Hybrid Cybersecurity Engineer III
Duration: 6+ months
Location: Silver Spring, MD
SUMMARY
-
The Cloud Security Engineer is a hands-on technical security professional responsible for designing, implementing, and operating cloud security controls across our public cloud environments, with a primary focus on Google Cloud Platform (GCP).
JOB RESPONSIBILITIES / TYPICAL DAY IN THE ROLE
-
Serve as a hands-on Cloud Security Engineer focused on securing enterprise-scale GCP environments.
-
Design, implement, and operate cloud vulnerability management processes across compute, container, serverless, and platform services.
-
Leverage and manage CSPM/CNAPP platforms (e.g., Wiz, Orca, Prisma Cloud) to identify misconfigurations, prioritize risk, and drive remediation efforts with engineering teams.
-
Develop automation and security tooling using Python (preferred) or similar scripting languages to improve detection, remediation, and reporting capabilities.
-
Partner with engineering and DevOps teams to integrate security controls into CI/CD pipelines and infrastructure-as-code workflows.
-
Review and harden GCP configurations, including IAM, networking, logging, storage, and container environments.
-
Support security assessments of AI/ML workloads and cloud-native data platforms; contribute to proof-of-concept initiatives related to AI/ML security where applicable.
-
Collaborate with cross-functional teams to remediate vulnerabilities identified through CSPM tools, scanners, and cloud-native security services.
-
Contribute to the development and maintenance of cloud security standards, configuration baselines, and operational documentation.
-
Support multi-cloud security initiatives, including AWS and Azure environments where required.
-
Stay current with emerging cloud threats, vulnerability trends, and advancements in cloud security tooling
o GCP Cloud Security Engineering & Hardening – 15%
o Cloud Vulnerability Management (analysis, prioritization, remediation coordination) – 30%
o CSPM/CNAPP Operations & Risk Reduction – 10%
o Security Automation & Python Development – 15% o CI/CD & DevSecOps Integration – 10%
o Architecture Reviews & Engineering Collaboration – 10%
o AI/ML & Emerging Technology Security Support – 5% o Documentation & Continuous Learning – 5%
MUST HAVE SKILLS / REQUIREMENTS
-
Strong knowledge and practical experience in Cloud Vulnerability Management
-
7+ years of experience; Vulnerability identification, prioritization, risk assessment, and remediation coordination across cloud workloads and services.
-
2) Demonstrated hands-on experience with AWS and GCP. a. 7+ years of experience; Cloud experience within a production environment.
-
3) Hands-on experience with at least one CSPM/CNAPP platform a. 3+ years of experience; (e.g., Wiz, Orca, Prisma Cloud, Lacework, or equivalent)
NICE TO HAVE SKILLS / PREFERRED REQUIREMENTS
-
Bachelor’s degree in Computer Science, Information Security, or related technical discipline, or equivalent practical experience.
-
Cloud security certifications such as:
-
GCP Professional Cloud Security Engineer
-
AWS Security Specialty or Solutions Architect c
-
Azure Security Engineer or Solutions Architect
-
Experience with AI/ML platforms and securing machine learning workloads; prior proof-of-concept or project experience is a plus.
-
Knowledge of AWS and/or Azure security services and architecture.
-
Familiarity with Oracle Cloud Infrastructure (OCI).
-
Experience integrating security tooling with platforms such as Slack, Jira, and CI/CD pipelines.
-
Experience with SIEM and observability platforms (e.g., Splunk).
-
Azure Experience is a plus.
-
Experience with Brinqa.
-
Excellent written and verbal communication skills with the ability to collaborate effectively with engineering and security stakeholders.
-
Demonstrated hands-on experience securing Google Cloud Platform (GCP) environments in production.
-
Strong knowledge and practical experience in Cloud Vulnerability Management, including vulnerability identification, prioritization, risk assessment, and remediation coordination across cloud workloads and services.
-
Hands-on experience with at least one CSPM/CNAPP platform (e.g., Wiz, Orca, Prisma Cloud, Lacework, or equivalent).
-
Proficiency in Python (preferred) or similar programming/scripting languages, with experience developing automation or security tooling.
-
Strong understanding of cloud IAM concepts, least-privilege access, and identity governance in GCP.
-
Solid understanding of cloud networking fundamentals, including VPC design, routing, segmentation, and secure connectivity patterns.
-
Experience securing containerized workloads and Kubernetes environments.
-
Familiarity with Infrastructure-as-Code (Terraform preferred) and secure configuration management practices.
-
Strong understanding of security principles, risk management, and compliance considerations in public cloud environments.