Principal CPE Engineer (GCP)
Mozn
Date: 5 hours ago
City: Riyadh
Contract type: Full time

About Mozn
Mozn is a rapidly growing technology firm revolutionising the field of Artificial Intelligence and Data Science headquartered in Riyadh, Saudi Arabia and it’s working to realise Vision 2030 with a proven track record of excellence in supporting and growing the tech ecosystem in Saudi Arabia and the GCC region. Mozn is the trusted AI technology partner for some of the largest government organizations, as well as many large corporations and startups.
We are in an exciting stage of scaling the company to provide AI-powered products and solutions both locally and globally that ensure the growth and prosperity of our digital humanity. It is an exciting time to work in the field of AI to create a long-lasting impact.
About The Role
We are looking for an experienced and hands-on Principal GCP Engineer to design, build, and secure Google Cloud Platform environments across multiple business lines. In this role, you will lead initiatives to implement Just-In-Time (JIT) access, enforce strong Identity and Access Management (IAM) controls, ensure separation of duties between authentication and authorization, deliver advanced network and network security architectures including secure connectivity to on-premises environments, implement Web Application Firewall (WAF) solutions, and manage secure migrations of workloads into GCP. Over time, you will expand your expertise to support other cloud platforms and containerized services such as Kubernetes to enable secure multi-cloud and modern application delivery. Your work will ensure that our cloud environments remain secure, compliant, and scalable, supporting critical services while enabling innovation.
What You'll Do
GCP Architecture, Networking & Engineering
Education
Mozn is a rapidly growing technology firm revolutionising the field of Artificial Intelligence and Data Science headquartered in Riyadh, Saudi Arabia and it’s working to realise Vision 2030 with a proven track record of excellence in supporting and growing the tech ecosystem in Saudi Arabia and the GCC region. Mozn is the trusted AI technology partner for some of the largest government organizations, as well as many large corporations and startups.
We are in an exciting stage of scaling the company to provide AI-powered products and solutions both locally and globally that ensure the growth and prosperity of our digital humanity. It is an exciting time to work in the field of AI to create a long-lasting impact.
About The Role
We are looking for an experienced and hands-on Principal GCP Engineer to design, build, and secure Google Cloud Platform environments across multiple business lines. In this role, you will lead initiatives to implement Just-In-Time (JIT) access, enforce strong Identity and Access Management (IAM) controls, ensure separation of duties between authentication and authorization, deliver advanced network and network security architectures including secure connectivity to on-premises environments, implement Web Application Firewall (WAF) solutions, and manage secure migrations of workloads into GCP. Over time, you will expand your expertise to support other cloud platforms and containerized services such as Kubernetes to enable secure multi-cloud and modern application delivery. Your work will ensure that our cloud environments remain secure, compliant, and scalable, supporting critical services while enabling innovation.
What You'll Do
GCP Architecture, Networking & Engineering
- Design, implement, and manage secure, scalable GCP environments for multiple business lines with compliance and security boundaries.
- Architect network segmentation, private connectivity, hybrid connectivity to on-premises (e.g., Cloud Interconnect, VPN), and service perimeters to enforce least privilege and data protection.
- Implement advanced network security controls, including firewall rules, DDoS protection, intrusion detection/prevention, secure routing, and WAF policy enforcement.
- Build and maintain robust IAM strategies, including fine-grained roles, service accounts, and workload identities.
- Implement and manage Just-In-Time (JIT) access models using GCP-native tools (e.g., Access Context Manager, IAM Conditions) or third-party solutions.
- Enforce clear separation of authentication (identity verification) and authorization (permissions and entitlements) to minimize insider and systemic risk.
- Lead migration of workloads from on-premises or other clouds to GCP, ensuring encryption, identity mapping, and compliance validation.
- Conduct pre- and post-migration reviews to ensure security and operational readiness.
- Design GCP organization resource hierarchies, access controls, and network architectures to support isolated workloads for different business units.
- Implement organization policies to enforce consistent security baselines across all projects and folders.
- Develop and maintain Terraform modules or Deployment Manager templates for repeatable, secure deployments.
