GCP Compliance Engineer for NERC POC
Budget: $250 – $750 USD
**Title:** GCP Compliance Engineer Needed for NERC CIP-Like POC Setup
**Description:**
We are seeking an experienced Google Cloud Platform (GCP) engineer to design and implement a small-scale Proof of Concept (POC) environment that demonstrates NERC CIP-like compliance controls. This POC won’t be for a specific client deployment yet, but will serve as an internal reference for future engagements. The ideal candidate has a deep understanding of GCP security, IAM, logging, monitoring, and compliance frameworks.
**Responsibilities:**
- Establish a dedicated GCP project and VPC network to mimic the isolation and segmentation required for NERC CIP compliance.
- Configure IAM policies, roles, service accounts, and MFA enforcement to reflect least-privilege and secure access principles.
- Implement Cloud KMS-based encryption at rest and set up secure data-in-transit configurations (TLS/HTTPS) for a few sample resources (e.g., Cloud Storage bucket, Cloud SQL instance).
- Enable and validate key logging and monitoring services (Cloud Audit Logs, Cloud Logging, Cloud Monitoring) to ensure visibility into all activities, changes, and potential anomalies.
- Demonstrate incident detection and response flows, integrating GCP Security Command Center, Pub/Sub alerts, and automated remediation (e.g., using Cloud Functions).
- Set up basic backup and restore scenarios (Cloud SQL backups, Cloud Storage versioning) to showcase data resilience.
- Document the resulting architecture, IAM policies, configuration snapshots, and a sample compliance-style report from Cloud Asset Inventory or similar tools.
**Requirements:**
- Proven experience with GCP resources: VPC, IAM, Cloud KMS, Cloud Logging/Monitoring, Security Command Center, Cloud SQL, and Cloud Storage.
- Familiarity with compliance frameworks or security best practices (NERC CIP, SOC 2, ISO 27001, etc.).
- Ability to set up infrastructure-as-code (e.g., Terraform, Deployment Manager) for reproducible environments.
- Strong communication skills and the ability to provide clear, well-organized documentation of the POC environment and its compliance features.
**Deliverables:**
- A functioning GCP project that demonstrates a security baseline, including network segmentation, strict IAM controls, encryption, logging, and basic incident response.
- Configuration files and scripts (Terraform, Deployment Manager, etc.) for reproducibility.
- Documentation of architecture diagrams, IAM policies, runbooks, backup/restore procedures, and a sample compliance report format.
Please provide:
- A brief summary of your relevant GCP compliance and security experience.
- Examples of past projects or portfolios demonstrating similar work (especially around compliance, IAM, logging, and encryption in GCP).
- A proposed timeline and cost estimate for delivering the POC environment and accompanying documentation.
We look forward to working with a skilled professional who can help us establish a strong, compliance-ready foundation for future client engagements.
**Description:**
We are seeking an experienced Google Cloud Platform (GCP) engineer to design and implement a small-scale Proof of Concept (POC) environment that demonstrates NERC CIP-like compliance controls. This POC won’t be for a specific client deployment yet, but will serve as an internal reference for future engagements. The ideal candidate has a deep understanding of GCP security, IAM, logging, monitoring, and compliance frameworks.
**Responsibilities:**
- Establish a dedicated GCP project and VPC network to mimic the isolation and segmentation required for NERC CIP compliance.
- Configure IAM policies, roles, service accounts, and MFA enforcement to reflect least-privilege and secure access principles.
- Implement Cloud KMS-based encryption at rest and set up secure data-in-transit configurations (TLS/HTTPS) for a few sample resources (e.g., Cloud Storage bucket, Cloud SQL instance).
- Enable and validate key logging and monitoring services (Cloud Audit Logs, Cloud Logging, Cloud Monitoring) to ensure visibility into all activities, changes, and potential anomalies.
- Demonstrate incident detection and response flows, integrating GCP Security Command Center, Pub/Sub alerts, and automated remediation (e.g., using Cloud Functions).
- Set up basic backup and restore scenarios (Cloud SQL backups, Cloud Storage versioning) to showcase data resilience.
- Document the resulting architecture, IAM policies, configuration snapshots, and a sample compliance-style report from Cloud Asset Inventory or similar tools.
**Requirements:**
- Proven experience with GCP resources: VPC, IAM, Cloud KMS, Cloud Logging/Monitoring, Security Command Center, Cloud SQL, and Cloud Storage.
- Familiarity with compliance frameworks or security best practices (NERC CIP, SOC 2, ISO 27001, etc.).
- Ability to set up infrastructure-as-code (e.g., Terraform, Deployment Manager) for reproducible environments.
- Strong communication skills and the ability to provide clear, well-organized documentation of the POC environment and its compliance features.
**Deliverables:**
- A functioning GCP project that demonstrates a security baseline, including network segmentation, strict IAM controls, encryption, logging, and basic incident response.
- Configuration files and scripts (Terraform, Deployment Manager, etc.) for reproducibility.
- Documentation of architecture diagrams, IAM policies, runbooks, backup/restore procedures, and a sample compliance report format.
Please provide:
- A brief summary of your relevant GCP compliance and security experience.
- Examples of past projects or portfolios demonstrating similar work (especially around compliance, IAM, logging, and encryption in GCP).
- A proposed timeline and cost estimate for delivering the POC environment and accompanying documentation.
We look forward to working with a skilled professional who can help us establish a strong, compliance-ready foundation for future client engagements.