Work closely with GCP platform and SaaS engineering teams to secure environments without disrupting innovation.
Provide practical, non-invasive recommendation that strengthen posture while enabling business agility.
Monitor GCP (primary), AWS, and Azure environments for risks flagged by MDR/AI systems.
Validate and triage incidents escalated by MDR/MSSP and AI detection platforms.
Provide clear incident summaries and reporting to the VP of Information Security.
Engage incident response retainers and cyber insurance partners as needed.
Lead and maintain evidence collection for SOC 2 Type II and ISO 27001 certifications.
Partner with Legal on customer audit/security requests and data privacy considerations (GDPR, CCPA).
Ensure continuous audit readiness across the enterprise.
Manage vendor security assessments and third-party risk processes.
Oversee penetration testing and ensure timely remediation of findings.
Support enterprise risk reporting and governance initiatives.
Deliver regular reports on cloud security posture, active threats, and compliance metrics.
Serve as the bridge between security operations and platform innovation teams, ensuring alignment with both compliance obligations and business priorities.
Requirements
Experience: 5+ years in cybersecurity with cloud security focus.
Cloud: Strong hands-on experience with Google Cloud Platform (preferred); AWS and Azure familiarity beneficial.
Certifications (preferred): Google Cloud Security certifications, CISSP, CCSP, or equivalent.
Knowledge Areas: MDR/MSSP workflows and incident escalation, SOC 2, ISO 27001, GDPR, and CCPA frameworks.
Strong communication and collaborative mindset.
Ability to integrate security without slowing innovation.