Technical Security and Compliance Analyst

Google Canada

Ottawa

Hybrid

CAD 128,000 - 131,000

Full time

9 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Google Public Sector's Governance, Risk and Compliance team seeks a Senior Technical Security and Compliance Analyst in Ottawa, ON. You will lead security validation, perform vulnerability assessments and penetration testing for regulated cloud and Linux environments, and guide complex SA&A/ATO processes.

The role requires a Bachelor’s degree and 5 years in cybersecurity, with an emphasis on government or defence contexts.

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology or related field.
  • 5 years of experience in cybersecurity, security engineering, pen testing, cloud security, or vulnerability assessment.
  • Experience with security validation in regulated environments (government/governmental) preferred.

Responsibilities

  • Lead security validation, including vulnerability assessments and penetration testing for cloud and Linux-based environments.
  • Drive SA&A/ATO processes to secure authorities to operate by translating frameworks into actionable engineering requirements.
  • Automate security tasks and vulnerability management workflows using scripting and configuration assessment tools.
  • Partner with product, engineering, and operations to guide security architecture, threat modeling, and software supply-chain security.
  • Analyze security data to deliver mitigation recommendations to technical and non-technical stakeholders.

Skills

Cybersecurity engineering
Security assessments
Penetration testing
Threat modeling
Automation

Education

Bachelor's degree

Tools

Kubernetes
Python
Bash
Ansible

Job description

Google Public Sector's Governance, Risk and Compliance team is hiring a Technical Security and Compliance Analyst based in Ottawa, Ontario. This is a senior-level cybersecurity role within a team that supports compliance across varied public sector regulatory frameworks—bridging rigorous government compliance requirements with hands‑on technical security validation in highly regulated cloud environments.

You’ll serve as a technical security leader, ensuring the security posture of specialized deployments by leading vulnerability assessments, penetration testing, and architectural reviews. The work spans everything from navigating complex Security Assessment and Authorization (SA&A) processes to partnering with engineering and operations teams on threat modeling and software supply‑chain security.

About the Role: Technical Security and Compliance Analyst

At the core of this position is the need to translate complex security compliance frameworks into actionable technical engineering requirements. You’ll lead security assessments and penetration testing for Linux-based and cloud infrastructure, analyze vulnerability data, and deliver mitigation recommendations that speak clearly to both technical teams and non‑technical stakeholders.

This role also carries a personnel security clearance requirement—candidates must hold or be eligible to obtain a valid clearance as a condition of employment. You’ll work across Google Cloud's public sector deployments, supporting mission‑critical infrastructure for government and education institutions across Canada and the United States.

Benefits and Salary

The compensation for this role in Canada is $128,000–$131,000 CAD annually, with a 15% bonus target, equity, and a comprehensive benefits package. Additional details about Google's benefits can be found on their careers page. Individual pay is determined by job-related skills, experience, and relevant education or training.

Job Details

Company: Google

Location: Ottawa, ON, Canada

Pay: $128,000–$131,000 CAD/year + 15% bonus target + equity + benefits

Responsibilities

Day-to-day, you’ll be working at the intersection of technical security validation and compliance governance—running hands‑on assessments while also guiding engineering teams through complex security architecture decisions. These responsibilities require both deep technical knowledge and the ability to communicate clearly across functions.

  • Lead technical security validation, including vulnerability assessments and penetration testing, for highly regulated cloud and Linux‑based environments
  • Drive Security Assessment and Authorization (SA&A) processes to secure Authorities to Operate (ATO) by translating complex security frameworks into actionable technical engineering requirements
  • Automate routine security tasks and vulnerability management workflows using scripting languages and modern configuration assessment tools
  • Partner with cross‑functional teams—including product, engineering, and operations—to guide security architecture, threat modeling, and software supply‑chain security
  • Analyze complex technical security data to deliver clear, actionable mitigation recommendations to both technical and non‑technical stakeholders
Requirements / Skills

The ideal candidate brings a strong foundation in cybersecurity engineering with hands‑on experience in regulated environments—particularly government or defence contexts. Google values professionals who can operate independently on complex assessments while collaborating effectively across teams and communicating security risks clearly at all levels.

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, a related technical field, or equivalent practical experience
  • 5 years of experience in cybersecurity, security engineering, pen testing, cloud security, or technical vulnerability assessment
  • Technical security validation experience with Linux operating systems, networking concepts, and access controls
  • Personnel Security Clearance: candidates must hold or be eligible to obtain a valid clearance as a condition of employment
  • Experience with SA&A or ATO processes in defence, government, or highly regulated environments (preferred)
  • Cloud and container security experience, including Kubernetes, containers, and distributed systems (preferred)
  • Threat modeling and automation skills using MITRE ATT&CK, manual pen testing, Python, Bash, or Ansible (preferred)
  • Knowledge of software supply‑chain security, including SBOMs, SAST, and vulnerability management (preferred)
  • Industry‑recognised certifications such as CISSP, OSCP, GCIH, or equivalent (preferred)
Industry-recognised security certifications such as CISSP, OSCP, GCIH, or equivalent. Experience navigating security frameworks and leading Security Assessment and Authorization (SA&A) or Authority to Operate (ATO) processes in defense, government, or highly regulated environments.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Technical Security and Compliance Analyst
Technical Security and Compliance Analyst

Google • Ottawa

Hybrid
CAD 128,000 - 131,000
Senior Security Validation & Compliance Engineer
Senior Security Validation & Compliance Engineer

Google Canada • Ottawa

Hybrid
CAD 128,000 - 131,000
Principal Consultant, Adversarial Resilience and Cyber Defence
Principal Consultant, Adversarial Resilience and Cyber Defence

Google • Alberta

Hybrid
CAD 198,000 - 202,000
Equity
Bonus target 20%
Benefits
Security Consultant Intern, BS/MS, Summer 2027
Security Consultant Intern, BS/MS, Summer 2027

Google • Toronto

On-site
CAD 75,000 - 91,000
Forward Deployed Detection and Response Consultant, Cyber Defence, National Security, Mandiant
Forward Deployed Detection and Response Consultant, Cyber Defence, National Security, Mandiant

Google Inc. • Ottawa

On-site
CAD 134,000 - 137,000
Equity
Senior Forward Deployed Detection and Response Consultant, Cyber Defence, National Security, Ma[...]
Senior Forward Deployed Detection and Response Consultant, Cyber Defence, National Security, Ma[...]

Google • Ottawa

On-site
CAD 166,000 - 170,000
Cybersercurity Compliance Analsyst
Cybersercurity Compliance Analsyst

Aplin • Edmonton

On-site
CAD 110,000 - 150,000
Forward Deployed Detection and Response Consultant, Cyber Defence, National Security, Mandiant
Forward Deployed Detection and Response Consultant, Cyber Defence, National Security, Mandiant

Google LLC • Ottawa

On-site
CAD 134,000 - 137,000
Principal Consultant, Adversarial Resilience and Cyber Defence
Principal Consultant, Adversarial Resilience and Cyber Defence

Google Inc. • Siksiká #146, Alberta

On-site
CAD 198,000 - 202,000
Staff Software Developer, Cloud
Staff Software Developer, Cloud

Google • Southwestern Ontario

On-site
CAD 216,000 - 221,000