Quick Overview
Job Description
Job Title: Cloud Security Engineer – Policy-as-Code (Google Cloud Platform)
Phoenix, AZ (Hybrid 3 days in office)
Exp: 10+yrs
About the Role
We're looking for a Cloud Security Engineer to design and enforce security guardrails across our Google Cloud environment. You'll define policy-as-code frameworks using Sentinel and native cloud controls, integrate them into our Terraform-based Infrastructure-as-Code pipelines, and work closely with our Cloud-Native Application Protection Platform (CNAPP) tooling — Wiz and Palo Alto Prisma Cloud — to keep deployments secure by default.
Responsibilities
• Evaluate Google Cloud native services and document the corresponding security controls, standards, and operating procedures.
• Conduct feasibility studies to translate existing security controls into policy-as-code scope.
• Design and develop policy-as-code frameworks (Sentinel and native cloud policies) for Terraform-based Infrastructure-as-Code pipelines.
• Partner with the Cloud-Native Application Protection Platform (CNAPP) team — leveraging Wiz and Palo Alto Prisma Cloud — to strengthen policy-as-code guardrails and enforce secure-by-default configurations across cloud platforms.
• Troubleshoot, reproduce, and root-cause customer-reported issues related to Compute, Storage, Data, and policy enforcement.
• Design for high availability while maintaining strong security posture and observability.
• Act as subject matter expert and internal consultant for engineering, sales, and customer teams on Google Cloud Platform infrastructure and deployment challenges.
Required Qualifications
• Bachelor's or Master's degree in Computer Science, Computer Engineering, or a related technical field — or equivalent work experience.
• 3-5 years of experience with Google Cloud foundational services: IAM, VPC, Cloud Logging, security controls, Storage, and Compute.
• 3-5 years of experience with Policy-as-Code (Sentinel) and Infrastructure-as-Code automation (Terraform), with a focus on implementing security controls for cloud-native infrastructure.
• Experience with Cloud-Native Application Protection Platform (CNAPP) tooling — specifically Wiz and/or Palo Alto Prisma Cloud — and secure-by-default enforcement patterns.
• Working knowledge of network isolation, data security, identity, and logging/monitoring tools, including XQL (Extended Query Language) or equivalent, for querying and investigating security event data.
• Proficiency in at least one object-oriented programming language: Java, Go, or Python.
• Strong analytical thinking with the ability to translate business and technical requirements into scalable solutions.
Preferred Qualifications
• Relevant certifications (e.g., Google Professional Cloud Security Engineer, HashiCorp Terraform Associate).
• FinOps domain knowledge.
• Familiarity with additional cloud-native domains (Data, Agentic AI infrastructure) as they relate to policy enforcement.
Similar jobs
- HI
Senior Core Infrastructure Engineer
Highnote
San Francisco, CA🇺🇸$170k - $230k/yrHybrid7 weeks agoAWSBigQueryGoogle Cloud+4Technology - ND
Senior Cloud Platform Architect
NewNTT DATA
Irving, Texas🇺🇸Hybrid34 minutes agoDockerShellAWS+7 - AS
Senior Cloud Solutions Engineer with Security Clearance
ACCELERA SOLUTIONS, INC.
Chantilly, VA🇺🇸On-site1 week agoAWSAzureDNS+2Technology - AG
Cloud Data Engineer
NewAdvent Global Solutions, Inc.
United States🇺🇸$51/hrRemoteYesterdayOraclePL/SQLSQL+5Technology - AB
Cloud Security Engineer
NewAE Business Solutions
Milwaukee, WI🇺🇸$150k/yrOn-siteYesterdayEncryptionTechnology - OT
Sr. Network Engineer
NewOnwardPath Technology Solutions LLC
Long Beach, CA🇺🇸HybridYesterdayTechnology