waypointjobs

KPG99 INC

Security Engineer

new york, NY

Check who can apply and the requirements below before continuing.

About this opportunity

KPG99 INC lists this Security Engineer opportunity in new york, New York. Review the employer’s description below for duties, qualifications and application requirements.

Job description

Requirement Notes (Candidate Job description below) : We are looking for a Senior (5+ years) GCP Security Engineer who lives on GCP and can own the security architecture end-to-end, not just advise on it. You will design guardrails, write Terraform, integrate with Harness CI/CD pipelines, and partner with engineering teams to ensure every resource deployed is secure by default. This role is GCP-first. Familiarity with AWS and Azure is a plus, but your day-to-day will be deep in Google Cloud: securing GKE workloads, governing AI pipelines on Vertex AI, managing identities via ICAM, and using native GCP security services to detect and respond to threats.

**** THE MANAGER WOULD LIKE TO SEE CERTIFICATIONS.

Must Have:

Experience with GCP security services including IAM, VPC Service Controls, Cloud Armor, KMS, Secret Manager, DLP, and SCC.

Strong Elastic SIEM experience including log ingestion, detection engineering, alert management, and threat correlation.

Production-level Terraform experience including module development, infrastructure automation, and state management.

Strong knowledge of Kubernetes and GKE security including pod security admission, network policies, Workload Identity, and Binary Authorization.

MANAGERS NOTES:

Looking for a Security-focused GCP Engineer

Risk/Compliance

Not DevOps or Logging

Must be fully hands-on developing

Should not rely on AI to assist with development

Job Description:

CANDIDATES MUST COMMIT TO A FINAL IN PERSON, ONSITE INTERVIEW (TRAVEL PAID BY THE CLIENT).

We are looking for a Senior GCP Security Engineer who lives on GCP and can own the security architecture end-to-end, not just advise on it. You will design guardrails, write Terraform, integrate with Harness CI/CD pipelines, and partner with engineering teams to ensure every resource deployed is secure by default. This role is GCP-first. Familiarity with AWS and Azure is a plus, but your day-to-day will be deep in Google Cloud: securing GKE workloads, governing AI pipelines on Vertex AI, managing identities via ICAM, and using native GCP security services to detect and respond to threats.

What You'll Bring:

5+ years of experience in cloud security, with the majority focused on GCP environments.

Deep hands-on experience with GCP security services including IAM, VPC Service Controls, Cloud Armor, KMS, Secret Manager, DLP, and SCC.

Strong Elastic SIEM experience including log ingestion, detection engineering, alert management, and threat correlation.

Production-level Terraform experience including module development, infrastructure automation, and state management.

Experience integrating security controls into CI/CD pipelines using Harness or equivalent platforms.

Strong knowledge of Kubernetes and GKE security including pod security admission, network policies, Workload Identity, and Binary Authorization.

Hands-on experience with ICAM or enterprise identity platforms governing non-human identities and workload access.

Practical knowledge of AI/ML security including Vertex AI workload protection, LLM API governance, and training data security.

Preferred Qualifications

Google Professional Cloud Security Engineer or Professional Cloud Architect certification.

Experience with policy-as-code tooling such as OPA/Rego, Sentinel, or Checkov.

Familiarity with AWS security services including IAM, GuardDuty, SCPs, and multi-cloud security architectures.

Experience with Cribl Stream or similar log routing technologies integrated with Elasticsearch.

Understanding of compliance-driven security requirements including NY DFS 23 NYCRR 500, NAIC, NIST CSF, CIS Benchmarks, and ISO 27001.

Working knowledge of enterprise identity platforms including SailPoint, CyberArk, Ping Identity, Active Directory, and LDAP.

Experience securing AI agent frameworks such as LangChain or Vertex AI Agent Builder.

Primary Technology Stack:

Infrastructure as Code: Terraform (required), Harness CI/CD, ICAM

Identity: GCP Workload Identity Federation, service account governance, ICAM, SailPoint, CyberArk, Ping Identity, Active Directory, LDAP

AI/ML: Vertex AI Agent Builder, Gemini APIs, BigQuery ML, RAG pipelines

Secondary: AWS (IAM, GuardDuty, Bedrock), Azure (familiarity acceptable)

#J-18808-Ljbffr

Worksite address

new york, NY, 10261, US

Who can apply

Review the original listing for work authorization, qualifications and employer requirements.

Ready for your next step?Apply on the official website
Apply on WhatJobs ↗

Explore related searches

Current related jobs

American Honda Motor Co., Inc.

WhatJobs

Senior Product Quality & Root Cause Engineer

haw river, NC

Salary not specified

What Makes a Honda, is Who makes a Honda Honda has a clear vision for the future, and it’s a joyful one.  We are looking for individuals with t…

Listing review due 2026-10-06View job

Avantor

WhatJobs

Process Engineer

carpinteria, CA

See pay details in description

The Opportunity: NuSil (apart of Avantor) is seeking a Process Engineer to be responsible for all phases of silicone products manufacturing…

Listing review due 2026-10-06View job

GE Vernova

WhatJobs

Lead Application Engineer

boston, MA

See pay details in description

Job Description Summary The Lead Application Engineer is an established leader in their respective engineering team. They will drive busine…

Listing review due 2026-10-06View job