GCP Network Security Engineer (Zero-Trust)

Tapestry

Mountain View, San Francisco, Austin, New York (CA, CA, TX, NY)

Hybrid

USD 174,000 - 255,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Competitive salary and equity
Medical, dental, and vision coverage
Generous PTO and flexible hybrid work

Job summary

Tapestry is seeking a Network Security Engineer to own the design, implementation, and operation of perimeter and cloud networks across GCP environments. You will secure inter-application connectivity, enforce security controls, and audit networks while collaborating with cross-functional teams on secure design patterns.

You will contribute to a scalable security program with Terraform, Cloud Armor, and VPC-SC, aiming to prevent public access and protect critical infrastructure in a hybrid work

Qualifications

  • Bachelor's or Master’s in Computer Science, Computer Engineering, or equivalent experience.
  • 5+ years of experience in network security engineering, cloud-native security, or a closely related infrastructure security field.
  • Deep expertise in cloud networking security, including experience with GCP services like VPC-SC, Cloud Armor, Cloud IDS, and Identity-Aware Proxy (IAP).
  • Strong technical understanding of networking protocols, perimeter defenses, and DDoS mitigation strategies across all layers of the OSI model.
  • Proven experience with Infrastructure-as-Code (IaC) tools, specifically Terraform, for building and managing security policies as code.

Responsibilities

  • Design, deploy, and govern secure GCP networking architecture, including VPC Service Controls and zero default VPC configurations.
  • Leverage GCP network security tools such as Cloud Armor, VPC-SC, Cloud NAT, and Private Service Connect to enforce a private-only network perimeter.
  • Protect global grid infrastructure from multi-layer DDoS threats and ensure resilient, high-availability connectivity across OSI layers.
  • Engineer security policies as Terraform code, ensuring firewall rules, VPC peering, and access control are automated and auditable.
  • Audit cloud and perimeter networks for gaps, misconfigurations, and drift, partnering with engineering teams to drive rapid remediation.
  • Implement boundary controls and ensure no external IPs or unauthenticated paths exist in production.

Skills

Cloud networking security
GCP networking
Security as Code
Terraform
DDoS mitigation

Education

Bachelor's or Master’s in Computer Science/Engineering

Tools

Terraform
GitHub Actions
Cloud Armor

Job description

Tapestry is seeking a Network Security Engineer to own the design, implementation, and operation of perimeter and cloud networks across GCP environments. You will secure inter-application connectivity, enforce security controls, and audit networks while collaborating with cross-functional teams on secure design patterns.

You will contribute to a scalable security program with Terraform, Cloud Armor, and VPC-SC, aiming to prevent public access and protect critical infrastructure in a hybrid work

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Hybrid Cloud Network Security Engineer (GCP)
Hybrid Cloud Network Security Engineer (GCP)

X Development, LLC • Mountain View (CA)

Hybrid
USD 174,000 - 255,000
Competitive salary
Equity
Health benefits
+3
GCP Security Architect - Zero-Trust & DoD (Remote)
GCP Security Architect - Zero-Trust & DoD (Remote)

CACI International Inc. • United States

Remote
USD 105,100 - 231,100
Security Engineer - Networking, Tapestry
Security Engineer - Networking, Tapestry

X Development, LLC • Mountain View (CA)

On-site
USD 174,000 - 255,000
Competitive salary
Equity
Health benefits
+3
Security Engineer - Networking
Security Engineer - Networking

Tapestry • Mountain View (CA), San Francisco (CA), Austin (TX), New York (NY)

On-site
USD 174,000 - 255,000
Competitive salary and equity
Medical, dental, and vision coverage
Generous PTO and flexible hybrid work
GCP Cloud Security Engineer — Terraform & IaC Expert
GCP Cloud Security Engineer — Terraform & IaC Expert

Tata Consultancy Services • Louisville (KY)

On-site
USD 90,000 - 130,000
Annual Incentive
Medical Coverage
Parental Leave
+5
Global Lead Network Architect — Zero Trust & IaC
Global Lead Network Architect — Zero Trust & IaC

Take-Two Interactive • Austin (TX)

On-site
USD 140,000 - 190,000
Medical (HSA & FSA) benefits
401(k) with company match
Employee stock purchase plan
+3
TIC Security Engineer: Zero Trust & Cloud Boundary Expert
TIC Security Engineer: Zero Trust & Cloud Boundary Expert

Entarian • Arlington (VA)

On-site
USD 140,000 - 190,000
Senior Cloud Security Engineer — GCP & IaC Expert
Senior Cloud Security Engineer — GCP & IaC Expert

Technology Resource Management • United States

Hybrid
USD 140,000 - 190,000
Senior Network Security Engineer – Cloud & Zero-Trust
Senior Network Security Engineer – Cloud & Zero-Trust

Workday • Atlanta (GA)

Hybrid
USD 144,000 - 258,000
Hybrid Cloud Zero-Trust Security Architect Lead
Hybrid Cloud Zero-Trust Security Architect Lead

gdit • Martinsburg (WV)

Hybrid
USD 115,000 - 155,000