Haystack
← Back to Jobs
Technology
ST

Sr. Google Cloud Platform Security Engineer

StevenDouglasUnited States🇺🇸United StatesPosted Sep 2, 2026

Why This Role Stands Out

This Sr. Google Cloud Platform Security Engineer role offers a significant opportunity to own end-to-end security architecture and drive impactful innovation within a reputable company, with the flexibility of a hybrid work model. You'll thrive here if you possess deep hands-on GCP security expertise, enjoy automating infrastructure with Terraform, and are passionate about securing cloud-native workloads and AI pipelines. Apply today to elevate your career in cloud security!

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
United States
Posted
2 weeks ago
AWSActive DirectoryAzureBigQueryGoogle CloudKubernetesLDAPLLMTerraform

Job Description

Looking for a Senior Google Cloud Platform Security Engineer who lives on Google Cloud Platform and can own the security architecture end-to-end, not just advise on it. You will design guardrails, write Terraform, integrate with Harness CI/CD pipelines, and partner with engineering teams to ensure every resource deployed is secure by default. This role is Google Cloud Platform-first. Familiarity with AWS and Azure is a plus, but your day-to-day will be deep in Google Cloud: securing GKE workloads, governing AI pipelines on Vertex AI, managing identities via ICAM, and using native Google Cloud Platform security services to detect and respond to threats.
 
What You'll Bring:

  • 5+ years of experience in cloud security, with the majority focused on Google Cloud Platform environments.
  • Deep hands-on experience with Google Cloud Platform security services including IAM, VPC Service Controls, Cloud Armor, KMS, Secret Manager, DLP, and SCC.
  • Strong Elastic SIEM experience including log ingestion, detection engineering, alert management, and threat correlation.
  • Production-level Terraform experience including module development, infrastructure automation, and state management.
  • Experience integrating security controls into CI/CD pipelines using Harness or equivalent platforms.
  • Strong knowledge of Kubernetes and GKE security including pod security admission, network policies, Workload Identity, and Binary Authorization.
  • Hands-on experience with ICAM or enterprise identity platforms governing non-human identities and workload access.
  • Practical knowledge of AI/ML security including Vertex AI workload protection, LLM API governance, and training data security.

 
Preferred Qualifications

  • Google Professional Cloud Security Engineer or Professional Cloud Architect certification.
  • Experience with policy-as-code tooling such as OPA/Rego, Sentinel, or Checkov.
  • Familiarity with AWS security services including IAM, GuardDuty, SCPs, and multi-cloud security architectures.
  • Experience with Cribl Stream or similar log routing technologies integrated with Elasticsearch.
  • Understanding of compliance-driven security requirements including NY DFS 23 NYCRR 500, NAIC, NIST CSF, CIS Benchmarks, and ISO 27001.
  • Working knowledge of enterprise identity platforms including SailPoint, CyberArk, Ping Identity, Active Directory, and LDAP.
  • Experience securing AI agent frameworks such as LangChain or Vertex AI Agent Builder.

 
Primary Technology Stack:

  • Google Cloud Platform: Vertex AI, GKE, Cloud Armor, KMS, SCC, DLP, Secret Manager, Certificate Manager, BigQuery, Cloud Run
  • Infrastructure as Code: Terraform (required), Harness CI/CD, ICAM
  • Identity: Google Cloud Platform Workload Identity Federation, service account governance, ICAM, SailPoint, CyberArk, Ping Identity, Active Directory, LDAP
  • AI/ML: Vertex AI Agent Builder, Gemini APIs, BigQuery ML, RAG pipelines
  • Secondary: AWS (IAM, GuardDuty, Bedrock), Azure (familiarity acceptable)
  • Observability: Elastic SIEM (primary), SCC, Cribl Stream, Elasticsearch

Similar jobs