Overview
As a Senior GCP Security Engineer, you will own the security foundations of Engine’s Google Cloud Platform. You collaborate with security, infrastructure, and product teams to design a secure cloud architecture and implement scalable, automated controls. You will drive continuous compliance (PCI DSS, 3DS) and lead incident response while championing a DevSecOps culture. This role sits at the heart of fast-paced fintech innovation, shaping secure infrastructure used by banks worldwide. You will work across IAM, networks, and hardened GKE clusters to protect data and services.
Pay / Benefits
- 33 days holiday including public holidays
- Birthday leave
- Private Medical Insurance with VitalityHealth
- Pension scheme
- Life insurance 4x salary
- Cycle to Work and EV leasing
Responsibilities
- Collaborate with stakeholders to define our Google Cloud security architecture (cloud identity, runtime security, security posture)
- Design, document, build and maintain a secure and scalable infrastructure on GCP using Infrastructure as Code
- Safeguard systems with secure user access, authentication and authorization mechanisms
- Engineer and automate technical controls in GCP to demonstrate compliance with PCI DSS and 3DS
- Drive security infrastructure deployments across growing environments
- Perform regular security assessments, audits, threat modelling and architecture design reviews
- Lead incident response efforts, including investigation and remediation of security breaches
- Support internal security awareness and DevSecOps mindset across technology teams
Key requirements
- Mature understanding of cloud security architecture with deep expertise in GCP
- Experience creating a GCP landing zone with organisation policies and VPC Service Controls
- Deep understanding of GCP IAM and its limitations
- Experience with containerised architectures on GCP (GKE, Compute Engine, Shared VPC, Cloud SQL)
- Expertise in Kubernetes security (GKE), RBAC, and network best practices
- Experience with Infrastructure as Code (Terraform)
- Experience with Security Command Center, Binary Authorization, Artifact Registry, and Secret Manager
- Experience with KMS, EKM, and cryptographic key management
- Experience with Workload Identity and Workload Identity Federation
- Experience with cloud-native security logging, monitoring, and detection
- Strong programming skills (Python, Go) for automation
- Good knowledge of OWASP Top 10 and MITRE ATT&CK
- Excellent problem-solving and communication skills
- Proactive security posture with threat awareness
- Incident response process knowledge
- Problem-solving
- Communication
- Active listening
- GCP security architecture
- GKE security and Kubernetes RBAC
- Terraform
…
