Security Engineering SME (Google Cloud Platform Vulnerability & Compliance)
Quick Overview
Job Description
Role: Security Engineering SME (Google Cloud Platform Vulnerability & Compliance)
Location: San Jose, CA
Mandatory Skills Google Cloud Platform
Experience Level: Senior (7+ years)
Role Overview
The Lead Security Engineer is the primary technical lead responsible for the end-to-end engineering and automation of the FedRAMP Key Security Indicator (KSI) initiative. This role bridges the gap between regulatory compliance and hands-on cloud engineering. The Lead Engineer will design automated cloud controls, manage Google Cloud Platform security vulnerability pipelines, and guide a technical team in deploying solutions that ensure continuous monitoring and secure architectures across Google Cloud Platform (Google Cloud Platform).
Key Responsibilities
- Technical Leadership & Translation: Lead discovery workshops to deconstruct FedRAMP KSIs and NIST SP 800-53 controls, translating high-level compliance mandates into binary, automatable technical specifications.
- Vulnerability Management & Pipelines: Oversee and implement VM vulnerability scanning (AutoVM, Tenable, Qualys, Nessus), container image scanning (Artifact Registry / Drydock), and static/dynamic analysis tools.
- Automation & Scripting: Analyze Google Cloud Asset Inventory (CAI) schemas and oversee the authoring and testing of Common Expression Language (CEL) evaluation rules to define precise Pass/Fail criteria for cloud controls.
- Pipeline & Telemetry Architecture: Design, deploy, and troubleshoot log agents (Fluentbit/Vector) and Cloud Logging sinks to ensure 100% telemetry coverage across container nodes, VMs, and control-plane APIs.
- Identity & Access Management (IAM): Architect and enforce least-privilege IAM bindings, service accounts, and VPC Service Controls across the Google Cloud Platform environment.
- Validation & Deployment: Test logic against synthetic resources in sandbox environments to minimize false positives, manage codebase version control (Git/Piper), and support progressive deployment rollouts.
- Cross-Functional Collaboration: Act as the technical bridge for the project, supporting gap analyses and providing engineering evidence to Governance teams and 3PAO assessors.
Qualifications & Requirements
- Experience: 7+ years in Cloud Security Engineering, DevSecOps, or Infrastructure Security, with proven experience as a Lead/Senior Engineer managing FedRAMP (Moderate/High) security vulnerability implementations.
- Cloud Platform Expertise: Strong, hands-on background in Google Cloud Platform (Google Cloud Platform), specifically with Cloud Asset Inventory (CAI), Security Command Center (SCC), IAM, Cloud Audit Logs, and Cloud Storage.
- Scripting & Languages: Advanced proficiency in Common Expression Language (CEL). Working knowledge of Python, Go, or Rego/OPA.
- Vulnerability Tooling: Practical experience configuring and automating vulnerability and container scanning tools in a large-scale cloud environment.
- Systems & Infrastructure: Experience with Google Cloud infrastructure and container orchestration (Kubernetes/GKE/Borg).
- Compliance Knowledge: Strong familiarity with automated control evaluation for NIST SP 800-53 Rev 5, CIS Benchmarks, and FedRAMP Continuous Monitoring (ConMon).
- Education: Bachelor s or Master s degree in Computer Science, Information Technology, Cybersecurity, or equivalent practical experience.
Similar jobs
- CD
Identity Governance and Security Posture Analyst
NewCloud Destinations LLC
United States🇺🇸Remote21 hours agoStakeholder ManagementAdministrative - KT
Senior Security Engineer
NewKBC Technologies, Inc
New York, NY🇺🇸Hybrid21 hours agoPCI DSSSOC 2SSO+6Technology - GI
On-Site Senior Certified Application Security Analyst (NIST SP 800-53/Cybersecurity/CSF controls/ Microsoft 365/Defender/Purview/ CISA/CRISC/CGRC/CISM/CISSP)
NewGlobal Information Services
Tallahassee, FL🇺🇸On-site21 hours agoHIPAAPowerShellTechnology - MS
Sr. Network Security Engineer III (6852) with Security Clearance
NewMetroStar Systems Inc.
Washington, DC🇺🇸$207k - $320k/yrHybrid21 hours agoAgileZero TrustTechnology - IT
CyberArk Consultant
Infosys Technologies Ltd
Richardson, TX🇺🇸On-site2 weeks agoAWSAzureGoogle Cloud+1Technology - IN
CRIBL Data Modeling Security Engineer
NewInnosoul inc
United States🇺🇸On-site21 hours agoBashPythonTechnology