A large financial services organization is expanding its Google Cloud and AI capabilities and is seeking a Senior GCP Security Engineer to help build security directly into its cloud engineering environment.
This is a hands‑on engineering position for someone who can move between architecture and implementation. You will design cloud security guardrails, automate controls through Terraform and CI/CD, secure Kubernetes workloads and cloud identities, and work closely with engineering teams deploying applications and AI workloads across GCP.
The role is particularly well suited for someone who combines deep Google Cloud security experience with modern infrastructure-as-code, Kubernetes security, identity, and emerging AI security.
Responsibilities
- Design and implement security architecture and guardrails across GCP.
- Build reusable security controls and infrastructure using Terraform.
- Secure GKE clusters and Kubernetes workloads across identity, network, workload, and deployment layers.
- Govern IAM, service accounts, workload identities, and non‑human access.
- Integrate security checks and controls into CI/CD pipelines.
- Protect AI and machine learning workloads, including Vertex AI, LLM APIs, agents, and RAG environments.
- Implement and operate native GCP security services for threat detection, data protection, encryption, secrets, and perimeter controls.
- Partner with cloud engineers, AI engineers, SREs, identity teams, and security stakeholders.
Role Requirements
- 5+ years of cloud security experience with significant recent GCP depth.
- Strong hands‑on experience implementing security controls within Google Cloud.
- Production‑level Terraform experience, including reusable modules and infrastructure automation.
- Strong Kubernetes and GKE security experience.
- Deep knowledge of GCP IAM, service accounts, Workload Identity, and workload access.
- Experience with multiple GCP security technologies such as SCC, VPC Service Controls, Cloud Armor, KMS, Secret Manager, and DLP.
- Experience incorporating security controls into modern CI/CD environments.
- Practical understanding of AI / ML security, ideally involving Vertex AI or comparable enterprise GenAI platforms.
- Ability to work directly with engineering teams and remain personally hands‑on.
Nice to Have
- Elastic SIEM or Elasticsearch.
- Cribl Stream.
- AWS security and Bedrock.
- Policy‑as‑code tools such as OPA/Rego, Sentinel, or Checkov.
- Enterprise identity platforms such as SailPoint, CyberArk, or Ping Identity.
- Google Cloud security or architecture certifications.
- Experience with financial services or another heavily regulated environment.