Lead Security Engineer
The primary responsibility of this position is to oversee and enhance the organization's overall security posture.
This encompasses a wide range of security aspects, including cloud, on-premises infrastructure, and everything in between.
You will be responsible for designing and enforcing policies, automating controls, and hardening infrastructure end-to-end.
With a focus on GCP resources, you will also partner with teams across networking, applications, and compliance to ensure we are secure by design and resistant to drift.
Key Responsibilities :
- Enterprise Security Architecture : Governance and Compliance - driving adherence to industry standards such as ISO 27001, SOC 2, GDPR, and CIS benchmarks on all infrastructure.
- Policy, Automation, and Guardrails : Own the end-to-end security lifecycle by defining policy-as-code, embedding continuous compliance checks into CI / CD pipelines, and building automated, drift-resistant guardrails across cloud, containers, and VMs.
- Infrastructure Hardening and Drift Detection : Implement automated drift alerts and self-healing playbooks for VPCs, firewall rules, Kubernetes clusters, and endpoints.
- Monitoring, Logging, and Incident Response : Configure Cloud Audit Logs, SIEM exports, and custom alerts for critical security events; lead root-cause investigations, build detection logic, and develop runbooks for cloud-wide incidents.
Requirements :
5+ years of experience driving security and compliance in dynamic, regulated environments, securing cloud-native platforms and hybrid infrastructures, with deep familiarity in fintech and portfolio-management standards, and best practices for supporting distributed, remote teams.Deep expertise with GCP security (IAM, KMS, VPC Service Controls, Cloud Logging / Audit, WAF, SecOps) and Kubernetes application hardening.Strong Infrastructure-as-Code skills (Terraform or equivalent) and GitOps experience (ArgoCD, Flux).Proficiency in Python scripting and policy-as-code frameworks (OPA, Gatekeeper).Excellent communicator able to translate technical findings into clear policies and remediation plans.Helpful Experience :
Familiarity with multi-cloud security controls.Security certifications (GCP Professional Security Engineer, CISSP, CKA / CKS).Experience with service mesh (Istio / Anthos) or zero-trust architectures.