Cloud Security Engineer
Quick Summary
5+ years of practical experience in Cloud Security Engineering, DevSecOps, Security Engineering, or a closely related discipline, including production environments.
This role offers the opportunity to establish and strengthen cloud security across a modern, cloud-native technology environment.
You will embed security directly into software development and delivery workflows, with a strong focus on DevSecOps and shift-left practices.
The position combines cloud security engineering, CI/CD security, vulnerability governance, container hardening, and infrastructure protection.
You will serve as a technical reference for engineering, SRE, and platform teams, influencing security standards without direct hierarchical authority.
The role requires balancing strong security controls with the speed and reliability expected from modern software delivery.
You will also contribute to production resilience, incident response, compliance, and the continuous improvement of cloud and software supply chain security.
- Integrate security controls into CI/CD pipelines, including SAST, SCA, container scanning, SBOM generation, and image signing and verification.
- Establish security practices that become part of the standard software delivery workflow rather than relying on manual controls at the end of the process.
- Evaluate, define, and lead the rollout of hardened container images using technologies and approaches such as Wolfi, Chainguard, and distroless images.
- Reduce attack surface and vulnerabilities in the base container images used by engineering teams.
- Lead vulnerability management and governance, including risk-based prioritization, remediation SLAs, and follow-up with engineering teams through resolution.
- Design and implement security controls across GCP infrastructure, including IAM, networking, Artifact Registry, and organization security policies.
- Work with Infrastructure as Code practices, particularly Terraform, to implement and maintain cloud security controls.
- Act as a technical security reference for engineering squads, promoting secure development and shift-left practices without unnecessarily slowing delivery.
- Collaborate with SRE teams on security-focused observability, runtime hardening, resilience, production security posture, and incident response.
- Conduct targeted penetration testing activities to validate security controls and remediation efforts alongside formal external penetration testing engagements.
- Support audits and compliance requirements related to CI/CD pipelines, vulnerability management, container images, and cloud security, including SOC 2 and PCI requirements.
- Establish and promote security standards that can be consistently adopted across technical teams.
Requirements
~2 min read- 5+ years of practical experience in Cloud Security Engineering, DevSecOps, Security Engineering, or a closely related discipline, including production environments.
- Strong hands-on knowledge of Google Cloud Platform, particularly IAM, networking, Artifact Registry, and organization-level security policies.
- Experience integrating security controls into CI/CD pipelines using GitLab CI, Jenkins, or similar technologies.
- Practical experience with vulnerability scanning tools such as Trivy, Snyk, Wiz, or comparable solutions.
- Strong production experience with Docker and Kubernetes, including multi-stage builds, runtime hardening, non-root execution, and dependency management.
- Knowledge of hardened and minimal container image ecosystems such as Wolfi, Chainguard, and distroless, or a strong willingness to develop deep expertise in these technologies.
- Solid scripting skills in Python and/or Bash for security automation and control implementation.
- Strong understanding of secure SDLC practices, OWASP Top 10, and basic threat modeling.
- Familiarity with SRE practices including observability, reliability, and incident response, with the ability to collaborate effectively with SRE teams.
- Strong technical communication skills and the ability to influence engineering teams without direct managerial authority.
- Experience with SBOMs, container image signing, cosign/Sigstore, and software supply chain security such as SLSA is an advantage.
- Experience with compliance frameworks such as SOC 2, PCI-DSS, or ISO 27001 is preferred.
- Previous experience in SRE, platform engineering, or infrastructure teams is beneficial.
- Certifications such as Google Professional Cloud Security Engineer, Certified Kubernetes Security Specialist (CKS), or equivalent are valued.
- Experience with Chainguard/Wolfi or other minimal-image ecosystems is a plus.
- Open-source contributions or published technical content related to DevSecOps or cloud security are advantageous.
What We Offer
~2 min readLocation & Eligibility
Listing Details
- Posted
- September 29, 2026
- First seen
- September 29, 2026
- Last seen
- September 29, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 68%
- Scored at
- September 29, 2026
Signal breakdown
Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.