Overview
In this GCP Security Engineer role, you will own the security foundations of Engine’s Google Cloud Platform environment. You’ll collaborate with cross-functional teams to shape a secure cloud architecture and automate risk controls. The position focuses on identity, access, compliance, and secure deployment practices to protect systems, data, and customers. You will lead incident response and drive a DevSecOps culture, enabling scalable, secure innovation for a fintech audience.
Pay / Benefits
- 33 days holiday
- Birthday leave
- Pension scheme
- Private Medical Insurance with VitalityHealth
- Life insurance 4x salary
- Mental health support and cancer care
Responsibilities
- Define and maintain GCP security architecture (cloud identity, runtime security, posture)
- Design, document, and build secure, scalable GCP infrastructure using Infrastructure as Code
- Ensure secure access, authentication, and authorization across systems
- Automate security controls to demonstrate continuous PCI DSS and 3DS compliance
- Drive security infrastructure deployments across growing environments
- Perform security assessments, threat modelling, and architecture reviews to identify risks and implement controls
- Lead incident response activities including investigation and remediation
- Support security awareness and DevSecOps adoption across engineering teams
Key requirements
- Mature understanding of cloud security architecture with deep GCP expertise
- Experience building a GCP landing zone and configuring organisation policies and VPC Service Controls
- Strong GCP IAM knowledge and limitations awareness
- Experience with GCP containers and services (GKE, Compute Engine, Shared VPC, Cloud SQL)
- Kubernetes security (GKE), RBAC, and network security best practices
- Proficiency with Infrastructure as Code (Terraform)
- Experience with Security Command Center and cloud-native security logging/detection
- Experience with Binary Authorization, Artifact Registry, and Artifact Analysis
- Key/secret management on GCP (Cloud KMS, EKM, Secret Manager) including key ceremonies
- Workload Identity and Workload Identity Federation for keyless auth of workloads/CI/CD
- Scripting in Python/Go for automation; contribute to open-source tools
- Knowledge of attack vectors and threat frameworks (OWASP Top 10, MITRE ATT&CK)
- Incident response process understanding and experience
- Excellent problem-solving, communication, and active listening skills
- Proactive security threat awareness and mitigation techniques
- Experience in secure software supply chain and CI/CD security practices
- problem-solving
- communication
- active listening
- GCP security architecture
- Terraform
- GKE security
…
