The Role :
We are looking for a dedicated Cloud Security Engineer to design, implement, and manage security controls within our Google Cloud Platform (GCP) environment. This role is critical in protecting our data and applications, ensuring we meet all compliance and regulatory requirements in a cloud-native landscape.
What You'll Do :
- Security Architecture : Design and implement secure architecture patterns for GCP services, focusing on networking (VPC Service Controls), identity (Cloud IAM), and data protection.
- Compliance & Governance : Ensure all cloud deployments adhere to security policies, industry standards (e.g., ISO 27001, SOC 2), and regulatory requirements.
- Security Automation : Develop and automate security enforcement and monitoring using Infrastructure as Code (IaC) tools like Terraform and scripting (Python / Go).
- Vulnerability Management : Conduct regular security assessments, penetration tests, and vulnerability scanning on cloud resources and applications, driving remediation efforts.
- Incident Response : Participate in the security incident response lifecycle, conducting forensic analysis and post-mortem reviews for cloud-related incidents.
Required Skills & Qualifications :
4+ years of experience in Information Security, with 2+ years specializing in Cloud Security (GCP is mandatory).Deep technical knowledge of GCP security services (Cloud IAM, Security Command Center, Cloud Armor, VPC Service Controls, GKE security).Hands-on experience with Terraform or other IaC tools for managing security configurations.Proficiency in scripting (Python or Go) for security automation tasks.Strong understanding of network security principles, threat modeling, and access management best practices.Relevant security certification (e.g., GCP Professional Cloud Security Engineer, CISSP, CCSP) is highly desirable(ref : hirist.tech)