← Back to jobs

E-Solutions Logo
Lead Security Engineer

E-Solutions

 

San Jose, CA, USA

Posted On: 3 days ago
Experience: 7+ years
Availability: Onsite
Openings: 1
Category: Security Engineer
Tenure: Contract - Corp-to-Corp
Related Jobs

No related jobs found

Description

Key Responsibilities

• Technical Leadership & Translation: Lead discovery workshops to deconstruct FedRAMP KSIs and NIST SP 800-53 controls, translating high-level compliance mandates into binary, automatable technical specifications.

• Vulnerability Management & Pipelines: Oversee and implement VM vulnerability scanning (AutoVM, Tenable, Qualys, Nessus), container image scanning (Artifact Registry / Drydock), and static/dynamic analysis tools.

• Automation & Scripting: Analyze Google Cloud Asset Inventory (CAI) schemas and oversee the authoring and testing of Common Expression Language (CEL) evaluation rules to define precise Pass/Fail criteria for cloud controls.

• Pipeline & Telemetry Architecture: Design, deploy, and troubleshoot log agents (Fluentbit/Vector) and Cloud Logging sinks to ensure 100% telemetry coverage across container nodes, VMs, and control-plane APIs.

• Identity & Access Management (IAM): Architect and enforce least-privilege IAM bindings, service accounts, and VPC Service Controls across the GCP environment.

• Validation & Deployment: Test logic against synthetic resources in sandbox environments to minimize false positives, manage codebase version control (Git/Piper), and support progressive deployment rollouts.

• Cross-Functional Collaboration: Act as the technical bridge for the project, supporting gap analyses and providing engineering evidence to Governance teams and 3PAO assessors.

 

Qualifications & Requirements

• Experience: 7+ years in Cloud Security Engineering, DevSecOps, or Infrastructure Security, with proven experience as a Lead/Senior Engineer managing FedRAMP (Moderate/High) security vulnerability implementations.

• Cloud Platform Expertise: Strong, hands-on background in Google Cloud Platform (GCP), specifically with Cloud Asset Inventory (CAI), Security Command Center (SCC), IAM, Cloud Audit Logs, and Cloud Storage.

• Scripting & Languages: Advanced proficiency in Common Expression Language (CEL). Working knowledge of Python, Go, or Rego/OPA.

• Vulnerability Tooling: Practical experience configuring and automating vulnerability and container scanning tools in a large-scale cloud environment.

• Systems & Infrastructure: Experience with Google Cloud infrastructure and container orchestration (Kubernetes/GKE/Borg).

• Compliance Knowledge: Strong familiarity with automated control evaluation for NIST SP 800-53 Rev 5, CIS Benchmarks, and FedRAMP Continuous Monitoring (ConMon).

• Education: Bachelor’s or Master’s degree in Computer Science, Information Technology, Cybersecurity, or equivalent practical experience

Education

Bachelor's or Master's degrees

Related Jobs

No related jobs found

← Back to jobs