At a Glance
- Tasks: Enhance GCP security controls and develop security guardrails for a major banking transformation.
- Company: Leading financial services organisation with a focus on innovation and security.
- Benefits: Competitive daily rate, hybrid work model, and opportunity to work on impactful projects.
- Other info: Initial 6-month contract with excellent career growth potential.
- Why this job: Join a dynamic team and strengthen cloud security in a regulated environment.
- Qualifications: Strong GCP security experience and knowledge of IAM and policy-as-code tools.
My client, a leading financial services organisation, is looking for a GCP Security Engineer to support a major banking transformation programme, focusing on cloud security controls, IAM risk, and threat-based reporting within Google Cloud. This role sits within a wider security architecture and risk function, helping implement security guardrails, controls and reporting frameworks across the GCP environment. This will be Inside Ir35, Hybrid London (2/3 days a week), and ideally circa £575+ per day for an initial 6 months.
Key Responsibilities for the GCP Security Engineer
- Implement and enhance GCP security controls across IAM, network and data layers
- Support development of security guardrails using policy-as-code tools (Sentinel / Prisma / OPA etc)
- Improve security metrics, dashboards and threat-based reporting
- Strengthen Identity & Access risk visibility across GCP environments
- Support integration of multiple security domains (Data Leakage, IAM, vulnerability posture) into a unified reporting framework
- Map controls and threats using MITRE ATT&CK framework
Required Experience
- Strong Google Cloud Platform (GCP) security experience
- Experience implementing cloud security controls
- Knowledge of IAM, identity governance, privileged access
- Experience working in regulated environments (banking, fintech, insurance etc)
- Exposure to policy-as-code / guardrails tools (Prisma Cloud, Hashicorp Sentinel, OPA, Terraform policies)
- Understanding of MITRE ATT&CK framework
GCP Security Engineer employer: Norton Blake
Contact Detail:
Norton Blake Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land GCP Security Engineer
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can refer you directly.
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repository showcasing your GCP security projects. This gives potential employers a tangible look at what you can do and sets you apart from the crowd.
✨Tip Number 3
Prepare for interviews by brushing up on common GCP security scenarios and challenges. Practice articulating how you've tackled similar issues in the past, especially around IAM and threat-based reporting.
✨Tip Number 4
Don't forget to apply through our website! We’ve got loads of opportunities that might be perfect for you. Plus, it’s a great way to ensure your application gets seen by the right people.
We think you need these skills to ace GCP Security Engineer
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the GCP Security Engineer role. Highlight your experience with Google Cloud Platform security, IAM, and any relevant tools like Prisma or Sentinel. We want to see how your skills match what we're looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about cloud security and how your background fits into our banking transformation programme. Keep it concise but impactful – we love a good story!
Showcase Relevant Projects: If you've worked on projects that involved implementing security controls or using policy-as-code tools, make sure to mention them. We’re keen to see real-world examples of your expertise in action, especially in regulated environments.
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you don’t miss out on any important updates. Plus, we love seeing applications come in through our own channels!
How to prepare for a job interview at Norton Blake
✨Know Your GCP Security Basics
Before the interview, brush up on your knowledge of Google Cloud Platform security controls. Be ready to discuss IAM, network security, and data protection measures. Familiarity with tools like Prisma and Sentinel will show that you’re not just a theoretical expert but someone who can apply this knowledge practically.
✨Showcase Your Experience with Policy-as-Code
Prepare specific examples of how you've implemented policy-as-code in previous roles. Discuss any challenges you faced and how you overcame them. This will demonstrate your hands-on experience and problem-solving skills, which are crucial for the role.
✨Understand the MITRE ATT&CK Framework
Make sure you can explain how the MITRE ATT&CK framework applies to cloud security. Be prepared to discuss how you would map controls and threats using this framework in a GCP environment. This shows that you have a strategic approach to security.
✨Prepare Questions About the Role
Think of insightful questions to ask about the company's security architecture and risk function. This not only shows your interest in the role but also helps you gauge if the company’s approach aligns with your values and expertise.