Live opening · Posted 11 hours ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
Job Title: Multi-Cloud Security & Compliance Engineer
Job Type: Full-Time
Location: Remote (U.S. based)
Clearance Requirement: U.S. Citizenship and Green card holder with the ability to obtain a clearance
Must be a US Citizen OR GC Holder Only
JOB DESCRIPTION
1. Position Overview
Seeking a Multi-Cloud Security & Compliance Engineer to secure Google Cloud Platform (GCP) and Oracle Cloud Infrastructure (OCI) environments. The role establishes and enforces a unified security posture, manages Zero Trust access boundaries, configures centralized security monitoring, and ensures cloud deployments meet stringent federal security and compliance requirements.
2. Key Responsibilities
Establish and enforce an integrated security posture across GCP and OCI, including security guardrails, standard configurations, and baseline controls.
Manage identity federation and implement IAM policies, role structures, least-privilege access, and segregation of duties across cloud environments.
Configure and operate centralized security monitoring to unify threat detection, vulnerability visibility, compliance tracking, logging, alerts, and telemetry.
Implement and maintain Zero Trust architectures and secure cloud landing zones.
Ensure cloud deployments align with FedRAMP HIGH, FISMA, NIST 800-53, and applicable security requirements.
Partner with security, governance, and audit teams to validate compliance throughout delivery lifecycle stages.
Identify vulnerabilities, policy deviations, and architectural risks and implement remediation actions.
Secure infrastructure-as-code and harden CI/CD pipelines using DevSecOps practices.
Translate regulatory frameworks and CIS Benchmarks into automated cloud security guardrails and operational controls.
3. Required Qualifications
Bachelor's degree in computer science, engineering, accounting/finance, information systems, or a technical discipline; 10 years of additional work experience may be considered in lieu of a degree.
5-10 years of experience in cloud security engineering, enterprise security architecture, or compliance programs.
Minimum 3 years of experience leading technical teams to achieve objectives and outcomes, including developing technical standards, recommending technology strategies, and providing technical direction.
Deep knowledge of GCP and OCI security services, IAM models, encryption, network security, and monitoring architecture.
Hands-on experience configuring cloud security tools such as Security Command Center, IAM federation, logging pipelines, and vulnerability-management solutions.
Experience with federal compliance frameworks such as NIST, FedRAMP, and FISMA.
Experience with multi-cloud governance programs, Zero Trust architectures, and regulated enterprise environments.
Familiarity with DevSecOps practices, infrastructure-as-code security, and CI/CD pipeline hardening.
Security/SecOps certification with a major cloud service provider.
Able to obtain Public Trust.
4. Preferred Qualifications
Active Public Trust (High-Risk) clearance.
Previous Federal Government experience.
One or more SecOps or Security certifications from Google, Oracle, AWS, or Azure.
Demonstrated experience implementing a unified security posture across GCP and OCI.
Experience implementing Zero Trust architectures, including Assured Workloads landing zones.
In-depth knowledge of FedRAMP, FISMA, and NIST 800-53.
Experience leading technical teams and ensuring compliance with security standards.
Experience with DevSecOps, CI/CD pipeline hardening, and secure infrastructure-as-code.
Expertise in identity federation and least-privilege IAM across multi-cloud deployments.
Hands-on experience with GCP Security Command Center and OCI Cloud Guard.
Experience translating CIS Benchmarks into automated cloud security guardrails.
Experience securing GKE, configuring GCP VPC Service Controls and OCI VCNs, securing cloud databases, and managing encryption keys with OCI Data Safe and Google/OCI KMS.
Threat hunting and vulnerability-management experience using SIEM and cloud-native scanning services.
5. Technical Requirements & Tool Proficiency
Build least-privilege access models and manage segregation of duties across cloud hierarchies.
Write, lint, and scan secure infrastructure templates before deployment.
Translate CIS Benchmarks, HIPAA, FISMA, and NIST 800-53 requirements into automated cloud guardrails.
Configure cloud-native logging, anomaly detection, and incident-response playbooks.
GCP: Organizations/Folders/Projects, Zero Trust, Assured Workloads, GKE security, VPC Service Controls, external IdP synchronization, Security Command Center, Cloud KMS/CMEK/HSM, SIEM/SecOps.
OCI: Compartments, VCNs and Security Lists, Maximum Security Zones, Autonomous Database security, IAM policies, Cloud Guard, Security Zones/Security Advisor, Vault, and Vulnerability Scanning Service.
Thank You
Work arrangement
Yes
More openings worth a look
Recently tracked roles with full details and direct application links.