Senior Google Cloud Security Consultant
Job description
About the role
The is a pivotal role focused on guiding organizations through the complete lifecycle of securing their Google Cloud infrastructure. You will partner with enterprise clients, translating high-level business risk and strict compliance mandates into coherent, long-term security strategies that scale. This position owns the design of robust security architectures, the implementation of stringent controls, and the optimization of environments to ensure they are resilient and efficient. You will act as a primary technical resource, bridging the gap between executive expectations and the technical execution required in the cloud. A significant portion of the role involves hands-on evaluation of current environments to identify gaps that could lead to exposure or misconfiguration. You will automate repetitive security tasks and enforce consistent policy application to reduce manual overhead and improve the overall security posture. Collaboration is essential, requiring close coordination with engineering and delivery teams to integrate security seamlessly into the development lifecycle and DevOps pipelines. The role also involves distilling intricate technical topics into concise briefings for both technical teams and executive leadership. Ultimately, you will contribute to the maturation of security operations, embedding practices that promote continuous enhancement and long-term success.
Key facts
What you'll do
- Perform scoping and discovery activities to fully understand client business objectives, existing technology landscapes, and specific security requirements for Google Cloud initiatives.
- Design and implement security architectures for Google Cloud environments, ensuring alignment with industry best practices, regulatory requirements, and client business needs.
- Evaluate and analyze current security postures, identifying vulnerabilities, misconfigurations, and gaps that could lead to potential exposure or compliance failures.
- Develop and implement security frameworks and controls specifically tailored for the Google Cloud Platform, focusing on identity, access management, data protection, and network security.
- Automate security processes and workflows using infrastructure-as-code methodologies to enforce consistent policy application and reduce manual overhead across large-scale environments.
- Conduct detailed assessments against major compliance frameworks, translating complex requirements into actionable checklists and implementation guidance for clients.
- Provide clear direction and guidance regarding secure configurations, reviewing designs and verifying that implementations adhere to established benchmarks and organizational standards.
- Distill complex technical and security topics into concise briefings and documentation for both technical teams and executive leadership, ensuring clarity and alignment.
- Advise on future technology adoption and roadmap development, helping to shape the client's long-term vision for cloud security and operational maturity.
- Collaborate closely with engineering and delivery teams to integrate security seamlessly into the development lifecycle, fostering a culture of shared responsibility.
- Support the creation of audit-ready documentation, including artifacts that justify architectural choices and demonstrate compliance with regulatory requirements.
- Monitor the threat landscape and emerging risks specific to cloud environments, proactively recommending adjustments to security strategies and controls.
- Lead workshops and knowledge transfer sessions, empowering client teams with the skills needed to maintain and evolve their security posture independently.
- Drive continuous improvement initiatives, identifying opportunities to enhance security operations, streamline processes, and leverage automation for greater efficiency.
- Act as a subject matter expert within the Coalfire team, contributing to the development of methodologies, tools, and frameworks that improve delivery quality.
Requirements
- Must have a proven track record of 3-5 years focused specifically on cloud infrastructure protection within Google Cloud environments.
- Must possess a deep understanding of the native security and identity services available within the Google Cloud Platform, including IAM, Cloud Security Command Center, and Cloud Key Management Service.
- Must demonstrate extensive knowledge of major compliance frameworks such as SOC 2, ISO 27001, GDPR, HIPAA, and PCI DSS, and their application to cloud controls.
- Must be capable of explaining complicated technical and security concepts in a clear manner that resonates with varied audiences, from technical engineers to executive leadership.
- Must have direct experience in advisory and assessment-based projects, including risk assessments, gap analyses, and compliance validation activities.
- Must be proficient in using the Google Cloud console, command-line tools, and common infrastructure-as-code tools such as Terraform or Deployment Manager.
- Must be comfortable working independently and effectively within distributed teams across different time zones, managing workload without direct supervision.
- Must hold current knowledge of security frameworks, risk management principles, and the application of security controls within cloud-native environments.
- Must be able to manage multiple priorities simultaneously, balancing the demands of client deliverables, project timelines, and quality expectations.
Nice to have
- Preferred experience with specific security frameworks, risk assessments, and compliance validation processes.
- Familiarity with security operations center (SOC) models and security monitoring practices.
- Background in DevOps practices and the integration of security within CI/CD pipelines.
Practical notes
This position is based in the United States and requires regular full-time availability. Travel is not expected as part of this role, and it is not eligible for visa sponsorship.