Google Infrastructure and Security Lead Architect
Deloitte · Stamford, CT · Today
Hybrid$141k–$278k/yrFull-time
Joining Our Team
Ai & Engineering is dedicated to transforming technology platforms and driving innovation. We work with businesses to improve their financial performance, accelerate new digital ventures, and fuel growth through innovation.
Responsibilities
- Architect and deploy highly scalable, multi-tenant GCP landing zones utilizing structured resource hierarchies (Organizations, Folders, Projects) tailored to client governance and billing requirements.
- Design centralized identity and access strategies leveraging Google Cloud Identity, Single Sign-On (SSO), and role-based access control (RBAC).
- Implement Context-Aware Access and the Principle of Least Privilege (PoLP) to secure human and machine identities.
- Standardize and automate the deployment of cloud infrastructure using Terraform.
- Develop modular, reusable infrastructure code to ensure consistent, repeatable, and auditable environment provisioning.
- Design and implement robust network topologies, including Shared VPCs, Hub-and-Spoke models, and isolated subnets to control traffic flow and minimize the blast radius of potential incidents.
- Secure inbound and outbound traffic flows by implementing Cloud Armor for WAF and DDoS protection, hierarchical firewall policies, and VPC Service Controls to prevent data exfiltration.
- Evaluate existing on-premises or multi-cloud legacy workloads to define optimal migration blueprints, utilizing industry-standard patterns.
- Guide development teams in modernizing applications by adopting GCP managed services, serverless computing (Cloud Run, Cloud Functions), and container orchestration platforms (Google Kubernetes Engine - GKE).
- Collaborate with data architects to ensure real-time streaming and batch ingestion pipelines (e.g., Pub/Sub, Dataflow, BigQuery) are architected with strict security boundaries and encryption standards.
- Integrate and tune Google Cloud Security Command Center (SCC Premium) to provide unified visibility into misconfigurations, vulnerabilities, and active threats.
- Architect strategies for data security at rest and in transit using Cloud KMS (including Customer-Managed Encryption Keys), GCP Secret Manager, and Cloud Data Loss Prevention (DLP).
- Develop and implement organization policies and Google Cloud Policy Library rules to establish automated security guardrails that prevent non-compliant resource deployments.
Requirements
- Bachelor's degree in computer science, Information Technology, Cybersecurity, or a closely related technical field (or equivalent practical experience).
- 7-10+ years of hands-on experience in cloud architecture, infrastructure engineering, or cloud security, with a significant portion of that time dedicated to Google Cloud Platform environments.
- Strong practical experience writing and maintaining Infrastructure as Code (IaC) using Terraform, alongside familiarity with CI/CD tools (e.g., GitHub Actions, GitLab CI, Cloud Build).
- Proven track record of participating in/or leading enterprise-scale cloud migrations and modernizing legacy infrastructure.
- Ability to travel up to 50% based on the work you do and the clients and industries/sectors you serve.
Qualifications
- Wages + Salary: The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs.
- Discretionary annual incentive program: An award, if any, depends on various factors, including, without limitation, individual and organizational performance.