- Automate compliance checks, security guardrails, and access provisioning.
- Integrate GCP-native security services (Security Command Center, Cloud Armor, IAM Recommender) into operational workflows.
- Implement and manage WAF solutions to protect applications from common and emerging web threats.
- Collaborate with MSSP or internal SOC teams to ensure log coverage, detection capabilities, and incident readiness.
- Partner with engineering and application teams to enable secure-by-design cloud adoption.
- Mentor cloud engineers on GCP security, IAM, networking, migration best practices, WAF management, and future multi-cloud and Kubernetes adoption.
Education
- Bachelor’s degree in Computer Science, Engineering, or related field (or equivalent experience).
- 10+ years in cloud engineering, with at least 5+ years of hands-on GCP architecture and implementation.
- Proven expertise in GCP IAM, including custom roles, service accounts, and policy troubleshooting.
- Experience implementing JIT access workflows for production and sensitive systems.
- Experience designing and enforcing separation of authentication and authorization in cloud access control.
- Demonstrated ability to design and implement advanced networking and network security solutions, including hybrid connectivity to on-premises.
- Hands-on expertise in implementing and managing WAF solutions.
- Demonstrated ability to manage secure environments for multiple business lines in a single GCP organization.
- Hands-on experience with secure workload migrations to GCP.
- Willingness and capability to expand into multi-cloud and Kubernetes environments.
- Expert-level knowledge of GCP networking (VPC, Shared VPC, Cloud Interconnect, VPN, firewall rules, private service connect, service perimeters).
- Expertise in WAF policy creation, tuning, and integration with GCP and hybrid application stacks.
- Proficiency with Terraform and automation scripting (Python, Bash, Go).
- Familiarity with GCP security tools (Security Command Center, Cloud Armor, IAM Recommender).
- Understanding of compliance frameworks (PCI-DSS, ISO 27001, SOC 2, NIST) in financial or regulated industries.
- Knowledge of Kubernetes security concepts and containerized workload protection.
- Strong communication, stakeholder management, and problem-solving abilities.
- GCP Professional Cloud Architect or Professional Cloud Security Engineer certification.
- Experience with BeyondCorp Enterprise or Access Context Manager for Zero Trust architectures.
- Exposure to MSSP oversight, including detection capability testing and SLA verification.
- Experience integrating GCP identity with Keycloak, Azure AD, or Okta.
- Knowledge of hybrid and multi-cloud security architectures.
- Experience in securing Kubernetes workloads and service meshes.
- You will be at the forefront of an exciting time for the Middle East, joining a high-growth rocket-ship in an exciting space.
- You will be given a lot of responsibility and trust. We believe that the best results come when the people responsible for a function are given the freedom to do what they think is best.
- The fundamentals will be taken care of: competitive compensation, top-tier health insurance, and an enabling culture so that you can focus on what you do best
- You will enjoy a fun and dynamic workplace working alongside some of the greatest minds in AI.
- We believe strength lies in difference, embracing all for who they are and empowered to be the best version of themselves.
How to apply
To apply for this job you need to authorize on our website. If you don't have an account yet, please register.
Post a resumeSimilar jobs
Hotel Front Office Manager
BAAN Holding | بان القابضة,
Riyadh
3 hours ago
Job Title: Hotel Front Office ManagerCompany: BAAN Holding | بان القابضةJob Type: Full-timeLocation: RiyadhBAAN Holding Group, formerly known as Al Hokair Group, was established in 1978 and boasts a legacy spanning over five decades. As one of the pioneers in the hospitality and entertainment sectors across Saudi Arabia and the Arab world, BAAN Holding continues to expand its investments, starting...

COOP / Tamheer – Corporate Pricing
Bupa Arabia,
Riyadh
8 hours ago
Job DescriptionRole Purpose:Supervise the renewal & new sales pricing process and assist pricing managers in reviewing and implementing the contractual terms.Key Accountabilities:1- Renewals Workflow:Prepare and check technical results of groups due for renewal on monthly basis.Identify major medical conditions of groups due for renewal and bring in notice to the pricing manager and medical underwriter.Supervise the preparation of quotations as...

Research on the status of the Disability Inclusion in Saudi Arabia Job ID : 262720
Urban Resilience Hub by UN-Habitat's CRGP,
Riyadh
9 hours ago
Result of ServiceThe incumbent will be responsible to provide an analysis of the current country context regarding the Rights of Persons with Disabilities, with recommended policy and advocacy actions and M&E plans.Work LocationExpected durationDuties and ResponsibilitiesQualifications/special SkillsLanguagesAdditional InformationNo FeeApply Now
