Security Engineer (GCP | Threat Modelling | DevSecOps)
Location: Bengaluru, India (Hybrid)
Company: Arj Global Ltd
About the Role
Arj Global is looking for an experienced Security Engineer to strengthen our cyber security engineering capabilities. This role will focus on threat modelling, secure architecture, and cloud security (GCP) while also contributing to AI-driven automation initiatives to enhance internal security processes.
You will work closely with product, engineering, and architecture teams to embed Security & Privacy by Design (SPbD) across critical systems.
Key Responsibilities
🔹 Threat Modelling & Secure Design
- Perform threat modelling across applications and systems to identify risks early in the lifecycle
- Embed Security & Privacy by Design (SPbD) principles across 20–30 critical systems
- Conduct architecture reviews and provide secure design recommendations
🔹 GCP Cloud Security
- Provide expert guidance on securing Google Cloud Platform (GCP) environments
- Implement and review:
- IAM & access controls
- Data protection & encryption
- GKE (container security)
- Serverless security
- Security monitoring (SCC, logging, alerting)
🔹 Security Controls & Automation
- Implement foundational controls such as MFA, least privilege, encryption, vulnerability management
- Contribute to automation initiatives:
- Security controls as code
- Policy-as-code (OPA or similar)
- AI-driven security workflows
🔹 Risk & Vulnerability Management
- Conduct security assessments and risk analysis
- Identify vulnerabilities and drive remediation strategies
- Support continuous improvement of security posture
🔹 Stakeholder Engagement
- Collaborate with engineering, product, and architecture teams
- Facilitate security workshops and design reviews
- Drive adoption of secure development practices
🔹 Mentorship & Knowledge Sharing
- Act as a subject matter expert for security best practices
- Mentor engineering teams on secure coding and architecture
Required Skills & Experience
- 6–8 years of experience in Cloud Security, with strong focus on GCP
- Hands-on expertise with:
- GCP IAM, VPC Service Controls
- Cloud Armor, Security Command Center
- Cloud KMS, GKE security
- Strong experience in:
- Threat modelling methodologies
- Secure architecture & design
- DevSecOps / Security by Design practices
- Deep understanding of:
- Cloud security risks & attack vectors
- Defense-in-depth strategies
- Logging, monitoring, and incident response
- Experience implementing:
- Access control, vulnerability management, encryption
Qualifications
- Bachelor’s degree in Computer Science, Information Security, or related field
- Relevant certifications preferred:
- CISSP
- CISM
- OSCP
- or equivalent security certifications
What We’re Looking For
- Strong problem-solving mindset with hands-on technical depth
- Excellent communication and stakeholder management skills
- Ability to work in Agile, cross-functional environments
- Passion for building secure, scalable, cloud-native systems
Ref 281214

