GCP Security Engineer
Indexed description
Our mission is to radically transform government and healthcare using the Google Cloud Platform. We do this by partnering with our clients and with the Google Cloud team to develop tools that make it easier for our clients to serve their communities.
We need a mid-level security engineer who can drop into a client environment, evaluate their setup, and make sure their GCP footprint is locked down. You'll work directly alongside client technical leads and our internal architects, so you should be comfortable explaining security trade-offs without getting bogged down in jargon. If you enjoy taking complex compliance rules and turning them into practical, working cloud controls, you'll fit right in.
- Set up least-privilege IAM policies, Workload Identity, and clean service account governance across GCP projects.
- Configure network guardrails like VPC Service Controls, Cloud Armor, and private access to protect sensitive workloads.
- Manage CMEK keys and configure DLP rules to protect data stored in BigQuery and Cloud Storage.
- Monitor GCP Security Command Center Premium to catch vulnerabilities and automate basic remediation steps.
- Write security guardrails directly into Terraform modules and deployment pipelines for GKE or Cloud Run.
- Pipe Cloud Logging audit trails into client SIEM tools and help set up incident response paths.
- Map FedRAMP, NIST 800-53, or HIPAA requirements directly to actual GCP system configurations.
- Run security reviews and threat modeling sessions directly with client security officers.
- Take high-level compliance mandates and turn them into actionable technical tasks for engineering teams.
- 3+ years working in InfoSec, cloud security engineering, or DevSecOps.
- At least 1 year of hands-on experience securing GCP environments.
- Proficient with Terraform for IaC alongside Python or Bash for scripting.
- Direct experience applying frameworks like FedRAMP, NIST, or HIPAA to cloud environments.
- BS in Computer Science, Cybersecurity, or equivalent practical experience.
- US Citizenship required due to public sector client requirements.
- Ability to work hybrid out of our Wheat Ridge, CO office and client sites (~50% of the time).
- Active GCP Professional Cloud Security Engineer certification.
- Prior experience working on government, higher ed, or healthcare systems.
- Hands-on work locking down GKE clusters and containerized applications.
- Experience securing AI/LLM pipelines or API gateways.
- Industry certs like CISSP, CCSP, or Security+.
The position is an excepted appointment subject to background investigation and drug screen. Due to the nature of our clients, this position requires US citizenship.
- Job Type: Full-time
- Pay: $100,000.00 – $140,000.00 per year + 10% bonus
- Health, Dental, and Vision insurance
- Simple IRA Retirement plan with company match
- Unlimited Paid Time Off (PTO)
- Google Certification reimbursement
- Location: Denver, Colorado area (Wheat Ridge, CO office)
- Hybrid Schedule: ~50% in-office/client site, 50% remote (up to 5% travel)
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search