2 months ago
Manila, PhilippinesSenior
Responsibilities
- Architect and implement GCP security controls across projects, folders, and organization-level policies.
- Design and manage IAM, workforce identity federation, service account governance, Workload Identity, and organization policy constraints.
- Implement VPC Service Controls, Private Google Access, Cloud Armor, firewall policies, data security, and zero-trust access controls.
- Integrate security tooling into GCP-native CI/CD pipelines and Terraform infrastructure-as-code workflows.
- Conduct threat modeling and security assessments for GCP-hosted financial workloads.
- Support audits and regulatory reviews, monitor GCP security posture, and communicate relevant GCP and threat-landscape changes to stakeholders.
Requirements
- 6+ years of information security experience, including 3+ years focused on GCP security in enterprise or regulated environments.
- Expertise with GCP security services including SCC, IAM, VPC Service Controls, Cloud Armor, KMS, DLP, and Chronicle.
- Hands-on experience with Terraform for GCP infrastructure security automation and strong Python skills for security tooling and automation.
- Knowledge of financial-services compliance requirements, cloud-native threat vectors, MITRE ATT&CK for Cloud, and detection engineering.
- Bachelor's degree in Computer Science, Cybersecurity, or a related field, or equivalent experience.
- Google Professional Cloud Security Engineer certification is strongly preferred.
- Google Professional Cloud Architect certification and certifications such as CISSP, CCSP, CISM, GCIA, or GCSA are preferred.
- Experience securing Google Workspace in enterprise financial services and familiarity with Apigee API security and Cloud Endpoints are preferred.
