Devsinc logo

Senior Cloud Security Engineer - GCP/OCI

DevsincDammam, Eastern Province, Saudi Arabia
On-site Full-time

Clicking Apply Now takes you to AutoApply where you can tailor your resume and apply.


Experience Level

Mid to Senior

Qualifications

7–12 years of experience in cybersecurity, with a minimum of 3 years focusing on public cloud environments (preferably GCP or OCI). Experience in fintech, banking, or other highly regulated sectors is essential. Strong knowledge of IAM/SSO/PAM, KMS/HSM, PKI, and effective key rotation methods. Practical experience with cloud security tools: CSPM, CNAPP, CWPP, CIEM, and native security tools. Comprehensive understanding of network and web security principles. Experience securing containers and Kubernetes, including network policies and runtime protection. Capability in using DevSecOps tools such as Terraform and CI/CD tools.

About the job

Devsinc is hiring a Senior Cloud Security Engineer focused on Google Cloud Platform (GCP) and Oracle Cloud Infrastructure (OCI). This position is based in Dammam, Eastern Province, Saudi Arabia. The role centers on building and maintaining secure, compliant cloud environments for clients in the banking, fintech, or other regulated sectors. Candidates should bring deep knowledge of regulatory frameworks and advanced security controls, with a strong background in high-compliance settings.

What You Will Do

  • Design and implement cloud security architectures and guardrails across network, identity, data, and logging layers.
  • Configure databases, storage, serverless, and other cloud-native services for security and compliance.
  • Develop and enforce least-privilege IAM models, including SSO (SAML/OIDC) and PAM workflows.
  • Oversee key and credential lifecycle management: MFA, short-lived tokens, and machine identity governance.
  • Protect data through encryption (at rest and in transit) and tokenization where needed.
  • Set up network segmentation, secure private connectivity, controlled egress, and API security measures.
  • Deploy protective controls such as WAF, DDoS mitigation, and bot defense.
  • Implement and maintain Zero Trust access models for users and services.
  • Integrate security scanning tools (SAST, DAST, Secrets, IaC) into CI/CD pipelines.
  • Maintain compliance and audit readiness for SAMA, NCA, ISO 27001, PCI DSS, and SWIFT CSP.
  • Develop and enforce policies-as-code, tagging standards, and exception workflows.
  • Manage integration of cloud logs with SIEM platforms (such as Splunk).
  • Coordinate cloud and container security scanning, track remediation SLAs, and work closely with engineering teams.

Requirements

  • 7–12 years of experience in cybersecurity, including at least 3 years securing public cloud environments (GCP or OCI preferred).
  • Direct experience in fintech, banking, or other highly regulated industries is required.
  • Expertise in IAM, SSO, PAM, KMS/HSM, PKI, and key rotation strategies.
  • Hands-on experience with cloud security platforms: CSPM, CNAPP, CWPP, CIEM, and native tools (such as GCP SCC or OCI Cloud Guard).
  • Strong understanding of network and web security: VPC/VNet, routing, private link, TLS/mTLS, and API gateways.
  • Experience with container and Kubernetes security, including runtime protection and network policy management.
  • Proficiency with DevSecOps tools: Terraform, CI/CD pipelines, scripting (Python or PowerShell), and log analysis (SQL or Regex).

About Devsinc

Devsinc is a leading technology company dedicated to providing innovative solutions to the fintech and banking sectors. We prioritize security and compliance, ensuring our infrastructures meet the highest standards of safety and reliability.

Similar jobs

Browse all companies, explore by city & role, or SEO search pages. View directory listings: all jobs, search results, location & role pages.

Tailoring 0 resumes

We'll move completed jobs to Ready to Apply automatically.