Search by job, company or skills

Cloud Security Engineer(Azure & GCP)

Early Applicant
  • Posted 4 days ago
  • Be among the first 10 applicants

Job Description

Job Summary

We are looking for a hands-on Cloud Security Architect with strong engineering expertise in securing enterprise workloads across Microsoft Azure and Google Cloud Platform (GCP). This is an implementation-focused role requiring extensive experience configuring cloud-native security services, automating security controls, and securing cloud infrastructure using Infrastructure as Code (IaC).

The ideal candidate should possess equal hands-on expertise in Azure and GCP, be proficient in Terraform, and work closely with Platform Engineering, DevOps, and Product teams to build secure, scalable cloud environments.

Key Responsibilities Cloud Security Engineering

  • Configure and manage Microsoft Defender for Cloud (Servers, Containers, Storage, Key Vault, DNS, Resource Manager).
  • Implement and manage Azure Firewall, Network Security Groups (NSGs), Azure WAF, Private Link, and Private Endpoints.
  • Administer Azure Key Vault, certificate lifecycle, and workload integration.
  • Configure Microsoft Entra ID (Azure AD) including Conditional Access, Privileged Identity Management (PIM), RBAC, Workload Identities, and Service Principal security.
  • Manage Google Security Command Center (SCC), including Security Health Analytics, Event Threat Detection, and Container Threat Detection.
  • Design and secure GCP VPC architectures, firewall rules, Shared VPC, Private Google Access, and VPC Service Controls.
  • Secure BigQuery environments using row/column-level security, authorized views, data masking, and VPC Service Controls.
  • Harden Cloud Run deployments with ingress controls, Binary Authorization, service identities, and secret management.
  • Implement and manage GCP IAM, custom roles, Organization Policies, Workload Identity Federation, and service account governance.

Cloud Security Architecture

  • Design and evolve enterprise cloud security architecture across Azure and GCP.
  • Evaluate security implications of new cloud services before adoption.
  • Ensure compliance with ISO 27001, ISO 27017, GDPR, and SOC 2.
  • Collaborate with Microsoft and Google technical teams on security best practices.
  • Monitor cloud security posture using Secure Score, Defender for Cloud, and Google SCC dashboards.

Automation & DevSecOps

  • Develop reusable Terraform modules for Azure and GCP security configurations.
  • Automate security provisioning using Infrastructure as Code.
  • Integrate security scanning into CI/CD pipelines, including:
    • Infrastructure as Code scanning
    • Container image scanning
    • Dependency vulnerability scanning
  • Implement Policy-as-Code using Azure Policy, GCP Organization Policies, OPA, Sentinel, Checkov, and tfsec.
Collaboration

  • Partner with DevOps and Product Engineering teams to implement security controls.
  • Design scalable IAM models and enforce least-privilege access.
  • Support Security Champion initiatives and internal cloud security knowledge sharing.
  • Translate security requirements into practical engineering solutions.

Required Skills Mandatory

  • 5+ years of hands-on experience securing Microsoft Azure environments.
  • 3+ years of hands-on experience securing Google Cloud Platform (GCP) environments.
  • Strong expertise with:
    • Microsoft Defender for Cloud
    • Azure Firewall
    • Azure WAF
    • Azure Key Vault
    • Microsoft Entra ID
    • Azure Monitor / Microsoft Sentinel
    • Google Security Command Center (SCC)
    • GCP IAM
    • VPC Networking
    • Organization Policies
    • BigQuery Security
    • Cloud Run Security
  • Strong experience with Terraform for Azure and GCP.
  • Experience triaging and remediating findings from Defender for Cloud and Google SCC.
  • Expertise in cloud networking security:
    • Firewalls
    • Private Connectivity
    • DNS Security
    • DDoS Protection
  • Strong knowledge of Identity & Access Management:
    • RBAC
    • Conditional Access
    • Workload Identity
    • Service Account Governance
  • Experience securing Kubernetes environments (AKS/GKE) and container workloads.
Preferred Skills

  • Microsoft Sentinel or Google Chronicle.
  • Azure DDoS Protection.
  • Azure Front Door WAF.
  • Google Cloud Armor.
  • Azure Confidential Computing.
  • GCP Assured Workloads.
  • Policy-as-Code frameworks:
    • OPA
    • Sentinel
    • Checkov
    • tfsec
Certifications (Preferred)

  • Microsoft Certified: AZ-500
  • Microsoft Certified: SC-100
  • Google Professional Cloud Security Engineer

Skills: cloud security,azure,gcp

More Info

Job Type:
Industry:
Employment Type:

About Company

Job ID: 151459619