listening
  • Proactive Approach
  • Collaboration
Certifications & Qualifications
  • CISSP
  • CCSP
  • CISM
  • GCP Professional Cloud Security Engineer
  • CKA
  • CKS
Industry Keywords
  • PCI DSS
  • OWASP Top 10
  • MITRE ATT&CK Framework
  • SOC 2
  • ISO 27001
  • Network Security
  • Hybrid GCP Connectivity
  • Data Residency Controls
  • Secure Code Reviews
  • Cryptography Management
Tools & Technologies
  • Terraform
  • Security Command Center
  • Cloud External Key Manager (EKM)
  • Secret Manager
  • Workload Identity Federation
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cloud Security Engineer, GCP
Senior Cloud Security Engineer, GCP

Jobtailor • Greater London

On-site
GBP 90,000 - 130,000
Staff Infrastructure Engineer – GCP
Staff Infrastructure Engineer – GCP

Jobtailor • Greater London

On-site
GBP 90,000 - 130,000
Senior Infrastructure Engineer – GCP
Senior Infrastructure Engineer – GCP

Jobtailor • Greater London

On-site
GBP 110,000 - 150,000
Senior GCP DevSecOps Engineer
Senior GCP DevSecOps Engineer

TESTQ Technologies LTD. • Sheffield

On-site
GBP 75,000 - 110,000
Read more
Read more

Experis • Sheffield

On-site
GBP 80,000 - 110,000
Public Cloud Assistant Infrastructure Engineer
Public Cloud Assistant Infrastructure Engineer

Jobtailor • Leeds

On-site
GBP 42,000 - 68,000
GCP DevSecOps Engineer
GCP DevSecOps Engineer

HCLTech • Sheffield

On-site
GBP 70,000 - 110,000
GCP Cloud Engineer
GCP Cloud Engineer

DELTACLASS TECHNOLOGY SOLUTIONS LIMITED • Leeds

On-site
GBP 70,000 - 90,000
Senior Cloud Security Engineer (SecOps)
Senior Cloud Security Engineer (SecOps)

bynd • Manchester

On-site
GBP 90,000 - 120,000
Competitive base salary
Pension scheme
Discretionary bonus
+1
Senior Security Engineer (GCP)
Senior Security Engineer (GCP)

Bynd Limited • Manchester

Hybrid
GBP 70,000 - 90,000
Competitive base salary
Private medical insurance
Flexible working hours
+1