GCP Cloud Security Architect

Donyati

United States

On-site

USD 140,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A leading retail technology firm is seeking a senior-level GCP Cloud Security Architect to design and implement a secure Google Cloud Platform environment for their business. This role involves developing security policies, ensuring compliance with PCI DSS, and managing identity and access management in a complex cloud setup. The ideal candidate will have over seven years of experience in cloud security architecture, expertise in GCP security services, and a solid understanding of regulatory compliance frameworks. This position is crucial for maintaining data protection and security protocols.

Qualifications

  • 7+ years of experience in a senior cloud security or cloud architect role.
  • Hands-on expertise with core GCP security services.
  • Experience designing and implementing Workload Identity Federation.

Responsibilities

  • Lead design and implementation of GCP landing zone security.
  • Develop and maintain Technical Security Design documents.
  • Oversee compliance with PCI DSS within the GCP environment.

Skills

GCP security services (IAM, VPC Service Controls)
Terraform (IaC)
CI/CD pipelines (GitHub Actions)
Cloud-native network security
Regulatory compliance frameworks (PCI DSS)

Job description

Get AI‑powered advice on this job and more exclusive features.

We are seeking a senior‑level GCP Cloud Security Architect to lead the design, implementation, and governance of a large American retail brand’s new Google Cloud Platform (GCP) landing zone. As a key player in the consumer retail space, the primary mission is to build a secure‑by‑default environment that protects customer data, ensures compliance with PCI DSS, and is hardened against security incidents.

You will be the lead subject matter expert for all cloud security matters, responsible for translating guiding principles into enforceable, automated policies. This is a hands‑on role for an expert who can move the security posture from "monitoring" to "fully enforced" and ensure the cloud foundation meets the highest standards of security and compliance.

Key Responsibilities
Security Design & Governance
  • Develop and maintain a comprehensive Technical Security Design document for the GCP security framework, ensuring it aligns with existing OCI/OSHI standards.
  • Design, implement, and document security controls to meet and maintain PCI DSS compliance within the GCP environment, preparing for and facilitating audits.
  • Translate high‑level security principles into detailed, enforceable Organization Policies and governance standards.
  • Drive the full adoption and operationalization of Google Security Command Center (SCC) Premium for continuous posture management, threat detection, and compliance reporting.
Network & Infrastructure Security
  • Conduct a deep dive review of all foundational infrastructure, including VPCs, private interconnects, and ingress/egress traffic patterns.
  • Design and implement a hardened VPC Service Controls (VPCSC) perimeter, moving from monitoring mode to a fully enforced posture to protect the Cardholder Data Environment (CDE) and other sensitive data.
  • Lead the migration from legacy GCP firewall rules to modern, centralized GCP firewall policies, ensuring strict enforcement and proper segmentation (especially for CDE isolation).
  • Design and configure security solutions for e‑commerce web applications and APIs using Cloud Armor.
  • Validate and optimize security service SKU selections to ensure maximum value and protection.
Identity & Access Management (IAM)
  • Serve as the lead technical expert for all GCP IAM strategy and implementation, focusing on least‑privilege access to sensitive consumer data.
  • Design and enforce granular Organization Policies to restrict high‑risk permissions (e.g., denying firewall modifications or public IP creation).
  • Implement time‑bound access and privileged access management (PAM) solutions for elevated permissions, especially for systems within the CDE scope.
  • Architect and execute the transition from service account keys to a keyless/credential‑less model using Workload Identity Federation between Azure AD and GCP.
  • Design and implement a best‑practice RBAC model for Google Secrets Manager.
  • Establish comprehensive logging and alerting for all critical identity, access, and permissions‑related events, per PCI DSS requirements.
Automation & DevSecOps
  • Perform a security‑focused review of the Terraform automation and GitHub Actions CI/CD pipelines.
  • Implement DevSecOps best practices to harden pipelines, manage access controls, improve error handling, and minimize the blast radius of deployments, ensuring compliance is built into the pipeline.
  • Establish security‑focused housekeeping and hygiene plans for pipeline maintenance, API versioning, and credential management.
  • Provide expert guidance on the security implications of migrating from Azure ARM/Jenkins to Terraform/GitHub Actions.
Required Qualifications & Skills (Must‑Have)
  • 7+ years of experience in a senior cloud security or cloud architect role.
  • Deep, hands‑on expertise with core GCP security services: IAM, VPC Service Controls, GCP Firewall Policies, Organization Policies, and Security Command Center (SCC) Premium.
  • Demonstrable experience designing, implementing, and auditing controls for regulatory compliance frameworks, specifically PCI DSS, within a major cloud provider (GCP preferred).
  • Proven experience designing and implementing Workload Identity Federation, specifically for federating identities from Azure AD.
  • Strong understanding of Terraform (IaC) and CI/CD pipelines (e.g., GitHub Actions, Jenkins) from a security (DevSecOps) perspective.
  • Expertise in cloud‑native network security, including CDE segmentation, VPC design, private interconnects, and WAFs (Cloud Armor).
  • Demonstrated ability to create high‑quality TDDs and security policy documentation for compliance and audit purposes.
  • Preferred (Nice‑to‑Have)
  • Experience in multi‑cloud environments, especially with Azure security (Azure AD, ARM).
  • Familiarity with other consumer data privacy regulations (e.g., CCPA/CPRA, GDPR).
  • Hands‑on experience with Google’s Privileged Access Management (PAM) solutions.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GCP Cloud Architect – Identity & Network Security
GCP Cloud Architect – Identity & Network Security

Largeton Group • New Jersey

On-site
USD 120,000 - 160,000
Senior GCP Cloud Security Architect - PCI-DSS & IAM Lead
Senior GCP Cloud Security Architect - PCI-DSS & IAM Lead

Donyati • United States

On-site
USD 140,000 - 180,000
Devops Cloud Security Engineer
Devops Cloud Security Engineer

Tata Consultancy Services • Louisville (KY)

On-site
USD 90,000 - 130,000
Annual Incentive
Medical Coverage
Parental Leave
+5
Lead Security Architect – GCP
Lead Security Architect – GCP

Five Rivers IT Inc. • Miami (FL)

On-site
USD 130,000 - 150,000
Cloud Security Engineer - GCP
Cloud Security Engineer - GCP

ExecuSource • Marietta (GA)

Hybrid
USD 115,000 - 155,000
Google Cloud Platform Security Architect | GCP Cloud Security & SIEM Engineer
Google Cloud Platform Security Architect | GCP Cloud Security & SIEM Engineer

Pacer Group • New York (NY)

Hybrid
Medical
Dental
Vision
+1
GCP Architect
GCP Architect

Compunnel, Inc. • Mount Laurel Township (NJ)

On-site
USD 120,000 - 150,000
GCP Security Engineer
GCP Security Engineer

BlueVector AI • Denver (CO)

Hybrid
USD 100,000 - 140,000
Health, Dental, and Vision insurance
Simple IRA Retirement plan with match
Unlimited PTO
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Google • Seattle (WA)

On-site
USD 152,000 - 221,000
Health insurance
Retirement benefits (401k)
Paid time off
+3
Senior Network Security Architect
Senior Network Security Architect

Talent Groups • Phoenix (AZ)

Hybrid
USD 120,000 - 150,000