Haystack
← Back to Jobs
Technology
GI

Google Cloud Platform Cloud Security Engineer

Galaxy Infotech INCPhoenix, AZ🇺🇸United StatesPosted Sep 30, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Phoenix, AZ, United States
Posted
20 hours ago
FirestoreAWSEncryptionOAuthPCI DSSSOC 2AzureBigQueryGoogle CloudPhoenixRESTTerraform

Job Description

There is A LOT below, but the gist is: The hiring manager indicated that most technical questions will focus on Google Cloud Platform database security, particularly BigQuery and Firestore.

1. Role Overview

  • The position is similar to a previously discussed cloud security role, but the primary focus for this position is Google Cloud Platform / Google Cloud security.
  • The resources will be embedded within the hiring manager's team but funded by an external/contact center technology organization.
  • The broader project involves Contact Center Technology (CCT) initiatives, including modernization of contact center technologies and migration/application work into Google Cloud Platform.
  • The application teams will primarily own the application-side work, while these resources will support the security assessment and implementation of security controls within the Google Cloud Platform environment.

2. Primary Responsibilities / Focus Areas

The hiring manager identified two primary areas of focus:

Google Cloud Platform Cloud Security

  • Hands-on experience securing workloads and resources in Google Cloud Platform.
  • Understanding how resources are deployed in the public cloud.
  • Ability to identify appropriate:
    • Security configurations.
    • Security controls.
    • IAM/access controls.
    • Encryption requirements.
    • Logging and monitoring requirements.
  • Ability to assess and implement security controls from a data security perspective.

Data Security / Database Security

  • Strong understanding of protecting data within cloud databases/data stores.
  • The two primary Google Cloud Platform data stores for this project are:
    • BigQuery
    • Firestore
  • Candidate should be able to identify specific security configurations required to protect these data stores.
  • Key areas include:
    • Data security.
    • Data loss prevention (DLP).
    • Encryption.
    • IAM/access controls.
    • Logging and monitoring.
    • Appropriate security configurations.

3. Google Cloud Platform vs. Other Cloud Experience

  • Google Cloud Platform is preferred, but it is not an absolute requirement.
  • Candidates with strong AWS or Azure cloud security experience may be considered.
  • For non-Google Cloud Platform candidates, the hiring manager wants to see a strong understanding of:
    • Cloud resource deployment.
    • Cloud security configurations.
    • Security controls.
    • Data protection in public cloud environments.
  • Candidates should ideally be able to transfer their existing cloud security knowledge to Google Cloud Platform.

4. Sentinel / Policy-as-Code

  • Sentinel / Policy-as-Code is not a hard requirement.
  • The hiring manager's team does not necessarily need this contractor to create Sentinel policies.
  • Another team will be responsible for creating the actual Sentinel policies.
  • It is sufficient for a candidate to:
    • Understand the purpose of policy-as-code.
    • Identify security requirements that should be enforced.
    • Communicate those requirements to the team responsible for implementing Sentinel policies.
  • Broader experience with Terraform, governance, and cloud security controls is acceptable.

5. AI, Telephony & Application Experience

  • Experience with:
    • Conversational AI.
    • Virtual agents.
    • Telephony platforms.
    • Contact center technologies.
  • These areas are nice-to-have rather than mandatory.
  • The application team will primarily drive these areas.
  • Candidates do not need deep experience in these technologies if they have strong cloud/data security expertise.

6. Candidate Location

  • The role is based in Phoenix.
  • The hiring manager is open to relo candidates who are willing to relocate to Phoenix.
  • Local Phoenix candidates are preferred where available, but relocation candidates are acceptable.

7. Candidate Quality / Vetting

The hiring manager emphasized the importance of thorough candidate vetting before profiles are submitted.

Concerns have arisen with some remote candidates who:

  • Appeared to be reading responses from ChatGPT during interviews.
  • Had discrepancies between their resumes and LinkedIn profiles.
  • Had LinkedIn profiles that appeared to closely mirror job descriptions without demonstrating corresponding experience.

Expectation: Candidates should be thoroughly screened internally before being submitted.

8. Interview Process

The hiring process will consist of approximately two rounds:

Round 1 senior member of team

  • Candidates will first interview with senior member of team.
  • Hiring manager will provide senior member of team with background/context on the role and candidates.

Round 2 Hiring Manager

  • Candidates who pass the first round will have a 30-minute second-round interview with the hiring manager.
  • The hiring manager will use this round to further assess technical fit and relevant cloud/data security experience.

10. Interview Preparation / Technical Focus

The hiring manager indicated that most technical questions will focus on Google Cloud Platform database security, particularly BigQuery and Firestore.

Candidates should be prepared to discuss:

  • How they would secure BigQuery and Firestore.
  • Appropriate IAM/access-control configurations.
  • Encryption requirements.
  • DLP/data protection.
  • Data security controls.
  • Logging and monitoring.
  • Security configurations for cloud-hosted data.
  • How they would identify and remediate security risks.

Candidates without direct BigQuery/Firestore experience may still be considered if they have strong cloud security fundamentals. The hiring manager indicated that candidates can review Google Cloud Platform documentation on these services before the interview and demonstrate how they would approach securing them.

Original JD:

Focus: Security assessment of Google Cloud Platform-based conversational AI, telephony, API, and backend integration architecture.
Responsibilities

  • Assess the end-to-end architecture from a data security and privacy standpoint.
  • Review security controls for Google Cloud Platform Shared VPC, interconnects, service accounts, IAM, and network segmentation.
  • Implement Sentinel policies for enforcing encryption standards and data access standards.
  • Implement database activity monitoring and blocking rules in Google Cloud Platform.
  • Assess AI-specific risks, including prompt/context leakage, model input/output handling, and knowledge store access.
  • Produce findings report with risk ratings, gaps, and remediation recommendations.
  • Review data flows across:
    • Google Cloud Platform service projects
    • Virtual agents / conversational AI
    • Telephony platforms
    • API proxies
    • Datastore, BigQuery, Cloud Storage
    • On-prem / Amex systems of record
  • Identify risks related and implement controls related to:
    • Blocking customer data exposure
    • PII handling
    • Encryption in transit and at rest
    • Secrets and key management, Users and NHI authentication
    • Database activity logging, monitoring, and auditability
    • Data retention and deletion

Required Skills

  • Strong experience in cloud security architecture, preferably Google Cloud Platform.
  • Hands-on knowledge of:
  • Google Cloud Platform IAM
  • VPC / Shared VPC
  • Cloud Run / GKE
  • BigQuery
  • Cloud Storage
  • Datastore / Firestore
  • Cloud KMS / Secret Manager
  • Experience assessing data protection controls for PII, PCI, or regulated customer data.
  • Knowledge of API security, including OAuth, mTLS, token handling, gateways, and service-to-service authentication.
  • Familiarity with network security, private connectivity, firewalls, segmentation, and hybrid cloud interconnects.
  • Understanding of logging, SIEM integration, audit trails, and security monitoring.
  • Experience with threat modeling and architecture risk reviews.

Preferred Skills

  • Experience with conversational AI / virtual agent platforms.
  • Knowledge of telephony/SIP integrations and contact center platforms.
  • Experience with PCI DSS, NIST, ISO 27001, SOC 2, or financial services security standards.
  • Familiarity with AI data governance, model safety, and GenAI security risks.

Similar jobs