Security Engineer

KPG99 INC

New York (NY)

On-site

USD 150,000 - 230,000

Full time

5 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

KPG99 INC in New York is seeking a Senior GCP Security Engineer who owns the security architecture end-to-end. You will design guardrails, implement Terraform modules, and integrate security controls within Harness CI/CD pipelines for secure-by-default deployments.

The role focuses on GCP-first operations—securing GKE workloads, Vertex AI pipelines, and ICAM-based identities. Familiarity with AWS/Azure is a plus, but daily work centers on Google Cloud security best practices.

Qualifications

  • 5+ years of cloud security experience, mainly in GCP.
  • Hands-on with GCP security services: IAM, VPC Service Controls, Cloud Armor, KMS, Secret Manager, DLP, SCC.
  • Elastic SIEM with log ingestion, detection engineering, alert management, threat correlation.
  • Terraform production-level experience with modules, automation, state management.
  • CI/CD integration using Harness or similar.
  • Kubernetes and GKE security knowledge: pod security policies, network policies, Workload Identity, Binary Authorization.
  • ICAM or enterprise identity platforms governing non-human identities.
  • AI/ML security including Vertex AI workload protection, LLM API governance, data security.

Responsibilities

  • Own the end-to-end security architecture on GCP.
  • Design guardrails and govern GKE workloads and Vertex AI pipelines.
  • Write Terraform modules and automate infrastructure.
  • Integrate security controls into CI/CD pipelines with Harness.
  • Collaborate with engineering teams to ensure secure-by-default deployments.
  • Manage identities and access controls via ICAM.

Skills

GCP security
Terraform
Harness CI/CD
Kubernetes security
ICAM management
AI/ML security

Education

Google Professional Cloud Security Engineer

Tools

Elastic SIEM
GKE
Cloud Armor
IAM
VPC Service Controls
KMS

Job description

Requirement Notes (Candidate Job description below) : We are looking for a Senior (5+ years) GCP Security Engineer who lives on GCP and can own the security architecture end-to-end, not just advise on it. You will design guardrails, write Terraform, integrate with Harness CI/CD pipelines, and partner with engineering teams to ensure every resource deployed is secure by default. This role is GCP-first. Familiarity with AWS and Azure is a plus, but your day-to-day will be deep in Google Cloud: securing GKE workloads, governing AI pipelines on Vertex AI, managing identities via ICAM, and using native GCP security services to detect and respond to threats.

**** THE MANAGER WOULD LIKE TO SEE CERTIFICATIONS.

Must Have:

  • Experience with GCP security services including IAM, VPC Service Controls, Cloud Armor, KMS, Secret Manager, DLP, and SCC.
  • Strong Elastic SIEM experience including log ingestion, detection engineering, alert management, and threat correlation.
  • Production-level Terraform experience including module development, infrastructure automation, and state management.
  • Strong knowledge of Kubernetes and GKE security including pod security admission, network policies, Workload Identity, and Binary Authorization.

MANAGERS NOTES:

  • Looking for a Security-focused GCP Engineer
  • Risk/Compliance
  • Not DevOps or Logging
  • Must be fully hands-on developing
  • Should not rely on AI to assist with development

Job Description:

CANDIDATES MUST COMMIT TO A FINAL IN PERSON, ONSITE INTERVIEW (TRAVEL PAID BY THE CLIENT).

We are looking for a Senior GCP Security Engineer who lives on GCP and can own the security architecture end-to-end, not just advise on it. You will design guardrails, write Terraform, integrate with Harness CI/CD pipelines, and partner with engineering teams to ensure every resource deployed is secure by default. This role is GCP-first. Familiarity with AWS and Azure is a plus, but your day-to-day will be deep in Google Cloud: securing GKE workloads, governing AI pipelines on Vertex AI, managing identities via ICAM, and using native GCP security services to detect and respond to threats.

What You'll Bring:

  • 5+ years of experience in cloud security, with the majority focused on GCP environments.
  • Deep hands-on experience with GCP security services including IAM, VPC Service Controls, Cloud Armor, KMS, Secret Manager, DLP, and SCC.
  • Strong Elastic SIEM experience including log ingestion, detection engineering, alert management, and threat correlation.
  • Production-level Terraform experience including module development, infrastructure automation, and state management.
  • Experience integrating security controls into CI/CD pipelines using Harness or equivalent platforms.
  • Strong knowledge of Kubernetes and GKE security including pod security admission, network policies, Workload Identity, and Binary Authorization.
  • Hands-on experience with ICAM or enterprise identity platforms governing non-human identities and workload access.
  • Practical knowledge of AI/ML security including Vertex AI workload protection, LLM API governance, and training data security.

Preferred Qualifications

  • Google Professional Cloud Security Engineer or Professional Cloud Architect certification.
  • Experience with policy-as-code tooling such as OPA/Rego, Sentinel, or Checkov.
  • Familiarity with AWS security services including IAM, GuardDuty, SCPs, and multi-cloud security architectures.
  • Experience with Cribl Stream or similar log routing technologies integrated with Elasticsearch.
  • Understanding of compliance-driven security requirements including NY DFS 23 NYCRR 500, NAIC, NIST CSF, CIS Benchmarks, and ISO 27001.
  • Working knowledge of enterprise identity platforms including SailPoint, CyberArk, Ping Identity, Active Directory, and LDAP.
  • Experience securing AI agent frameworks such as LangChain or Vertex AI Agent Builder.

Primary Technology Stack:

  • Infrastructure as Code: Terraform (required), Harness CI/CD, ICAM
  • Identity: GCP Workload Identity Federation, service account governance, ICAM, SailPoint, CyberArk, Ping Identity, Active Directory, LDAP
  • AI/ML: Vertex AI Agent Builder, Gemini APIs, BigQuery ML, RAG pipelines
  • Secondary: AWS (IAM, GuardDuty, Bedrock), Azure (familiarity acceptable)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior GCP Security Engineer
Senior GCP Security Engineer

Madison-Davis, LLC • New York (NY)

On-site
USD 180,000 - 240,000
Senior Security Engineer
Senior Security Engineer

twentysix • El Segundo (CA)

On-site
USD 120,000 - 180,000
Cloud Security Engineer - GCP
Cloud Security Engineer - GCP

ExecuSource • Marietta (GA)

Hybrid
USD 115,000 - 155,000
Security Engineer (Google SecOps Technical Credential)
Security Engineer (Google SecOps Technical Credential)

Infinite Ranges • United States

Remote
USD 100,000 - 140,000
GCP Tech Lead
GCP Tech Lead

Insight Global • Hartford (CT)

On-site
USD 180,000 - 240,000
Google Cloud Platform Security Architect | GCP Cloud Security & SIEM Engineer
Google Cloud Platform Security Architect | GCP Cloud Security & SIEM Engineer

Pacer Group • New York (NY)

Hybrid
Medical
Dental
Vision
+1
GCP Cloud Security Architect
GCP Cloud Security Architect

Donyati • United States

On-site
USD 140,000 - 180,000
Devops Cloud Security Engineer
Devops Cloud Security Engineer

Tata Consultancy Services • Louisville (KY)

On-site
USD 90,000 - 130,000
Annual Incentive
Medical Coverage
Parental Leave
+5
Staff Cloud Security Engineer
Staff Cloud Security Engineer

ninjatrader • Chicago (IL)

On-site
USD 180,000 - 240,000
Senior Google Cloud Security Engineer
Senior Google Cloud Security Engineer

Akkodis • Charlotte (NC)

Hybrid
USD 90,000 - 103,000