Back to search
BlueVector AI Linkedin · Posted yesterday

GCP Security Engineer

Denver, Colorado, United States

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

About Us

Our mission is to radically transform government and healthcare using the Google Cloud Platform. We do this by partnering with our clients and with the Google Cloud team to develop tools that make it easier for our clients to serve their communities.


About the Role

We need a mid-level security engineer who can drop into a client environment, evaluate their setup, and make sure their GCP footprint is locked down. You'll work directly alongside client technical leads and our internal architects, so you should be comfortable explaining security trade-offs without getting bogged down in jargon. If you enjoy taking complex compliance rules and turning them into practical, working cloud controls, you'll fit right in.


Key ResponsibilitiesCloud Security & Identity Governance
  • Set up least-privilege IAM policies, Workload Identity, and clean service account governance across GCP projects.
  • Configure network guardrails like VPC Service Controls, Cloud Armor, and private access to protect sensitive workloads.
  • Manage CMEK keys and configure DLP rules to protect data stored in BigQuery and Cloud Storage.


Security Engineering & Automation
  • Monitor GCP Security Command Center Premium to catch vulnerabilities and automate basic remediation steps.
  • Write security guardrails directly into Terraform modules and deployment pipelines for GKE or Cloud Run.
  • Pipe Cloud Logging audit trails into client SIEM tools and help set up incident response paths.


Compliance & Client Engagement
  • Map FedRAMP, NIST 800-53, or HIPAA requirements directly to actual GCP system configurations.
  • Run security reviews and threat modeling sessions directly with client security officers.
  • Take high-level compliance mandates and turn them into actionable technical tasks for engineering teams.


Required Qualifications
  • 3+ years working in InfoSec, cloud security engineering, or DevSecOps.
  • At least 1 year of hands-on experience securing GCP environments.
  • Proficient with Terraform for IaC alongside Python or Bash for scripting.
  • Direct experience applying frameworks like FedRAMP, NIST, or HIPAA to cloud environments.
  • BS in Computer Science, Cybersecurity, or equivalent practical experience.
  • US Citizenship required due to public sector client requirements.
  • Ability to work hybrid out of our Wheat Ridge, CO office and client sites (~50% of the time).


Preferred Qualifications
  • Active GCP Professional Cloud Security Engineer certification.
  • Prior experience working on government, higher ed, or healthcare systems.
  • Hands-on work locking down GKE clusters and containerized applications.
  • Experience securing AI/LLM pipelines or API gateways.
  • Industry certs like CISSP, CCSP, or Security+.


Conditions of Employment

The position is an excepted appointment subject to background investigation and drug screen. Due to the nature of our clients, this position requires US citizenship.

  • Job Type: Full-time
  • Pay: $100,000.00 – $140,000.00 per year + 10% bonus


Benefits
  • Health, Dental, and Vision insurance
  • Simple IRA Retirement plan with company match
  • Unlimited Paid Time Off (PTO)
  • Google Certification reimbursement


Job Location & Travel
  • Location: Denver, Colorado area (Wheat Ridge, CO office)
  • Hybrid Schedule: ~50% in-office/client site, 50% remote (up to 5% travel)


Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search