Impress employers and recruiters.
Choose from hundreds of resume examples.

Impress employers and recruiters.
Choose from hundreds of resume examples.
Tailor your resume to this Senior Cloud Security Engineer (GCP) - Engine by Starling role.
Rezi rewrites your resume against Starling's job description. Free.

Tailor your resume to this Senior Cloud Security Engineer (GCP) - Engine by Starling role.
Rezi rewrites your resume against Starling's job description. Free.
Don't guess if your resume is good enough.
See how it scores against the Senior Cloud Security Engineer (GCP) - Engine by Starling posting at Starling — free, in seconds.

Don't guess if your resume is good enough.
See how it scores against the Senior Cloud Security Engineer (GCP) - Engine by Starling posting at Starling — free, in seconds.
About the Role
Engine is Starling's software-as-a-service (SaaS) business, providing technology to leading banks worldwide. We empower banks to build rapid growth businesses on our platform, enabling them to benefit from innovative digital features and efficient back-office processes that have driven Starling's success. Our technologists work in a fast-paced, collaborative environment focused on building disruptive technology at the forefront of fintech. We foster an open culture where innovation, collaboration, and self-driven individuals who take ownership are core to our success.
Responsibilities
- Collaborate with stakeholders to define Google Cloud security architecture, including cloud identity, runtime security, and security posture.
- Design, document, build, and maintain a secure and scalable infrastructure on GCP using Infrastructure as Code.
- Safeguard systems, applications, and data by ensuring secure user access, authentication, and authorization mechanisms.
- Engineer and automate technical controls within GCP to ensure continuous compliance with standards like PCI DSS and 3DS.
- Drive security infrastructure deployments across growing environments.
- Perform security assessments, audits, threat modeling, and architecture design reviews to identify and mitigate risks and vulnerabilities.
- Lead incident response efforts, including investigation and remediation of security breaches.
- Support internal security awareness and training programs, advocating for the DevSecOps mindset.
Requirements
- Mature understanding of cloud security architecture with deep expertise in GCP and a proven track record.
- Experience creating a GCP landing zone, configuring services like organization policies and VPC Service Controls.
- Deep understanding of GCP IAM and its limitations.
- Experience with service-oriented architecture using containers, distributed systems, and immutable infrastructure on GCP (GKE, Compute Engine, Shared VPC, Cloud SQL).
- Expertise in Kubernetes, securing clusters (GKE) and meshes (Cilium preferable), networking best practices, and RBAC implementation.
- Experience with Infrastructure as Code and infrastructure provisioning tools, particularly Terraform.
- Experience configuring GCP-native security posture and threat management with Security Command Center.
- Experience securing the software supply chain with Binary Authorization, Artifact Registry, and Artifact Analysis.
- Experience with key and secret management on GCP (Cloud KMS, Cloud External Key Manager, Secret Manager), including cryptographic key ceremonies.
- Experience with Workload Identity and Workload Identity Federation for keyless authentication of workloads and CI/CD.
- Experience configuring and utilizing cloud-native security logging, monitoring, and detection services.
- Strong programming skills in Python, Go, and other languages for security automation and contributing to open-source tools.
- In-depth knowledge of security principles, technologies, best practices, and threat detection/mitigation strategies.
- Knowledge of common attack vectors and methodologies (OWASP Top 10, MITRE ATT&CK Framework, social engineering tactics).
- Ability to identify potential threats, attack vectors, and vulnerabilities in systems and applications.
- Ability to document security requirements from various stakeholders.
- Excellent problem-solving, communication, and active listening skills with a passion for security.
- Ability to identify security gaps and create solutions to minimize risk and impact.
- Proactive approach to staying updated with the latest security threats, vulnerabilities, and mitigation techniques.
- Thorough understanding of the incident response process (preparation, identification, containment, eradication, recovery, lessons learned).
Skills
- GCP
- GKE
- Kubernetes
- Terraform
- Security Command Center
- Binary Authorization
- Artifact Registry
- Artifact Analysis
- Cloud KMS
- Cloud External Key Manager
- Secret Manager
- Workload Identity
- Workload Identity Federation
- Python
- Go
- OWASP Top 10
- MITRE ATT&CK Framework
- PCI DSS
- 3DS
- Cilium
- CKA
- CKS
- Network security
- TCP/IP
- BGP
- VPNs
- Firewalls
- WAFs
- IDS/IPS
- Assured Workloads
- Access Transparency
- NIST
- SOC 2
- ISO 27001
- Sigstore
- Notary
- SAST
- DAST
- Cryptography management
- ISC2 CC
- CISSP
- CCSP
- CISM
- AWS Security Specialty
- GCP Professional Cloud Security Engineer
- Java
- AWS
- Microservice architecture
- EKS
- TeamCity
- Grafana
- RDS
- CloudSQL
- PostgreSQL
Location
- Hybrid
Work Type
- Hybrid Working
Experience Level
- Senior level
Benefits
- 33 days holiday (including public holidays)
- An extra day’s holiday for your birthday
- Annual leave increases with length of service
- Option to buy or sell up to five extra days off
- 16 hours paid volunteering time a year
- Salary sacrifice
- Company enhanced pension scheme
- Life insurance at 4x your salary
- Group income protection
- Private Medical Insurance with VitalityHealth (including mental health support and cancer care)
- Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton
- Generous family-friendly policies
- Incentives refer a friend scheme
- Perkbox membership (retail discounts, wellness platform)
- Access to initiatives like Cycle to Work
- Salary Sacrificed Gym partnerships
- Electric Vehicle (EV) leasing
About the Company
- Engine is Starling's software-as-a-service (SaaS) business, providing technology to leading banks worldwide.
- We empower banks to build rapid growth businesses on our platform, enabling them to benefit from innovative digital features and efficient back-office processes that have driven Starling's success.
- Our technologists work in a fast-paced, collaborative environment focused on building disruptive technology at the forefront of fintech.
- We foster an open culture where innovation, collaboration, and self-driven individuals who take ownership are core to our success.
- Our purpose is underpinned by five values: Listen, Keep It Simple, Do The Right Thing, Own It, and Aim For Greatness.
Equal Opportunity
- Engine by Starling is an equal opportunity employer, and we’re proud of our ongoing efforts to foster diversity & inclusion in the workplace.
- Individuals seeking employment at Engine by Starling are considered without regard to race, religion, national origin, age, sex, gender, gender identity, gender expression, sexual orientation, marital status, medical condition, ancestry, physical or mental disability, military or veteran status, or any other characteristic protected by applicable law.