Cloud Security Operations Analyst (REMOTE)
VanguardAbout the role
Global Risk and Security (GR&S) at Vanguard enables business strategy, protects client and Vanguard interests (e.g., assets and data), and stewards a strong risk culture. Our teams leverage enterprise-wide insights, deep expertise, and trusted advice so that across Vanguard leaders and crew drive faster, stronger, risk-informed decisions.
Ā
Within GR&S, the Enterprise Security and Fraud (ES&F) sub-division is responsible for the global protection of Vanguard crew, property, data, and client assets. We are the trusted advisors that protect the pride of Vanguard with state-of-the-art security and fraud capabilities. We are a world-class destination of highly engaged, passionate, and diverse talent expected to continuously learn and develop in an ever-changing security landscape.
Our crew are our greatest resource ā by joining our team you will build collaborative long-term relationships and enjoy a suite of benefits that includes comprehensive health and wellness care, work-life balance, and an investment in your future at its core.
We are seeking a Senior Cloud Security Specialist to serve as a technical authority for securing Google Cloud Platform (GCP) environments. In this role, you will design, operate, and continuously improve cloud threat detection, investigation, and response capabilities, with a strong focus on Google Security Command Center (SCC), GCP-native telemetry, and CNAPP integrations.
You will partner closely with Cloud Engineering, Security Operations, and Governance teams to ensure a resilient, compliant, and highly observable GCP security posture across enterprise-scale environments.
Key Responsibilities
- Act as a subject matter expert for GCP cloud security, providing hands-on leadership across detection, investigation, and response
- Design, configure, and optimize Google Security Command Center (SCC) findings, detectors, and risk prioritization
- Monitor and investigate security events using GCP audit logs, VPC flow logs, workload telemetry, and behavioral indicators
- Identify misconfigurations, identity misuse, workload compromise, and data exfiltration risks across GCP projects, folders, and organizations
- Correlate SCC findings with CNAPP, endpoint, and SIEM data sources to perform end-to-end threat analysis
- Identify attack paths and exposure chains across complex GCP environments
- Assist with the development of automated response playbooks for containment actions such as IAM revocation, workload isolation, and network restriction
- Lead cloud-native incident response activities, including triage, containment, eradication, and recovery
- Perform cloud forensics to analyze identity activity, workload behavior, and data access patterns
- Produce investigation reports, root cause analyses, and post-incident recommendations
- Provide architectural guidance on secure GCP design, including identity, network segmentation, workload isolation, and data protection
- Partner with engineering teams to embed security controls into CI/CD pipelines and infrastructure-as-code workflows
Required Qualifications
- Deep hands-on experience with Google Cloud Platform security architecture, including IAM, organization policies, VPC Service Controls, Cloud Logging, and Cloud Monitoring
- Expert-level knowledge of Google Security Command Center (SCC), including Premium tier capabilities, built-in detectors, and security posture management
- Experience with GCP-native threat detection services such as Event Threat Detection, Container Threat Detection, and Security Health Analytics
- Strong investigation skills using cloud-native logs, workload telemetry, and behavioral analytics
- Experience integrating GCP security telemetry with CNAPP platforms (e.g., Wiz, Prisma Cloud, Orca)
- Hands-on experience with SIEM/SOAR platforms (e.g., Splunk, Sentinel, Elastic, Tines)
- Knowledge of cloud security frameworks such as MITRE ATT&CK and CSA CCM
- Experience supporting regulatory and compliance requirements (e.g., ISO 27001, GDPR, SOX) in cloud environments
Preferred Qualifications
- Experience leading or mentoring cloud security analysts or engineers
- Strong background in cloud-native incident response and forensics
- Experience securing large-scale, multi-project GCP environments
- Familiarity with Terraform or other infrastructure-as-code tools <
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights ā in under 60 seconds.
Apply Now āGenerate Application KitFree account required ā sign up in 30s