Staff Cloud Security Engineer

As a Staff Cloud Security Engineer, you will be the most senior individual contributor responsible for cloud platform security. You will set technical direction for securing workloads across Google Cloud Platform, design edge and perimeter defenses using Cloudflare and Google Cloud Armor, and build guardrails that enable engineering teams to move quickly without compromising security. This is a hands-on individual contributor role involving architecture decisions, security reviews, incidents, and engineering standards.

Responsibilities

  • Own cloud security architecture across GCP environments, including IAM, least privilege, VPC Service Controls, Organization Policy, Shared VPC, Workload Identity, KMS/encryption, and Security Command Center.
  • Design, deploy, and tune edge and application-layer defenses using Cloudflare and Google Cloud Armor.
  • Lead threat modeling and security architecture reviews for new services and major platform changes.
  • Build security guardrails as code through policy-as-code, secure Terraform modules, and CI/CD security controls.
  • Advance cloud detection and response by partnering with SOC and Incident Response teams on logging pipelines, Chronicle/SIEM detections, and cloud-native alerting.
  • Serve as a senior technical responder during security incidents, including investigation, containment, remediation, and post-incident hardening.
  • Partner with GRC and Compliance teams to translate regulatory requirements into scalable technical controls and evidence.
  • Mentor senior and mid-level engineers while raising security maturity.
  • Represent Cloud Security during cross-functional planning, architecture reviews, and strategic initiatives.

Requirements

  • 8+ years of security engineering experience, including at least 5 years focused on cloud security in production environments.
  • Deep hands-on expertise securing GCP environments, including IAM, networking, VPC Service Controls, Security Command Center, KMS, and Organization Policy.
  • Production experience with Cloudflare, including WAF, DDoS Protection, Zero Trust/Access, Bot Management, and Google Cloud Armor.
  • Strong Infrastructure-as-Code experience using Terraform and experience securing CI/CD pipelines.
  • Proficiency in Python, Go, or another programming or scripting language for automation and tooling.
  • Experience securing workloads in regulated industries and familiarity with PCI DSS, SOC 2, ISO, SOX, or similar frameworks.
  • Technical leadership ability and experience influencing engineering teams without direct authority.
  • Preferred: relevant cloud security or architecture certifications, GKE/Kubernetes and supply chain security experience, multi-cloud experience, detection engineering or threat hunting experience, and fintech or trading experience.

Benefits

  • Generous PTO
  • 7 paid holidays annually plus 5 conditional holidays annually
  • 1 service day annually
  • 401k with 3.5% company match
  • Paid parental bonding leave
  • Health, vision, and dental coverage
  • Life and disability insurance covered 100% by NinjaTrader
  • 20 additional flex remote days annually
  • 5 company-wide office-optional weeks tied to major holidays
  • Annual target bonus of 12%

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available