GCP Security Engineer

BlueVector AI

Denver (CO)

Hybrid

USD 100,000 - 140,000

Full time

20 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health, Dental, and Vision insurance
Simple IRA Retirement plan with match
Unlimited PTO

Job summary

BlueVector AI in the Denver area is seeking a mid-level security engineer to join our team. You will drop into client environments, assess GCP footprints, and implement lockdowns with a focus on least-privilege IAM, guardrails, and secure data handling.

You’ll work directly with client technical leads and with our internal architects, translating complex compliance rules into practical cloud controls and pipelines.

Qualifications

  • 3+ years in InfoSec, cloud security, or DevSecOps.
  • At least 1 year securing GCP environments.
  • Experience applying FedRAMP, NIST, or HIPAA to cloud environments.
  • US Citizenship required due to public sector client requirements.

Responsibilities

  • Set up least-privilege IAM policies, Workload Identity, and clean service account governance across GCP projects.
  • Configure network guardrails like VPC Service Controls, Cloud Armor, and private access to protect sensitive workloads.
  • Manage CMEK keys and DLP rules to protect data in BigQuery and Cloud Storage.
  • Map FedRAMP, NIST 800-53, or HIPAA requirements to actual GCP configurations and perform threat modeling.

Skills

Cloud security engineering
Terraform IaC
GCP security controls
Python or Bash scripting
Security compliance FedRAMP/NIST/HIPAA

Education

BS in Computer Science, Cybersecurity, or equivalent

Tools

Terraform
Python
Bash

Job description

Our mission is to radically transform government and healthcare using the Google Cloud Platform. We do this by partnering with our clients and with the Google Cloud team to develop tools that make it easier for our clients to serve their communities.

About Us

Our mission is to radically transform government and healthcare using the Google Cloud Platform. We do this by partnering with our clients and with the Google Cloud team to develop tools that make it easier for our clients to serve their communities.

About the Role

We need a mid-level security engineer who can drop into a client environment, evaluate their setup, and make sure their GCP footprint is locked down. You'll work directly alongside client technical leads and our internal architects, so you should be comfortable explaining security trade-offs without getting bogged down in jargon. If you enjoy taking complex compliance rules and turning them into practical, working cloud controls, you'll fit right in.

Key Responsibilities - Cloud Security & Identity Governance
  • Set up least-privilege IAM policies, Workload Identity, and clean service account governance across GCP projects.
  • Configure network guardrails like VPC Service Controls, Cloud Armor, and private access to protect sensitive workloads.
  • Manage CMEK keys and configure DLP rules to protect data stored in BigQuery and Cloud Storage.
Key Responsibilities - Security Engineering & Automation
  • Monitor GCP Security Command Center Premium to catch vulnerabilities and automate basic remediation steps.
  • Write security guardrails directly into Terraform modules and deployment pipelines for GKE or Cloud Run.
  • Pipe Cloud Logging audit trails into client SIEM tools and help set up incident response paths.
Key Responsibilities - Compliance & Client Engagement
  • Map FedRAMP, NIST 800-53, or HIPAA requirements directly to actual GCP system configurations.
  • Run security reviews and threat modeling sessions directly with client security officers.
  • Take high-level compliance mandates and turn them into actionable technical tasks for engineering teams.
Required Qualifications
  • 3+ years working in InfoSec, cloud security engineering, or DevSecOps.
  • At least 1 year of hands-on experience securing GCP environments.
  • Proficient with Terraform for IaC alongside Python or Bash for scripting.
  • Direct experience applying frameworks like FedRAMP, NIST, or HIPAA to cloud environments.
  • BS in Computer Science, Cybersecurity, or equivalent practical experience.
  • US Citizenship required due to public sector client requirements.
  • Ability to work hybrid out of our Wheat Ridge, CO office and client sites (~50% of the time).
Preferred Qualifications
  • Active GCP Professional Cloud Security Engineer certification.
  • Prior experience working on government, higher ed, or healthcare systems.
  • Hands-on work locking down GKE clusters and containerized applications.
  • Experience securing AI/LLM pipelines or API gateways.
  • Industry certs like CISSP, CCSP, or Security+.
Conditions of Employment

The position is an excepted appointment subject to background investigation and drug screen. Due to the nature of our clients, this position requires US citizenship.

  • Job Type: Full-time
  • Pay: $100,000.00 – $140,000.00 per year + 10% bonus
Benefits
  • Health, Dental, and Vision insurance
  • Simple IRA Retirement plan with company match
  • Unlimited Paid Time Off (PTO)
  • Google Certification reimbursement
Job Location & Travel
  • Location: Denver, Colorado area (Wheat Ridge, CO office)
  • Hybrid Schedule: ~50% in-office/client site, 50% remote (up to 5% travel)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cloud Consultant / Application Developer
Cloud Consultant / Application Developer

BlueVector AI • Denver (CO)

Hybrid
USD 90,000 - 130,000
Health, Dental, Vision insurance
Simple IRA with company match
Unlimited PTO
+1
Cloud Security Engineer - GCP
Cloud Security Engineer - GCP

ExecuSource • Marietta (GA)

Hybrid
USD 115,000 - 155,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Google • Seattle (WA)

On-site
USD 152,000 - 221,000
Health insurance
Retirement benefits (401k)
Paid time off
+3
Senior Security Consultant, Google Public Sector
Senior Security Consultant, Google Public Sector

Google • Reston (VA)

Hybrid
USD 132,000 - 194,000
Bonus
Equity
Comprehensive benefits
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Socket.dev • Seattle (WA)

On-site
USD 152,000 - 221,000
Bonus target
Equity
Benefits
Security Engineer, PSO
Security Engineer, PSO

Google Inc. • Seattle (WA)

On-site
USD 152,000 - 222,000
Health, dental, vision, life insurance
Retirement Benefits: 401(k) with company match
Paid Time Off: 20 days vacation annually
+3
Security Engineer (Google SecOps Technical Credential)
Security Engineer (Google SecOps Technical Credential)

Infinite Ranges • United States

Remote
USD 100,000 - 140,000
Senior Security Engineer, Public Sector
Senior Security Engineer, Public Sector

Google • Reston (VA)

Hybrid
USD 166,000 - 244,000
Google Cloud Platform Security Architect | GCP Cloud Security & SIEM Engineer
Google Cloud Platform Security Architect | GCP Cloud Security & SIEM Engineer

Pacer Group • New York (NY)

Hybrid
Medical
Dental
Vision
+1
Staff Security Engineer Manager
Staff Security Engineer Manager

Google • United States

On-site
USD 207,000 - 301,000
Health insurance
401(k) match
Paid time off
+2