Source description
About the role
Job Title: Platform Compliance & Security Engineer Location: Jersey City, NJ (Onsite) Duration: 12+Months Contract Primary Skillset: GCP, Python, Terraform, Security Secondary Skillset: Encryption/Decryption, Security Command Center, Data Protection, Data Sensitivity, Data Categorization, Key Management Job Summary: We are looking for a GCP Platform Compliance & Security Engineer to drive security governance, data protection, and regulatory compliance across Google Cloud Platform environments. This role combines deep GCP security expertise with hands-on proficiency in Python, Terraform, and cloud-native security tooling to implement robust controls across encryption, key management, and data classification frameworks. The ideal candidate will work closely with data, platform, and engineering teams to enforce security policies, manage sensitive data lifecycles, and ensure continuous compliance with industry standards such as ISO 27001, SOC 2, PCI-DSS, and GDPR — all while maintaining operational agility on Google Cloud. Key Responsibilities • Define, implement, and enforce cloud security policies across GCP using Organization Policies, IAM constraints, and VPC Service Controls to ensure consistent compliance posture across all projects and environments. • Design and manage encryption strategies for data at rest and in transit using Google Cloud KMS, Customer-Managed Encryption Keys (CMEK), and Customer-Supplied Encryption Keys (CSEK), ensuring adherence to key rotation and lifecycle policies. • Operate and configure GCP Security Command Center to identify threats, misconfigurations, and vulnerabilities across the platform; triage findings and drive remediation workflows with relevant engineering teams. • Implement data protection controls using Cloud DLP (Data Loss Prevention) APIs to detect, classify, and redact sensitive information (PII, PCI, PHI) across GCP storage, databases, and data pipelines. • Establish and maintain enterprise-wide data classification taxonomy (Public, Internal, Confidential, Restricted), tag GCP resources accordingly, and automate classification enforcement through Python-based tooling and Terraform. • Continuously monitor GCP environments for compliance against frameworks such as CIS GCP Benchmarks, NIST, ISO 27001, and SOC 2, generating audit-ready reports and evidence packages using Cloud Audit Logs and SCC findings. • Embed security controls into Terraform IaC templates by enforcing secure defaults, conducting static analysis with tools like tfsec or Checkov, and integrating security gates into CI/CD pipelines. • Design and govern least-privilege IAM architectures across GCP, manage service account hygiene, implement Workload Identity Federation, and enforce just-in-time access patterns for privileged operations. • Coordinate vulnerability assessments, manage Container Vulnerability Scanning (Artifact Registry), and lead threat modeling exercises for new platform capabilities to proactively address security risks. • Lead security incident response activities for GCP-hosted workloads, conduct forensic investigation using Cloud Logging and Chronicle, and drive post-incident reviews to improve platform security controls. Must-Have Skills • Deep hands-on experience with GCP security services including Cloud KMS, Security Command Center, Cloud DLP, VPC Service Controls, Cloud Armor, Binary Authorization, and Chronicle. • Strong Python skills applied to security automation — writing scripts for compliance checks, DLP policy enforcement, auto-remediation, and integrating GCP APIs for security event processing. • Proven ability to write secure Terraform configurations, enforce security policies via code, and integrate static analysis tools (tfsec, Checkov) into CI/CD pipelines for GCP deployments. • In-depth knowledge of symmetric/asymmetric encryption, GCP Cloud KMS key hierarchies, CMEK/CSEK implementation, envelope encryption patterns, and HSM-backed key operations. • Hands-on experience with Cloud DLP for sensitive data discovery, classification schema design (PII/PCI/PHI), data masking/tokenization techniques, and enforcement of data handling policies. • Working knowledge of CIS GCP Benchmarks, NIST 800-53, ISO 27001, SOC 2 Type II, PCI-DSS, and GDPR requirements as they apply to cloud infrastructure and data management practices. • Expertise in GCP IAM design, service account management, Workload Identity Federation, Organization Policy constraints, and implementing least-privilege access models at scale.
More at Thoughtwave Software and Solutions