Tech Stack
CloudGoGoogle Cloud PlatformKubernetesOpen SourcePythonTerraform
About the role
- Perform Threat Modelling of architectural infrastructure changes and new cloud infrastructure and Kubernetes deployments in GCP
- Design, implement, and manage robust security controls and configurations for GCP environments
- Develop and maintain secure Infrastructure as Code (IaC) using Terraform and related tools
- Implement, manage, and enhance Cloud Security monitoring using DataDog, including alert configuration and response procedures beyond out-of-the-box rules
- Implement and manage Just-in-Time (JIT) access solutions for elevated privilege access to cloud resources
- Establish and manage the cloud incident management process and lead incident response activities for cloud security events
- Collaborate with infrastructure and development teams to integrate cloud security best practices throughout the infrastructure lifecycle
- Research and evaluate emerging cloud security threats and vulnerabilities and develop effective mitigation strategies
- Develop and deliver cloud security training and awareness programs to engineering and relevant teams
- Contribute to the development and maintenance of cloud security standards, policies, and documentation
- Manage and drive continuous improvement of cloud security posture and strategic initiatives
- Accurately document cloud security configurations, processes, and knowledge and disseminate to other teams
- Conduct vulnerability assessments and drive remediation for cloud infrastructure
- Support requirements and evidence requested from auditors, compliance and regulators
Requirements
- Extensive experience in Cloud Security, with deep expertise in GCP
- Strong understanding of Threat Modelling principles and their application to cloud infrastructure and architectural designs
- Hands-on experience with cloud security tools and technologies, including DataDog for security monitoring and Terraform for Infrastructure as Code
- Proven experience in designing, implementing, and managing cloud security controls and configurations
- Experience with Identity and Access Management (IAM) in cloud environments, including implementation and management of Just-in-Time (JIT) access solutions
- Proven ability to establish and manage incident response programs specifically for cloud environments
- Proficiency in scripting or programming languages relevant to cloud automation and security (e.g., Python, Go, or similar) is a plus
- Comfortable explaining technical security concepts, vulnerabilities, and effective mitigations to diverse audiences
- Self-motivated and able to work independently and effectively in a remote setting while maintaining a team-focused mindset
- Highly skilled in documenting security processes and configurations and sharing knowledge with other teams
- Background experience in disruptive technology environments, ideally within FinTech, SaaS, or Crypto
- Relevant security certifications (e.g., GCP Professional Cloud Security Engineer - Specialty, CISSP, CISM) are a plus but not required
- Good understanding of cryptography and its applications in cloud security
- Contribution to the security community (e.g., open source projects, conference talks, CTFs)