Google Infrastructure and Security Lead Architect
Deloitte · Philadelphia, PA · Today
Hybrid$141k–$278k/yrFull-time
Joining Our Team
Ai & Engineering is dedicated to transforming technology platforms and driving innovation to support our clients' success. We work with talented professionals to reimagine and re-engineer critical operations and processes for businesses.
Responsibilities
- Architect and deploy highly scalable, multi-tenant GCP landing zones utilizing structured resource hierarchies (Organizations, Folders, Projects).
- Design centralized identity and access strategies leveraging Google Cloud Identity, Single Sign-On (SSO), and role-based access control (RBAC).
- Implement Context-Aware Access and the Principle of Least Privilege (PoLP) to secure human and machine identities.
- Standardize and automate the deployment of cloud infrastructure using Terraform.
- Develop modular, reusable infrastructure code to ensure consistent, repeatable, and auditable environment provisioning.
- Design and implement robust network topologies, including Shared VPCs, Hub-and-Spoke models, and isolated subnets to control traffic flow and minimize the blast radius of potential incidents.
- Secure inbound and outbound traffic flows by implementing Cloud Armor for WAF and DDoS protection, hierarchical firewall policies, and VPC Service Controls to prevent data exfiltration.
- Evaluate existing on-premises or multi-cloud legacy workloads to define optimal migration blueprints, utilizing industry-standard patterns.
- Guide development teams in modernizing applications by adopting GCP managed services, serverless computing (Cloud Run, Cloud Functions), and container orchestration platforms (Google Kubernetes Engine - GKE).
- Collaborate with data architects to ensure real-time streaming and batch ingestion pipelines (e.g., Pub/Sub, Dataflow, BigQuery) are architected with strict security boundaries and encryption standards.
- Integrate and tune Google Cloud Security Command Center (SCC Premium) to provide unified visibility into misconfigurations, vulnerabilities, and active threats.
- Architect strategies for data security at rest and in transit using Cloud KMS (including Customer-Managed Encryption Keys), GCP Secret Manager, and Cloud Data Loss Prevention (DLP).
- Develop and implement organization policies and Google Cloud Policy Library rules to establish automated security guardrails that prevent non-compliant resource deployments.
Qualifications
- Bachelor's degree in computer science, Information Technology, Cybersecurity, or a closely related technical field (or equivalent practical experience).
- 7-10+ years of hands-on experience in cloud architecture, infrastructure engineering, or cloud security, with a significant portion of that time dedicated to Google Cloud Platform environments.
- Strong practical experience writing and maintaining Infrastructure as Code (IaC) using Terraform, alongside familiarity with CI/CD tools (e.g., GitHub Actions, GitLab CI, Cloud Build).
- Proven track record of participating in/or leading enterprise-scale cloud migrations and modernizing legacy infrastructure.
- Ability to travel up to 50% based on the work you do and the clients and industries/sectors you serve.
Preferred Qualifications
- 12+ years of comprehensive experience in cloud migration and security architecture, particularly in consulting, professional services, or client-facing advisory roles.
- Active status as a Google Cloud Professional Cloud Architect or Google Cloud Professional Cloud Security Engineer.
- Recognized cybersecurity certifications such as CISSP, CCSP, or CISM.
- Deep expertise in securing containerized workloads, Kubernetes (GKE) clusters, and microservice meshes (e.g., Anthos/Google Cloud Service Mesh).
- Strong ability to align technical designs with compliance frameworks such as NIST SP 800-53, CIS Benchmarks, SOC 2, HIPAA, or GDPR.