DevSecOps Engineer
Cloud Security EngineerThis position is 100% remote. Candidates must be eligible to obtain a US Secret Clearance. Candidates need to live in either the Eastern or Central Time Zone. This role will be focused on implementing DevSecOps practices and working closely with our engineering team to secure our cloud environment. Your expertise in cloud security, infrastructure-as-code, and GRC oversight will be crucial in ensuring compliance, security, and operational integrity across our systems. Candidates that apply must have strong GCP and Terraform hands on experience.Key Responsibilities:Implement security controls and best practices in the GCP Cloud environmentEstablish GCP cloud governance frameworksWork with the engineering team and architects to ensure secure cloud architecture design and deploymentLead the preparation for third-party security assessments, specifically targeting compliance with industry security frameworks like NISTProvide hands-on expertise in implementing security solutions and integrating them throughout the development lifecycleDevelop, enhance, and maintain infrastructure-as-code setups using Terraform, ensuring efficient and secure deployment processesCollaborate with the team to create Terraform modules and reusable components for consistent and scalable infrastructure managementConduct code reviews and provide guidance on Terraform best practices to ensure high-quality infrastructure codeContribute to the enhancement and maintenance of infrastructure-as-code setups using TerraformSupport the team with security-related incidents and ensure continuous improvement of cloud security practicesUtilize GCP tools such as Cloud Security Command Center, Cloud Armor, and Forseti Security to enhance security postureImplement and manage GCP Identity and Access Management (IAM) policies and rolesLeverage GCP's VPC Service Controls to protect sensitive dataIdeal Candidate Qualifications:Experience in cloud security, with a focus on Google Cloud Platform (GCP) and exposure to AzureHands-on experience with security controls (e.g., DNS obfuscation, cross-cloud interconnects)Familiarity with infrastructure-as-code tools like TerraformExperience with compliance frameworks such as NIST and hands-on involvement with third-party security assessmentsAbility to work closely with engineers, architects, and other stakeholders to implement secure cloud solutionsStrong problem-solving skills and a proactive approach to security engineering tasks