Haystack
← Back to Jobs
Technology
ST

Sr. Google Cloud Platform Security Engineer

StevenDouglasUnited States🇺🇸United StatesPosted 28 Aug 2026

Why This Role Stands Out

This Sr. Google Cloud Platform Security Engineer role offers a significant opportunity to own end-to-end security architecture and drive impactful innovation within a reputable company, with the flexibility of a hybrid work model. You'll thrive here if you possess deep hands-on GCP security expertise, enjoy automating infrastructure with Terraform, and are passionate about securing cloud-native workloads and AI pipelines. Apply today to elevate your career in cloud security!

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
United States
Posted
22 hours ago
AWSActive DirectoryAzureBigQueryGoogle CloudKubernetesLDAPLLMTerraform

Job Description

Looking for a Senior Google Cloud Platform Security Engineer who lives on Google Cloud Platform and can own the security architecture end-to-end, not just advise on it. You will design guardrails, write Terraform, integrate with Harness CI/CD pipelines, and partner with engineering teams to ensure every resource deployed is secure by default. This role is Google Cloud Platform-first. Familiarity with AWS and Azure is a plus, but your day-to-day will be deep in Google Cloud: securing GKE workloads, governing AI pipelines on Vertex AI, managing identities via ICAM, and using native Google Cloud Platform security services to detect and respond to threats.
 
What You'll Bring:

  • 5+ years of experience in cloud security, with the majority focused on Google Cloud Platform environments.
  • Deep hands-on experience with Google Cloud Platform security services including IAM, VPC Service Controls, Cloud Armor, KMS, Secret Manager, DLP, and SCC.
  • Strong Elastic SIEM experience including log ingestion, detection engineering, alert management, and threat correlation.
  • Production-level Terraform experience including module development, infrastructure automation, and state management.
  • Experience integrating security controls into CI/CD pipelines using Harness or equivalent platforms.
  • Strong knowledge of Kubernetes and GKE security including pod security admission, network policies, Workload Identity, and Binary Authorization.
  • Hands-on experience with ICAM or enterprise identity platforms governing non-human identities and workload access.
  • Practical knowledge of AI/ML security including Vertex AI workload protection, LLM API governance, and training data security.

 
Preferred Qualifications

  • Google Professional Cloud Security Engineer or Professional Cloud Architect certification.
  • Experience with policy-as-code tooling such as OPA/Rego, Sentinel, or Checkov.
  • Familiarity with AWS security services including IAM, GuardDuty, SCPs, and multi-cloud security architectures.
  • Experience with Cribl Stream or similar log routing technologies integrated with Elasticsearch.
  • Understanding of compliance-driven security requirements including NY DFS 23 NYCRR 500, NAIC, NIST CSF, CIS Benchmarks, and ISO 27001.
  • Working knowledge of enterprise identity platforms including SailPoint, CyberArk, Ping Identity, Active Directory, and LDAP.
  • Experience securing AI agent frameworks such as LangChain or Vertex AI Agent Builder.

 
 
Primary Technology Stack:

  • Google Cloud Platform: Vertex AI, GKE, Cloud Armor, KMS, SCC, DLP, Secret Manager, Certificate Manager, BigQuery, Cloud Run
  • Infrastructure as Code: Terraform (required), Harness CI/CD, ICAM
  • Identity: Google Cloud Platform Workload Identity Federation, service account governance, ICAM, SailPoint, CyberArk, Ping Identity, Active Directory, LDAP
  • AI/ML: Vertex AI Agent Builder, Gemini APIs, BigQuery ML, RAG pipelines
  • Secondary: AWS (IAM, GuardDuty, Bedrock), Azure (familiarity acceptable)
  • Observability: Elastic SIEM (primary), SCC, Cribl Stream, Elasticsearch

Similar jobs