Data Security Engineer
The Data Security Engineer will secure cloud infrastructure, Kubernetes workloads, data pipelines, identities, secrets, and software supply chains supporting AI research and a creator platform. The role requires hands-on experience with cloud security, infrastructure as code, CI/CD, incident response, and compliance.
About the job
Responsibilities
- Harden GCP environments, Kubernetes clusters, and containers through workload isolation, network segmentation, IAM discipline, and secure-by-default guardrails.
- Secure Terraform, CI/CD pipelines, and deployment systems against supply-chain attacks and other threats.
- Protect video and metadata ETL pipelines through encryption, isolation, logging, and observability.
- Monitor AI training-data movement and usage through Cloud Logging, SIEM, OpenTelemetry, and Honeycomb.
- Manage identity, access, and secrets, including privileged-access visibility, key rotation, least-privilege baselines, workload identity, and PKI.
- Secure the software supply chain with scanned builds and dependencies, artifact provenance, and hardened GitHub Actions runners.
- Lead threat modeling, red-team exercises, tabletop drills, incident response, and external penetration tests.
- Maintain compliance for creator data and AI training data.
Requirements
- Experience securing cloud infrastructure, preferably GCP; AWS security experience is also relevant.
- Experience with Kubernetes and container security.
- Experience with infrastructure as code and CI/CD security, especially Terraform and GitHub Actions.
- Knowledge of cloud IAM, workload identity, KMS, Secret Manager, and PKI.
- Experience securing data pipelines and implementing encryption, isolation, logging, and observability.
- Familiarity with software supply-chain security, dependency scanning, artifact provenance, and hardened CI runners.
- Experience with threat modeling, red teaming, incident response, and penetration testing.
Technology Stack
- GCP: GKE, Cloud Run, Cloud SQL, Google Cloud Storage, Pub/Sub, BigQuery
- Cloudflare, Akamai
- Terraform, GitHub Actions
- Cloud IAM, workload identity, KMS, Secret Manager
- Cloud Logging, SIEM, OpenTelemetry, Honeycomb
Skills
GCP, Kubernetes, Docker, Terraform, GitHub Actions, Cloud Iam, Kms, Secret Manager, Pki, SIEM, OpenTelemetry, Cloud Logging, BigQuery, Cloud Run, Cloud Sql
Similar jobs
Security Engineering jobsOwn and strengthen Onebrief’s corporate security stack across endpoints, identity, SaaS, Zero Trust, and monitoring. The role emphasizes security automation, configuration-baseline enforcement, telemetry integration, and continuously validated compliance controls.
The Security Engineer will secure cloud infrastructure, engineering systems, APIs, model-training environments, and GPU clusters while supporting rapid delivery. The role requires hands-on cloud security, IAM, secrets and certificate management, compliance ownership, vulnerability monitoring, and incident response experience.
Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.
Build and lead a Security Quality Management System for agentic and human-led SOC investigations, establishing quality standards, sampling, validation, reporting, and corrective actions. The role requires 5+ years in quality, governance, operational excellence, or controls, plus security operations and people-management experience.
Develop and maintain secure platform software spanning authentication, authorization, communications, data access, and automated security testing. The role requires 5+ years of security-focused software development experience, strong coding skills, and expertise in cloud and container security.