Sr. GCP Security Engineer
Job Description
Architect and implement end-to-end GCP security controls across projects, folders, and organization-level policiesDesign and manage IAM strategy: workforce identity federation, service account governance, Workload Identity, and organization policy constraintsImplement and manage VPC Security Controls — VPC Service Controls, Private Google Access, Cloud Armor, and firewall policiesLead data security strategy as well as zero-trust access controls for internal applications and services hosted on GCPIntegrate security tooling into GCP-native CI/CD pipelines (Cloud Build, Artifact Registry) and Infrastructure as Code (Terraform)Conduct threat modeling and security assessments for GCP-hosted financial workloadsSupport audit and regulatory reviews as well as monitor GCP security postureStay current with GCP releases and the evolving FSI threat landscape; communicate relevant changes to stakeholders
Qualification
6+ years of information security experience, with 3+ years focused on GCP security in enterprise or regulated environmentsExpert-level proficiency with GCP security services: SCC, IAM, VPC Service Controls, Cloud Armor, KMS, DLP, ChronicleHands-on experience with Terraform for GCP infrastructure security automationStrong command of Python for security tooling and automationKnowledge of financial services compliance requirementsDeep understanding of cloud-native threat vectors, attack techniques (MITRE ATT&CK for Cloud), and detection engineeringBachelor's degree in Computer Science, Cybersecurity, or related field (or equivalent experience)Preferred QualificationsGoogle Professional Cloud Security Engineer certification — strongly preferredGoogle Professional Cloud Architect certificationCertifications: CISSP, CCSP, CISM, GCIA, or GCSAExperience securing Google Workspace in an enterprise financial services contextFamiliarity with Apigee API security and Cloud Endpoints for financial API gateways
About The Global Business Services
A dynamic offshore hub based in the Philippines, serving as a vital extension of its parent organization’s operations. As an internal support center, it delivers high-impact services across multiple departments, including technology, compliance, finance, and operations, supporting various lines of business.