Jobs · Pennsylvania

Google Infrastructure and Security Lead Architect

Deloitte · Philadelphia, PA · Today
Hybrid$141k–$278k/yrFull-time

Joining Our Team

Ai & Engineering is dedicated to transforming technology platforms and driving innovation to support our clients' success. We work with talented professionals to reimagine and re-engineer critical operations and processes for businesses.

Responsibilities

  • Architect and deploy highly scalable, multi-tenant GCP landing zones utilizing structured resource hierarchies (Organizations, Folders, Projects).
  • Design centralized identity and access strategies leveraging Google Cloud Identity, Single Sign-On (SSO), and role-based access control (RBAC).
  • Implement Context-Aware Access and the Principle of Least Privilege (PoLP) to secure human and machine identities.
  • Standardize and automate the deployment of cloud infrastructure using Terraform.
  • Develop modular, reusable infrastructure code to ensure consistent, repeatable, and auditable environment provisioning.
  • Design and implement robust network topologies, including Shared VPCs, Hub-and-Spoke models, and isolated subnets to control traffic flow and minimize the blast radius of potential incidents.
  • Secure inbound and outbound traffic flows by implementing Cloud Armor for WAF and DDoS protection, hierarchical firewall policies, and VPC Service Controls to prevent data exfiltration.
  • Evaluate existing on-premises or multi-cloud legacy workloads to define optimal migration blueprints, utilizing industry-standard patterns.
  • Guide development teams in modernizing applications by adopting GCP managed services, serverless computing (Cloud Run, Cloud Functions), and container orchestration platforms (Google Kubernetes Engine - GKE).
  • Collaborate with data architects to ensure real-time streaming and batch ingestion pipelines (e.g., Pub/Sub, Dataflow, BigQuery) are architected with strict security boundaries and encryption standards.
  • Integrate and tune Google Cloud Security Command Center (SCC Premium) to provide unified visibility into misconfigurations, vulnerabilities, and active threats.
  • Architect strategies for data security at rest and in transit using Cloud KMS (including Customer-Managed Encryption Keys), GCP Secret Manager, and Cloud Data Loss Prevention (DLP).
  • Develop and implement organization policies and Google Cloud Policy Library rules to establish automated security guardrails that prevent non-compliant resource deployments.

Qualifications

  • Bachelor's degree in computer science, Information Technology, Cybersecurity, or a closely related technical field (or equivalent practical experience).
  • 7-10+ years of hands-on experience in cloud architecture, infrastructure engineering, or cloud security, with a significant portion of that time dedicated to Google Cloud Platform environments.
  • Strong practical experience writing and maintaining Infrastructure as Code (IaC) using Terraform, alongside familiarity with CI/CD tools (e.g., GitHub Actions, GitLab CI, Cloud Build).
  • Proven track record of participating in/or leading enterprise-scale cloud migrations and modernizing legacy infrastructure.
  • Ability to travel up to 50% based on the work you do and the clients and industries/sectors you serve.

Preferred Qualifications

  • 12+ years of comprehensive experience in cloud migration and security architecture, particularly in consulting, professional services, or client-facing advisory roles.
  • Active status as a Google Cloud Professional Cloud Architect or Google Cloud Professional Cloud Security Engineer.
  • Recognized cybersecurity certifications such as CISSP, CCSP, or CISM.
  • Deep expertise in securing containerized workloads, Kubernetes (GKE) clusters, and microservice meshes (e.g., Anthos/Google Cloud Service Mesh).
  • Strong ability to align technical designs with compliance frameworks such as NIST SP 800-53, CIS Benchmarks, SOC 2, HIPAA, or GDPR.

Similar jobs