Overview
We are seeking a Contract Cloud Security Engineer to contribute to a SOC 2 infrastructure buildout for a venture-backed technology company. In this hands-on delivery role, the contractor will collaborate directly with the Head of Engineering and platform team, focusing on improving security across GCP, Kubernetes, and CI/CD practices. This position is well-suited for independent contractors looking for a structured engagement with a clear scope and defined deliverables.
Responsibilities
- Develop and implement Datadog Cloud Security measures including CSPM and container security.
- Integrate GCP audit, data access, and VPC flow logs into Datadog.
- Harden GKE and Kubernetes environments following Pod Security Standards and RBAC.
- Secure GitHub usage through actions, branch protection, and audit log streaming.
- Manage backup and disaster recovery implementations using Terraform.
- Ensure supply chain security best practices with tools like cosign and Binary Authorization.
- Collaborate with engineering leadership to raise pull requests in Terraform and GitOps stacks.
- Document and provide audit evidence alongside technical changes.
Requirements
- Proven experience with Terraform and Kubernetes hardening.
- Strong background in implementing compliance-oriented controls, particularly focused on SOC 2.
- Deep knowledge of GCP services and security practices.
- Proficiency in Datadog and cloud SIEM integration.
- Experience with GitHub security hardening practices.
- Familiarity with backup and disaster recovery practices in cloud environments.
- Ability to work independently and deliver results within a fixed timeframe.