About the job
Devsinc is hiring a Senior Cloud Security Engineer focused on Google Cloud Platform (GCP) and Oracle Cloud Infrastructure (OCI). This position is based in Dammam, Eastern Province, Saudi Arabia. The role centers on building and maintaining secure, compliant cloud environments for clients in the banking, fintech, or other regulated sectors. Candidates should bring deep knowledge of regulatory frameworks and advanced security controls, with a strong background in high-compliance settings.
What You Will Do
- Design and implement cloud security architectures and guardrails across network, identity, data, and logging layers.
- Configure databases, storage, serverless, and other cloud-native services for security and compliance.
- Develop and enforce least-privilege IAM models, including SSO (SAML/OIDC) and PAM workflows.
- Oversee key and credential lifecycle management: MFA, short-lived tokens, and machine identity governance.
- Protect data through encryption (at rest and in transit) and tokenization where needed.
- Set up network segmentation, secure private connectivity, controlled egress, and API security measures.
- Deploy protective controls such as WAF, DDoS mitigation, and bot defense.
- Implement and maintain Zero Trust access models for users and services.
- Integrate security scanning tools (SAST, DAST, Secrets, IaC) into CI/CD pipelines.
- Maintain compliance and audit readiness for SAMA, NCA, ISO 27001, PCI DSS, and SWIFT CSP.
- Develop and enforce policies-as-code, tagging standards, and exception workflows.
- Manage integration of cloud logs with SIEM platforms (such as Splunk).
- Coordinate cloud and container security scanning, track remediation SLAs, and work closely with engineering teams.
Requirements
- 7–12 years of experience in cybersecurity, including at least 3 years securing public cloud environments (GCP or OCI preferred).
- Direct experience in fintech, banking, or other highly regulated industries is required.
- Expertise in IAM, SSO, PAM, KMS/HSM, PKI, and key rotation strategies.
- Hands-on experience with cloud security platforms: CSPM, CNAPP, CWPP, CIEM, and native tools (such as GCP SCC or OCI Cloud Guard).
- Strong understanding of network and web security: VPC/VNet, routing, private link, TLS/mTLS, and API gateways.
- Experience with container and Kubernetes security, including runtime protection and network policy management.
- Proficiency with DevSecOps tools: Terraform, CI/CD pipelines, scripting (Python or PowerShell), and log analysis (SQL or Regex).
