Hybrid Cloud Network Security Engineer (GCP)

X Development, LLC

Mountain View (CA)

Hybrid

USD 174,000 - 255,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Competitive salary
Equity
Health benefits
Generous PTO
Hybrid work model
401(k)

Job summary

Tapestry, a Google-affiliated group, is seeking a Network Security Engineer to own the architectural design, implementation, and operations of our perimeter and cloud networks across GCP environments. You will secure inter-application connectivity and guardrails, enforce security controls, and audit networks for vulnerabilities to protect the AI-powered electric grid.

Join a cross-functional team and implement Terraform-based security policies, leveraging VPC-SC, Cloud Armor, and other tools.

Qualifications

  • Bachelor's or Master's in Computer Science, Computer Engineering, or equivalent experience.
  • 5+ years of experience in network security engineering, cloud-native security, or a closely related infrastructure security field.
  • Deep expertise in cloud networking security, including experience with GCP services like VPC Service Controls (VPC-SC), Cloud Armor, Cloud IDS, and Identity-Aware Proxy (IAP).
  • Strong understanding of networking protocols, perimeter defenses, and DDoS mitigation strategies across all layers of the OSI model.
  • Proven experience with IaC tools, specifically Terraform, for building and managing security policies as code.
  • Excellent communication and collaboration skills to navigate technical ambiguity and align cross-functional engineering teams on secure design patterns.

Responsibilities

  • Design, deploy, and govern secure GCP networking architecture, including VPC-SC and zero default VPC configurations to ensure secure connectivity and strictly prevent the use of public endpoints.
  • Leverage GCP network security tools including Cloud Armor, VPC-SC, Cloud NAT, and Private Service Connect to enforce a private-only network perimeter and prevent public access to production resources.
  • Protect Tapestry's global grid infrastructure from multi-layer DDoS threats, ensuring resilient, high-availability connectivity across OSI layers.
  • Engineer and codify security policies as Terraform code (Security as Code), ensuring automated, version-controlled, and auditable firewall rules, VPC peering, and access controls.
  • Audit cloud and perimeter networks for security gaps, misconfigurations, and drift, partnering with engineering teams to drive rapid vulnerability resolutions.
  • Implement boundary controls, secure inter-app connectivity, and ensure no external IPs or unauthenticated boundary paths across production systems.
  • Align architecture with ISO 27001, SOC 2, and energy-specific standards like NERC CIP and FERC CEII enclaves.
  • Partner with AppSec, SecEng/Ops, DataSec, DevOps and Grid Engineering to implement network security telemetry and monitoring.

Skills

Security architecture
Terraform
DDoS mitigation
GCP networking security
IaC
Analytical thinking
Cross‑functional collaboration

Education

Bachelor's or Master's in CS/CE

Tools

Terraform
GCP tools (VPC-SC, Cloud Armor, Cloud IDS)

Job description

Tapestry, a Google-affiliated group, is seeking a Network Security Engineer to own the architectural design, implementation, and operations of our perimeter and cloud networks across GCP environments. You will secure inter-application connectivity and guardrails, enforce security controls, and audit networks for vulnerabilities to protect the AI-powered electric grid.

Join a cross-functional team and implement Terraform-based security policies, leveraging VPC-SC, Cloud Armor, and other tools.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

GCP Network Security Engineer (Zero-Trust)
GCP Network Security Engineer (Zero-Trust)

Tapestry • Mountain View (CA), San Francisco (CA), Austin (TX), New York (NY)

Hybrid
USD 174,000 - 255,000
Competitive salary and equity
Medical, dental, and vision coverage
Generous PTO and flexible hybrid work
Security Engineer - Networking
Security Engineer - Networking

Tapestry • Mountain View (CA), San Francisco (CA), Austin (TX), New York (NY)

On-site
USD 174,000 - 255,000
Competitive salary and equity
Medical, dental, and vision coverage
Generous PTO and flexible hybrid work
Security Engineer - Networking, Tapestry
Security Engineer - Networking, Tapestry

X Development, LLC • Mountain View (CA)

On-site
USD 174,000 - 255,000
Competitive salary
Equity
Health benefits
+3
Remote Cloud Security Engineer — Terraform & Compliance
Remote Cloud Security Engineer — Terraform & Compliance

Google • Tallahassee (FL)

Remote
USD 57,308,000 - 85,962,000
Senior Cloud Network Engineer — GCP & Hybrid Security
Senior Cloud Network Engineer — GCP & Hybrid Security

CACI International • United States

Remote
USD 116,000 - 254,000
Hybrid GCP Security Architect: End-to-End Cloud Defense
Hybrid GCP Security Architect: End-to-End Cloud Defense

New York Life • New York (NY)

Hybrid
USD 124,000 - 177,000
GCP Cloud Security Engineer — Terraform & IaC Expert
GCP Cloud Security Engineer — Terraform & IaC Expert

Tata Consultancy Services • Louisville (KY)

On-site
USD 90,000 - 130,000
Annual Incentive
Medical Coverage
Parental Leave
+5
Lead Security Cloud Engineer - GCP
Lead Security Cloud Engineer - GCP

EPAM Systems Inc • United States

Remote
USD 150,000 - 190,000
Senior Cloud Security Engineer — GCP & IaC Expert
Senior Cloud Security Engineer — GCP & IaC Expert

Technology Resource Management • United States

Hybrid
USD 140,000 - 190,000
Senior GCP Security Engineer
Senior GCP Security Engineer

Madison-Davis, LLC • New York (NY)

On-site
USD 180,000 - 240,000