D

GCP Infra Security (GCP + AI+ DevSecOps) - Senior Consultant

Deloitte · Hyderabad / Secunderabad, Telangana, Telangana, India, Telangana

6–12 yrs experienceFullTime, PermanentPosted 5 days ago
Apply now →

Job description

Job Description - -------------- **Summary** **Position Summary** **Cyber** Deloitte Cyber understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful insights to help our clients navigate the ever-changing threat landscape. Through powerful insights and managed services that simplify complexity, we enable businesses to operate with resilience, grow with confidence, and proactively manage to secure achievements. **Position Summary** **Level:** Senior Consultant **Work you'll do:** As a Senior Consultant you will be supporting the clients with their Cyber needs specifically helping them protect and secure their Google Cloud Platform (GCP) infrastructure . This will include: * Assist in designing and implementing secure Google Cloud Platform infrastructure solutions under the guidance of senior consultants and managers. * Support security assessments, threat modeling, and risk analysis activities for client GCP environments. * Help review and update Identity and Access Management (IAM) policies, service account configurations, VPC architectures, and firewall rules. * Contribute to integrating security tools and controls into CI/CD pipelines and DevOps workflows. * Support the configuration and tuning of cloud-native security services, such as VPC Service Controls, Cloud Armor, IAM, and Security Command Center. * Help develop and maintain secure Infrastructure-as-Code (IaC) templates using tools like Terraform or Deployment Manager. * Assist in implementing security controls and processes to help client environments meet relevant security standards and frameworks (e.g., ISO 27001, NIST, CIS, HIPAA, PCI-DSS). * Collaborate with client stakeholders and internal teams to align security activities with business objectives. * Lead and review documentation and training materials to support client teams in managing their GCP security posture. * Lead and support GCP Security, Compliance \& Controls initiatives covering governance, identity, network security, monitoring, and data protection. * Experience using Wiz for Cloud Security Posture Management (CSPM), Cloud Workload Protection (CWPP), container and Kubernetes security, vulnerability management, and risk prioritization. * Design and implement security controls for AI/GenAI workloads on GCP, including Vertex AI and Gemini-based environments, with emphasis on access control, data isolation, prompt security, logging, and monitoring. * Guide clients in the secure implementation of AI-enabled solutions on GCP by supporting solution design, deployment, and integration across Vertex AI and related Google Cloud services. * Strengthen AI security and governance by applying controls for data privacy, model risk, compliance, and responsible AI across ML and Generative AI solutions. **The Team:** Enterprise Security teams embed security in all aspects of digital transformation by securing a client's technical backbone while also enabling secure digital transformation. Services include security architecture, secure development and deployment, end-to-end cyber cloud capabilities, application security, and security for emerging technologies and connected products. Examples of work include Secure by Design, Cloud Security Orchestration \& Automation, Core Infrastructure Security, and Secure Software Enablement. **Qualifications** **Must Have Skills/Project Experience/Certifications:** * 7 years of experience in cloud security or cloud infrastructure, with hands-on exposure to Google Cloud Platform (GCP) and its security features. * Familiarity with designing and implementing secure GCP architectures, preferably as part of a team. * Understanding of cloud security principles, such as least-privilege access and zero-trust concepts. * Experience with GCP networking, IAM, data protection and related security controls. * Exposure to infrastructure-as-code tools (e.g., Terraform, Cloud Deployment Manager). * Experience working with CI/CD pipelines and integrating security controls. * Proficiency with scripting languages (e.g., Python, Bash) for automation tasks. * Knowledge of container security (e.g., GKE, Kubernetes RBAC, image scanning) is a plus. * Strong communication and teamwork skills, with the ability to contribute to client discussions and documentation. * Strong understanding of AI/GenAI implementation and security on GCP, including Vertex AI and Gemini, with knowledge of secure solution design, deployment, integration, identity and access management, data isolation, prompt security, logging, and monitoring. * Knowledge of AI governance, data privacy, responsible AI, and compliance considerations, with the ability to apply controls for model risk management, policy enforcement, and continuous risk identification using GCP-native security and AI-assisted capabilities. **Good to Have Skills/Project Experience/Certifications:** * Relevant security certifications (e.g., GCP Associate Cloud Engineer, GCP Professional Cloud Security Engineer, CompTIA Security , Vertex AI / GenAI and AI governance or security credentials such as IAPP AIG) are a plus. * Awareness of security frameworks such as NIST, CIS, or MITRE ATT\&CK, and applying them to GCP, Vertex AI and AI-enabled environments. **Education:** * Bachelor's degree or higher in Computer Science, or equivalent experience. **Location:** * Bangalore, Hyderabad, Pune, Chennai #FY27CyberCampaign #CyberEnterpriseSecurity **Our purpose** Deloitte's purpose is to make an impact that matters for our people, clients, and communities. At Deloitte, purpose is synonymous with how we work every day. It defines who we are. Our purpose comes through in our work with clients that enables impact and value in their organizations, as well as through our own investments, commitments, and actions across areas that help drive positive outcomes for our communities. **Our people and culture** Our inclusive culture empower