GCP Cloud Engineer

Insight Global

Saint Paul (MN)

On-site

USD 140,000 - 180,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Insight Global is seeking an experienced GCP Cloud Engineer to join a Security Green Team. You will translate vulnerability findings into automated remediation embedded into cloud builds, codifying fixes as infrastructure as code and enforcing guardrails through policy-as-code.

This hands-on role shapes cloud security as it scales. Responsibilities include hardening CI/CD pipelines, coordinating patching, and preparing environments for container/Kubernetes workloads while maintaining security

Qualifications

  • 5–10 years of hands-on cloud engineering with GCP.
  • Experience hardening GCP to CIS Benchmarks.
  • Policy-as-code and guardrails across cloud environments.
  • Strong CI/CD and pipeline automation.
  • Advanced IaC using Terraform.
  • Proficiency in Python and Bash for automation.
  • Kubernetes and container security.
  • CSPM and vulnerability tooling experience.

Responsibilities

  • Assess the current GCP and cloud environment to identify gaps.
  • Validate guardrails meet CIS benchmarks and policy requirements.
  • Design and implement policy enforcement across GCP via policy-as-code.
  • Codify fixes as Infrastructure as Code (Terraform) to prevent reoccurrence.
  • Build and harden CI/CD pipelines with dev teams.
  • Prepare environment for upcoming container/Kubernetes workloads.
  • Coordinate server patching and lifecycle management.
  • Maintain dashboards on security posture and remediation velocity.

Skills

GCP
CIS Benchmarks
Policy as Code
CI/CD Pipelines
Terraform
Python
Bash
Kubernetes
Automation
Cloud Security
Vulnerability Scanning

Tools

Terraform
Ansible
Kubernetes
Security Command Center
Tenable
Qualys
Wiz
Prisma Cloud

Job description

Job Description

Insight Global is seeking an experienced GCP Cloud Engineer to serve as a core member of a Security Green Team – the function responsible for translating vulnerability and misconfiguration findings into durable, automated remediation that is embedded into how cloud infrastructure is built and maintained. Moving beyond a reactive, manual approach to patching, this individual will own the configuration remediation pipeline for the Google Cloud estate: codifying fixes as infrastructure as code, automating patch and image lifecycle management, hardening cloud baselines against CIS benchmarks, and enforcing policies and guardrails through policy-as-code. This is a hands-on engineering position in which architects establish strategic direction and the engineer executes against it. As the organization's Google Cloud footprint continues to mature, the successful candidate should anticipate a significant volume of foundational hardening work.

Key Responsibilities:
  • Assess the current GCP and broader cloud environment to identify hardening and configuration gaps.

  • Validate that guardrails are in place and meet CIS benchmarks.

  • Design and implement policy enforcement and guardrails across GCP via policy-as-code and continuous compliance scanning.

  • Codify fixes and standards as Infrastructure as Code (Terraform) so misconfigurations do not reappear downstream.

  • Build and harden CI/CD pipelines with development teams, integrating security and policy gates.

  • Prepare the environment for forthcoming container and Kubernetes workloads as the Kubernetes platform team engages.

  • Coordinate server patching and lifecycle management with the platform and Linux teams.

  • Maintain dashboards and reporting on security posture, remediation velocity, and cloud risk.

We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.

Skills and Requirements
  • 5-10 years of hands-on cloud engineering, with deep expertise in Google Cloud Platform (GCP).

  • Proven experience hardening cloud environments to CIS Benchmarks for GCP.

  • Track record establishing policies and guardrails across a hyperscaler (org policies, policy-as-code, continuous compliance).

  • Strong CI/CD command, building and hardening pipelines in partnership with development teams.

  • Advanced automation and Infrastructure as Code, primarily Terraform.

  • GCP OS patch management, coordinating server patching with the platform team.

  • GCP identity and security services: IAM, VPC/firewall, KMS/Secret Manager, logging and monitoring.

  • Proficiency in Python and Bash for automation and reporting. - Ansible for configuration management and patch orchestration

  • Hyperscaler certifications (AWS, Google Cloud, and/or Azure).

  • HashiCorp Terraform Associate or equivalent IaC certification.

  • CSPM and vulnerability tooling (Security Command Center, Security Hub, Wiz, Prisma Cloud, Tenable, or Qualys).

  • Container and image scanning (Trivy, Aqua, Artifact Registry / ECR) and Kubernetes hardening.

  • Knowledge of the security "color wheel" model and Green / Purple Team frameworks.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AWS Cloud Engineer
AWS Cloud Engineer

Insight Global • Saint Paul (MN)

On-site
USD 120,000 - 170,000
GCP Cloud Security Engineer
GCP Cloud Security Engineer

Insight Global • Reston (VA)

On-site
USD 120,000 - 180,000
Security Engineer
Security Engineer

KPG99 INC • New York (NY)

On-site
USD 150,000 - 230,000
Senior GCP Security Engineer
Senior GCP Security Engineer

Madison-Davis, LLC • New York (NY)

On-site
USD 180,000 - 240,000
Senior Security Engineer
Senior Security Engineer

twentysix • El Segundo (CA)

On-site
USD 120,000 - 180,000
GCP Architect
GCP Architect

Compunnel, Inc. • Mount Laurel Township (NJ)

On-site
USD 120,000 - 150,000
Cloud Security Engineer - GCP
Cloud Security Engineer - GCP

ExecuSource • Marietta (GA)

Hybrid
USD 115,000 - 155,000
Security Engineer (Google SecOps Technical Credential)
Security Engineer (Google SecOps Technical Credential)

Infinite Ranges • United States

Remote
USD 100,000 - 140,000
Staff Cloud Security Engineer
Staff Cloud Security Engineer

ninjatrader • Chicago (IL)

On-site
USD 180,000 - 240,000
Devops Cloud Security Engineer
Devops Cloud Security Engineer

Tata Consultancy Services • Louisville (KY)

On-site
USD 90,000 - 130,000
Annual Incentive
Medical Coverage
Parental Leave
+5