Federal Express Corporation is seeking a Cloud Network Security Engineer to design and maintain secure cloud network architectures within Google Cloud Platform. The role involves deploying network security services, automating infrastructure, and ensuring compliance with security standards while collaborating with various teams.
Responsibilities:
- Design, implement, and maintain highly secure cloud network architectures within Google Cloud Platform (GCP), adhering to Zero Trust principles and organizational security standards
- Deploy, configure, and manage core GCP network security services, including Cloud Next-Generation Firewalls (NGFW), VPC Service Controls (VPC SC), Cloud Intrusion Detection Systems (Cloud IDS), and Cloud Armor
- Lead the automation of network security infrastructure deployment using IaC tools (primarily Terraform). Build and maintain reusable modules for secure baseline configurations
- Implement and tune logging and monitoring solutions for network traffic. Respond to alerts generated by Cloud Logging, SIEM platforms, and centralized firewall logging
- Partner closely with Cloud Architects, Platform engineering DevOps, and application teams to embed security requirements into cloud deployments without hindering developer velocity
- Ensure all cloud network configurations comply with internal policies, industry regulations, and best practices
Requirements:
- 5+ years of experience in Network Engineering or Information Security, with at least 2+ years of dedicated, hands-on experience securing Google Cloud Platform (GCP) environments
- Deep understanding of GCP networking constructs, including Shared VPCs, Cloud Router, Cloud NAT, Interconnect, and Peering
- Proven technical expertise in configuring and managing GCP Cloud Firewalls (Standard and NGFW/Hierarchical)
- Proven technical expertise in configuring and managing VPC Service Controls (VPC SC) for data exfiltration mitigation
- Proven technical expertise in configuring and managing Cloud IDS / IPS solutions
- Proven technical expertise in configuring and managing Cloud Armor (WAF and DDoS protection)
- Proven technical expertise in configuring and managing secure web gateways and proxy solutions
- Advanced proficiency in Terraform. Experience writing, testing, and managing complex state files and custom provider modules for cloud infrastructure
- Strong scripting skills in Python, Go, or Bash for automating routine security tasks, API integrations, and custom remediation scripts
- Hands-on experience with Git workflows and embedding IaC deployments into CI/CD pipelines
- Bachelor's degree in computer science, information systems and/or equivalent formal training or work experience
- Six (6) years' experience in a minimum of four (4) of the following areas: Business continuity and disaster recovery, network forensics, security and risk frameworks, endpoint security, information systems auditing, vendor risk assessment, cyber risk assessment, network intrusion detection/prevention, identity and access management, IT lifecycle management
- Strong technical, consulting, and project management skills
- Ability to communicate technical subject matter effectively to multiple organizational layers
- Google Cloud Professional Security Engineer, Google Cloud Professional Network Engineer, CISSP, or equivalent industry certifications
- Familiarity with cross-cloud connectivity and security principles across Azure or AWS is a strong plus
- Experience conducting threat modeling for complex distributed cloud architectures