Senior GCP Security Engineer

Posted 2 days ago

madisondavisNew York (NY)

SENIORITY

Lead

Apply

About the role

A large financial services organization is expanding its Google Cloud and AI capabilities and is seeking a Senior GCP Security Engineer to help build security directly into its cloud engineering environment. This is a hands-on engineering position for someone who can move between architecture and implementation. You will design cloud security guardrails, automate controls through Terraform and CI/CD, secure Kubernetes workloads and cloud identities, and work closely with engineering teams deploying applications and AI workloads across GCP.The role is particularly well suited for someone who combines deep Google Cloud security experience with modern infrastructure-as-code, Kubernetes security, identity, and emerging AI security.
Responsibilities: Design and implement security architecture and guardrails across GCP.Build reusable security controls and infrastructure using Terraform. Secure GKE clusters and Kubernetes workloads across identity, network, workload, and deployment layers. Govern IAM, service accounts, workload identities, and non-human access. Integrate security checks and controls into CI/CD pipelines. Protect AI and machine learning workloads, including Vertex AI, LLM APIs, agents, and RAG environments. Implement and operate native GCP security services for threat detection, data protection, encryption, secrets, and perimeter controls. Partner with cloud engineers, AI engineers, SREs, identity teams, and security stakeholders.
Role Requirements: 5+ years of cloud security experience with significant recent GCP depth. Strong hands-on experience implementing security controls within Google Cloud. Production-level Terraform experience, including reusable modules and infrastructure automation. Strong Kubernetes and GKE security experience. Deep knowledge of GCP IAM, service accounts, Workload Identity, and workload access. Experience with multiple GCP security technologies such as SCC, VPC Service Controls, Cloud Armor, KMS, Secret Manager, and DLP.Experience incorporating security controls into modern CI/CD environments. Practical understanding of AI / ML security, ideally involving Vertex AI or comparable enterprise GenAI platforms. Ability to work directly with engineering teams and remain personally hands-on.
Nice to Have: Elastic SIEM or Elasticsearch. Cribl Stream. AWS security and Bedrock. Policy-as-code tools such as OPA/Rego, Sentinel, or Checkov. Enterprise identity platforms such as Sail Point, Cyber Ark, or Ping Identity. Google Cloud security or architecture certifications. Experience with financial services or another heavily regulated environment.

Before you apply

Applying takes about a minute. These four things decide how fast it moves after that.

Your profile is current

It's what we read first. Occupations, seniority and locations matter more than a long history.

Two examples you can talk through

Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.

A number in mind

What you're on now and what would make you move. We negotiate better when we know both.

Your notice period

Employers plan around it, and it's the question that stalls offers most often.

Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.

More like this