Cloud Infrastructure Security Engineer
We are looking for a Cloud Infrastructure Security Engineer to help establish, automate, and continuously improve security controls across Google Cloud environments. This position focuses on cloud-native security architecture, policy automation, infrastructure governance, and secure-by-default deployments.
About the role
The ideal candidate will work closely with engineering, cloud security, CNAPP, sales, and customer-facing teams to develop scalable controls, troubleshoot complex infrastructure challenges, and strengthen the overall security and operational posture of Google Cloud environments.
Location: Phoenix, AZ (100% onsite). Candidates must currently reside within commuting distance. Relocation is not available. This is a 12+ month contract position.
Responsibilities
- Develop and maintain security controls across Google Cloud infrastructure, covering identity, networking, compute, storage, logging, monitoring, and other foundational cloud capabilities.
- Assess Google Cloud services and infrastructure patterns to establish appropriate security requirements, technical standards, operational procedures, and governance practices.
- Analyze existing security requirements and determine their suitability for automated enforcement through Policy as Code.
- Build and enhance Policy as Code capabilities using HashiCorp Sentinel and native cloud policy mechanisms.
- Integrate automated security policies and guardrails into Infrastructure as Code delivery workflows, particularly Terraform-based deployment pipelines.
- Partner with cloud security and CNAPP teams to strengthen preventive controls and establish secure-by-default configurations across cloud environments.
- Develop reusable policy frameworks that improve consistency, security, and governance throughout the infrastructure deployment lifecycle.
- Evaluate cloud-native services spanning compute, storage, data, communications, and emerging agentic AI workloads to understand their architectural and security implications.
- Investigate complex cloud infrastructure issues by reproducing customer-reported scenarios, analyzing underlying architectures, identifying root causes, and developing appropriate remediation or policy solutions.
- Review cloud architectures to support resilient, highly available environments while maintaining strong security controls and comprehensive operational visibility.
- Implement and evaluate controls related to network isolation, data protection, identity management, centralized logging, metrics, monitoring, and security analytics.
- Work with engineering teams to identify technical deployment challenges and provide practical solutions that align security requirements with business and operational needs.
- Serve as a technical advisor to internal engineering, sales, and customer organizations on Google Cloud infrastructure security and deployment requirements.
- Contribute to continuous improvement of cloud governance, automation, and security engineering practices.
- Stay current with emerging cloud technologies and rapidly adopt relevant capabilities to improve security, automation, and operational efficiency.
Requirements
- Bachelor's or Master's degree in Computer Science, Computer Engineering, or another technical discipline, or equivalent professional experience.
- 5 years of experience working with Google Cloud infrastructure and core capabilities such as IAM, VPC, Cloud Logging, security controls, storage, and compute services.
- 5 years of practical experience with Infrastructure as Code and automation technologies, particularly Terraform.
- Experience working with Policy as Code technologies such as HashiCorp Sentinel or comparable cloud-native policy frameworks.
- Experience designing and implementing automated security controls for cloud-native infrastructure.
- Strong understanding of Google Cloud architecture and its core services, including compute, storage, networking, data, and identity capabilities.
- Knowledge of cloud security concepts involving network isolation, data protection, identity and access management, logging, monitoring, and security visibility.
- Ability to assess cloud services and translate security requirements into enforceable technical controls and automated policies.
- Experience working with cloud infrastructure deployment pipelines and integrating security guardrails into Infrastructure as Code workflows.
- Programming or software development experience in at least one object-oriented or general-purpose language such as Java, Go, or Python.
- Ability to troubleshoot cloud infrastructure issues, reproduce technical scenarios, investigate underlying causes, and develop effective solutions.
- Strong understanding of high-availability cloud architectures and the relationship between resilience, security, and observability.
- Ability to understand technical requirements and business objectives and translate them into practical engineering solutions.
- Strong analytical, problem-solving, communication, and collaboration skills.
Preferred Qualifications
- Experience working with CNAPP platforms and cloud security posture management capabilities.
- Experience developing advanced Sentinel policies or native cloud policy controls at scale.
- Familiarity with FinOps concepts and cloud cost-management practices.
- Exposure to security requirements for data-intensive, telephony, communications, or AI-driven cloud workloads.
- Knowledge of agentic AI architectures and associated cloud infrastructure considerations.
- Experience working with XQL or comparable security analytics and query languages.
- Familiarity with enterprise cloud governance and automated compliance enforcement.
- Experience supporting customer-facing technical engagements or cloud security consulting.
- Understanding of Agile software development and engineering practices.
What We're Looking For
- A cloud security engineer who can combine infrastructure knowledge with practical security automation.
- Someone who can transform security requirements into scalable, enforceable policies and automated guardrails.
- An engineer who enjoys analyzing complex cloud architectures, troubleshooting difficult infrastructure problems, and determining effective root-cause solutions.
- A technically curious professional who can quickly understand emerging Google Cloud capabilities and evaluate their security implications.
- A collaborative subject matter expert who can work across engineering, security, sales, and customer organizations.
- A strong communicator who can translate complex technical requirements into clear and actionable solutions.
- A proactive problem-solver who continuously looks for opportunities to improve cloud security, automation, governance, and deployment efficiency.