Security Engineer (GCP & Threat Modelling)
Location: India (Bangalore preferred) | Remote with occasional travel
Experience: 6โ8 Years
Engagement: Contract / Consultant (Excellent rates)
At Arj Global, we are supporting enterprise clients in strengthening their cyber security posture across critical platforms. We are looking for a Security Engineer who will play a key role in threat modelling, secure architecture, and AI-driven security automation, ensuring security and privacy are embedded across systems from design to deployment.
Key Responsibilities
Security by Design & Engineering Collaboration
- Drive Security & Privacy by Design (SPbD) across 20โ30 business-critical systems
- Partner with product, engineering, and architecture teams to embed security early in the lifecycle
๐น GCP Security Expertise
- Provide hands-on expertise in securing Google Cloud Platform (GCP) environments
- Cover areas including IAM, data protection, GKE security, serverless, and monitoring
๐น Secure Architecture & Design Reviews
- Review cloud-native architectures and provide actionable security recommendations
- Ensure compliance with enterprise security policies and regulatory standards
๐น Security Controls & Automation
- Implement core security controls such as MFA, least privilege, encryption, and vulnerability management
- Contribute to automation initiatives like policy-as-code (OPA) and security tooling
๐น Risk & Vulnerability Management
- Conduct security assessments and threat modelling exercises
- Identify vulnerabilities and recommend remediation strategies for critical systems
๐น Stakeholder Engagement
- Work closely with engineering leads, product managers, and stakeholders
- Facilitate security workshops, reviews, and best practice adoption
๐น Mentorship & Knowledge Sharing
- Act as a security SME, mentoring teams and promoting secure development practices
Required Skills & Experience
- Bachelorโs degree in Computer Science, Information Security, or equivalent experience
- 6โ8 years of experience in cloud security with strong focus on GCP
- Deep expertise in GCP services such as:
- IAM, VPC Service Controls
- Cloud Armor, Security Command Center
- Cloud KMS, GKE Security
- Strong understanding of:
- Security by Design / DevSecOps principles
- Cloud security architecture and threat modelling
- Common attack vectors and defense strategies
- Experience implementing foundational controls:
- Access control, encryption, vulnerability management
- Logging, monitoring, and incident response
- Excellent stakeholder management and communication skills
Certifications (Preferred)
- CISSP / CISM / OSCP or equivalent security certifications

