24 Sep
|
Olevea Nxt
|
Mumbai
– Google Cloud & Network Security Engineer
Job Title: Google Cloud & Network Security Engineer
Department: Cloud / Infrastructure & Security
Experience: 5+ years
Location: Mumbai
Employment Type: Full-time
About the Role
We are looking for an experienced Google Cloud & Network Security Engineer to support the migration and transformation of Google Cloud workloads into a secure, standardized landing-zone setting.
The role will focus on Google Cloud networking, network security, firewall implementation, routing, traffic inspection, secure administrative access, identity and access controls, and cloud security operations. The candidate will work closely with infrastructure, security, cloud, and application teams to implement and operationalize the required Google Cloud security architecture.
The project covers approximately 34 Google Cloud projects and follows a Secure-First / Zero Trust approach.
Key Responsibilities
- Design, implement, and maintain secure Google Cloud network architecture aligned with Zero Trust principles.
- Configure and manage Cloud NGFW or approved next-generation firewall appliances as centralized security inspection points.
- Configure hierarchical and VPC firewall policies and enforce appropriate network and application controls.
- Implement and maintain VPC routes, custom static routes, dynamic routes, and policy-based routing.
- Configure secure inbound traffic flows using Google Cloud Load Balancing and Cloud Armor WAF/DDoS protection.
- Configure and manage outbound traffic flows through Cloud NAT, Cloud NGFW, and approved network virtual appliances.
- Implement network segmentation using Shared VPC, VPC firewall policies, and approved connectivity architectures.
- Configure inter-VPC connectivity using Network Connectivity Center, VPC Network Peering, Cloud VPN, and Shared VPC, as required by the architecture.
- Implement secure administrative access using Identity-Aware Proxy (IAP), OS Login, or approved hardened jump-host solutions.
- Configure IAM roles, firewall policies, and source ranges to restrict SSH/RDP access to authorized identities and approved access paths.
- Ensure workload virtual machines are not unnecessarily exposed through external IP addresses.
- Implement and manage Cloud IDS / IPS and Cloud NGFW threat-prevention controls.
- Configure FQDN, URL, egress filtering, DNS security, and threat-intelligence controls where applicable.
- Implement and monitor Cloud Logging, VPC Flow Logs, Firewall Rules Logging, and Cloud Audit Logs.
- Support Google Cloud security controls including Security Command Center, SIEM, SOAR, EDR/XDR, DLP, VPC Service Controls, Secure Web Proxy, and CASB as applicable.
- Support Google Cloud migration activities, landing-zone implementation, security-control integration, governance, and operational handover.
- Troubleshoot cloud networking, routing,
firewall, connectivity, and security-related issues.
- Maintain technical documentation for network architecture, routing, firewall policies, security controls, and operational procedures.
- Support implementation, testing, UAT, rollback, and post-implementation validation activities.
- Collaborate with cloud, security, infrastructure, application, and business teams throughout the migration and transformation phases.
Required Technical SkillsGoogle Cloud Platform
- Google Cloud VPC
- Shared VPC
- Cloud NGFW
- Google Cloud Armor
- Cloud Load Balancing
- Cloud NAT
- Network Connectivity Center
- VPC Network Peering
- Cloud VPN
- IAM
- Identity-Aware Proxy (IAP)
- OS Login
- Cloud Logging
- Cloud Audit Logs
- VPC Flow Logs
- Security Command Center
- Cloud IDS / IPS
- Cloud DNS
Networking & Security
- VPC routing and route tables
- Custom static and dynamic routes
- Policy-based routing
- Network segmentation
- Hierarchical and VPC firewall policies
- Firewall rule configuration
- Network traffic inspection
- IDS/IPS
- DDoS protection
- WAF
- DNS security
- FQDN and URL filtering
- Egress filtering
- Secure administrative access
- Zero Trust security principles
- Cloud network security architecture
Identity & Security The candidate should have exposure to:
- Cloud IAM and least-privilege access
- Privileged Access Management (PAM)
- Identity-Aware Proxy
- Context-Aware Access
- BeyondCorp Enterprise
- Security Command Center
- SIEM
- SOAR
- EDR/XDR
- DLP
- VPC Service Controls
- Secure Web Proxy
- CASB
These controls form part of the security and identity architecture described in the SOW.
Good to Have
- Experience with enterprise Google Cloud migration projects
- Experience implementing Google Cloud landing zones
- Experience with Shared VPC governance
- Experience with Cloud NGFW deployment and hardening
- Experience with Cloud Armor deployment and hardening
- Knowledge of Google Cloud organization policies
- Experience with ServiceNow / CMDB integration
- Experience with Cloud DDoS protection
- Knowledge of third-party / next-generation firewalls
- Experience with backup and disaster recovery
- Knowledge of threat intelligence and security operations
- Experience working in 24x7 enterprise cloud environments
- Experience with cloud security governance and compliance
Qualifications
- Bachelor's degree in Computer Science, Information Technology, Networking, Cybersecurity, or a related field.
- 5+ years of relevant experience in Google Cloud infrastructure, cloud networking, network security, or a related field.
- Strong hands-on experience with Google Cloud networking and security services.
- Experience working on enterprise cloud migration, security implementation, or landing-zone projects.
- Strong troubleshooting and problem-solving skills.
Key Responsibilities During Implementation The engineer will be expected to support:
1. Inbound Traffic Security
Route internet traffic through approved Google Cloud Load Balancers and Cloud Armor, with traffic reaching only approved backend services.
1. Outbound Traffic Security
Route approved outbound traffic through Cloud NGFW or centralized network virtual appliances, with Cloud NAT providing controlled internet connectivity for private workloads.
1. VPC Routing & Connectivity
Implement appropriate static, dynamic, and policy-based routes, and support connectivity through Shared VPC, VPC Peering, Cloud VPN, or Network Connectivity Center.
1. Secure Administrative Access
Implement identity-aware administrative access through IAP, OS Login, or approved hardened jump-host patterns, while restricting SSH/RDP access through IAM and firewall policies.
1. Centralized Firewall
Deploy and operationalize Cloud NGFW or an approved next-generation firewall appliance as the centralized security inspection point.
1. Security Controls
Implement and maintain firewall policies, IDS/IPS, Cloud Armor, DNS security, TLS inspection where approved, FQDN/URL filtering, egress filtering, and centralized logging.
1. Migration & Transformation
Support controlled migration waves, Google Cloud resource hierarchy and organization policies, Shared VPC governance, security integration, compliance alignment, and operational handover. Project Context The project involves standardizing DFS Google Cloud workloads within the BTIS-GIT native landing zone, with approximately 34 Google Cloud projects. The architecture follows a Secure-First / Zero Trust approach, with inbound, outbound, east-west, and administrative traffic controlled, inspected where required, logged, and monitored.
Phase I – Secure First: Target completion 30 November 2026
Phase II – Transformation & Operationalization: Target completion 30 November 2027
Candidate Profile
We are looking for a candidate with robust hands-on experience in Google Cloud networking and cloud security, particularly someone who can independently work on VPC architecture, routing, firewall implementation, Cloud NGFW, Cloud Armor, secure access, traffic inspection, security controls, troubleshooting, and enterprise cloud migration.
The role requires practical implementation experience rather than only theoretical knowledge of Google Cloud security.
Work Location: In person
📌 Google Cloud Platform (Mumbai)
🏢 Olevea Nxt
📍 Mumbai