Security Engineer
About the Role
We are seeking a Security Engineer to join our team and help maintain and strengthen our security posture within Google Cloud Platform. This role focuses on hands-on security operations, vulnerability management, and implementing security best practices across our cloud infrastructure.
Key Responsibilities
GCP Security Operations
- Manage and configure GCP security services including IAM, Security Command Center, and SecOps
- Conduct routine security configuration reviews across cloud resources
- Implement standard security hardening measures following GCP best practices
- Monitor and respond to security alerts and findings within the GCP environment
- Maintain security documentation and ensure adherence to established security standards
Security Assessments & Vulnerability Management
Execute vulnerability scans across infrastructure and applicationsAnalyze and interpret scan results to identify potential security risksTriage security findings based on severity and business impactProvide remediation guidance to engineering teams for identified vulnerabilitiesReview Python code and system architectures for common security weaknesses, including :Authentication and authorization flaws
Injection vulnerabilitiesInsecure configurations and misconfigurationsOther OWASP Top 10 security issuesSecurity Automation
Develop Python or Bash scripts to automate routine security tasksCreate custom security checks and validation scriptsAutomate repetitive security processes to improve efficiencyBuild tools to support security monitoring and reporting activitiesRequired Qualifications
Hands-on experience with GCP security services (IAM, Security Command Center, SecOps)Practical experience conducting vulnerability assessments and managing security findingsDemonstrated ability to review code (particularly Python) and system designs for security issuesProficiency in Python or Bash scripting for automation purposesStrong understanding of GCP security best practices and cloud security fundamentalsAbility to communicate security findings and recommendations clearly to technical teamsPreferred Qualifications
GCP security certifications (Professional Cloud Security Engineer)Experience with security frameworks and compliance standardsFamiliarity with DevSecOps practices and CI / CD pipeline securityBackground in incident response or security operations