Staff Cloud Security Engineer

ninjatrader

Chicago (IL)

On-site

USD 180,000 - 240,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

PVH (Tommy Hilfiger/Calvin Klein) is seeking a Staff Cloud Security Engineer to set technical direction for securing our cloud workloads on GCP. You will design edge defenses with Cloudflare and Cloud Armor, build policy-as-code guardrails, and drive security across IAM, KMS, and Compliance.

You will mentor engineers and lead incident response efforts. The role emphasizes risk-aware architectural decisions, cross-functional collaboration, and enabling engineers to move fast without compromising

Qualifications

  • 8+ years of experience in security engineering, including 5+ years in cloud security.
  • Hands-on with Google Cloud Platform environments: IAM, networking, VPC Service Controls, Security Command Center, KMS, Organization Policy.
  • Production experience with Cloudflare: WAF, DDoS Protection, Zero Trust/Access, Bot Management, and Cloud Armor.
  • IaC and CI/CD security: Terraform modules and secure pipelines.

Responsibilities

  • Own cloud security architecture across GCP environments, including IAM and least privilege design.
  • Design, deploy, and tune edge and application defenses using Cloudflare and Google Cloud Armor.
  • Lead threat modeling and security reviews for new services and major platform changes.
  • Build guardrails as code through policy-as-code and secure Terraform modules.
  • Advance cloud detection/response by partnering with SOC and IR teams on logging and SIEM detections.
  • Respond as senior technical responder during incidents: investigation, containment, remediation, hardening.
  • Translate ISO, SOC 2, SOX into scalable technical controls with GRC.
  • Mentor engineers to raise security maturity; represent Cloud Security in planning.

Skills

Cloud security
Threat modeling
IAM design
Terraform / IaC
Python/Go
Incident response
Security architecture
Mentoring

Tools

Terraform
Cloudflare
Google Cloud Armor
Chronicle/SIEM

Job description

Role Overview

As a Staff Cloud Security Engineer, you are the most senior individual contributor responsible for the security of our cloud platform. You will set the technical direction for how we secure workloads across Google Cloud Platform (GCP), design our edge and perimeter defenses using Cloudflare and Google Cloud Armor, and build the guardrails that enable engineering teams to move quickly without compromising security.

Responsibilities
  • Own the cloud security architecture across our GCP environments, including IAM and least privilege design, VPC Service Controls, Organization Policy, Shared VPC, Workload Identity, KMS/encryption, and Security Command Center.
  • Design, deploy, and tune edge and application-layer defenses using Cloudflare (WAF, DDoS Protection, Zero Trust/Access, Bot Management, Rate Limiting) and Google Cloud Armor (Security Policies, Adaptive Protection, Rate Limiting, and Global Load Balancer integration).
  • Lead threat modeling and security architecture reviews for new services and major platform changes while balancing business velocity with security risk.
  • Build security guardrails as code through policy-as-code, secure Terraform modules, and CI/CD security controls so secure defaults become the path of least resistance.
  • Advance cloud detection and response capabilities by partnering with the SOC and Incident Response teams on logging pipelines, Chronicle/SIEM detections, and cloud-native alerting.
  • Serve as a senior technical responder during security incidents, including investigation, containment, remediation, and post-incident hardening.
  • Partner with GRC and Compliance teams to translate regulatory requirements such as ISO, SOC 2, SOX, and similar frameworks into scalable technical controls and evidence.
  • Mentor senior and mid-level engineers while raising the overall security maturity of the engineering organization.
  • Represent Cloud Security during cross-functional planning, architecture reviews, and strategic initiatives.
Qualifications
  • 8+ years of experience in security engineering, including at least 5 years focused on cloud security in production environments.
  • Deep hands‑on expertise securing Google Cloud Platform environments, including IAM, networking, VPC Service Controls, Security Command Center, KMS, and Organization Policy.
  • Demonstrated production experience with Cloudflare, including WAF, DDoS Protection, Zero Trust/Access, Bot Management, and Google Cloud Armor.
  • Strong Infrastructure-as-Code experience using Terraform and securing CI/CD pipelines.
  • Proficiency in at least one programming or scripting language such as Python or Go for automation and tooling.
  • Experience securing workloads within regulated industries and familiarity with frameworks such as PCI DSS, SOC 2, ISO, SOX.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cloud Security Engineer
Cloud Security Engineer

Jobtailor • Charlotte (NC)

On-site
USD 65,000 - 90,000
Senior Security Engineer
Senior Security Engineer

twentysix • El Segundo (CA)

On-site
USD 120,000 - 180,000
Staff Security Engineer, Product Security Engineering, Cloud CISO
Staff Security Engineer, Product Security Engineering, Cloud CISO

Socket.dev • New York (NY)

On-site
USD 207,000 - 300,000
Staff Security Engineer, Product Security Engineering, Cloud CISO
Staff Security Engineer, Product Security Engineering, Cloud CISO

Google • New York (NY)

On-site
USD 207,000 - 300,000
Security Engineer (Google SecOps Technical Credential)
Security Engineer (Google SecOps Technical Credential)

Infinite Ranges • United States

Remote
USD 100,000 - 140,000
Senior Staff Security Engineer, GCP Cyber Defense Center
Senior Staff Security Engineer, GCP Cyber Defense Center

Google • Sunnyvale (CA)

On-site
USD 262,000 - 364,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Socket.dev • Seattle (WA)

On-site
USD 152,000 - 221,000
Bonus target
Equity
Benefits
Senior Staff Security Engineer, GCP Cyber Defense Center
Senior Staff Security Engineer, GCP Cyber Defense Center

Socket.dev • Sunnyvale (CA)

On-site
USD 262,000 - 364,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Manhattan Associates • Atlanta (GA)

On-site
USD 120,000 - 150,000
GCP Cloud Security Architect
GCP Cloud Security Architect

Donyati • United States

On-site
USD 140,000 - 180,000