Retour à la recherche
Logo de Google
GoogleSource d’offres vérifiée

Technical Security and Compliance Analyst

Offre en anglais
  • Ottawa, ON
  • Sur place
  • Publié 17 sept. 2026
  • 1 poste

128 000 $–131 000 $ / année

Ouvre un site externe

Connectez-vous pour enregistrer ce poste
Type d’emploi
Temps plein
Niveau d’expérience
Expérimenté · 5+ ans
Formation minimale
Baccalauréat
Langue de l’offre
anglais
Heures de travail
40 heures par semaine

Résumé du poste

You will lead technical security validation, vulnerability assessments, and penetration testing for highly regulated cloud environments. Additionally, you will drive Security Assessment and Authorization processes to secure Authorities to Operate by translating complex frameworks into technical requirements.

Détails du poste

MINIMUM QUALIFICATIONS: * Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, a related technical field, or equivalent practical experience. * 5 years of experience in cybersecurity, security engineering, pen testing, cloud security, or technical vulnerability assessment. * Experience performing technical security validation, with Linux operating systems, networking concepts, and access controls. * Candidates must hold or be eligible to obtain a valid Personnel Security Clearance as a condition of employment. PREFERRED QUALIFICATIONS: * Experience navigating security frameworks and leading Security Assessment and Authorization (SA&A) or Authority to Operate (ATO) processes in defense, government, or highly regulated environments. * Experience assessing and securing modern infrastructure, including cloud platforms, Kubernetes, containers, and distributed systems. * Experience with threat modeling (e.g., MITRE ATT&CK), manual pen testing, security assessment tooling, and automating security workflows using Python, Bash, or Ansible. * Knowledge of software supply-chain security, including Software Bill of Materials (SBOMs), Static Application Security Testing (SAST), and vulnerability management. * Excellent communication and cross-functional collaboration skills, complemented by industry-recognized security certifications (e.g., CISSP, OSCP, GCIH, or equivalent). ABOUT THE JOB: The Google Public Sector (GPS) Governance, Risk and Compliance team enables GPS business with public sector customers by supporting compliance across varied compliance regimes. We serve as a trusted advisor to the business by ensuring that public sector risk exposure is transparent and proactively managed. We promote the growth of Google Cloud’s Public Sector business by driving accountability, consistency, efficiency, and governance. As a Security and Compliance Specialist within the Governance, Risk, and Compliance (GRC) team, you will serve as a technical security leader for critical, highly regulated cloud environments. You will ensure the security posture of specialized deployments, bridging the gap between rigorous compliance frameworks and technical validation. In this role, you will lead security assessments, vulnerability analysis, and architectural reviews to support mission-critical infrastructure. You will work closely with engineering, operations, and external partners to navigate complex security requirements and achieve required authorizations. Google Public Sector [https://about.google/intl/ALL_us/public-sector/#:~:text=We're%20committed%20to%20advancing,%2C%20research%2C%20and%20edtech%20companies.] brings the magic of Google to the mission of government and education with solutions purpose-built for enterprises. We focus on helping United States public sector institutions accelerate their digital transformations, and we continue to make significant investments and grow our team to meet the complex needs of local, state and federal government and educational institutions. Individual pay is determined by factors including job-related skills, experience, and relevant education or training. Canada: $128000 - $131000 (CAD) + 15% bonus target + equity + benefits Learn more about benefits at Google [https://www.google.com/about/careers/applications/benefits/]. RESPONSIBILITIES: * Lead technical security validation, including vulnerability assessments and penetration testing, for highly regulated cloud and Linux-based environments. * Drive Security Assessment and Authorization (SA&A) processes to secure Authorities to Operate (ATO) by translating complex security frameworks into actionable technical engineering requirements. * Automate routine security tasks and vulnerability management workflows using scripting languages and modern configuration assessment tools. * Partner with cross-functional teams—including product, engineering, and operations—to guide security architecture, threat modeling, and software supply-chain security. * Analyze complex technical security data to deliver clear, actionable mitigation recommendations to both technical and non-technical stakeholders.

Ce que vous ferez

You will lead technical security validation, vulnerability assessments, and penetration testing for highly regulated cloud environments. Additionally, you will drive Security Assessment and Authorization processes to secure Authorities to Operate by translating complex frameworks into technical requirements.

Exigences

Candidates must have a bachelor's degree in a technical field and at least 5 years of experience in cybersecurity or security engineering. Proficiency in Linux, networking, and security automation tools is required, along with eligibility for a personnel security clearance.

Avantages

• Bonus • Equity • Health Insurance

Compétences indiquées

  • Linux · Souhaitée
  • Python · Souhaitée

Autres compétences pertinentes

Relevées dans la description du poste. Confirmez les exigences importantes ci-dessus.

  • Cybersecurity
  • Security Engineering
  • Penetration Testing
  • Cloud Security
  • Vulnerability Assessment
  • Linux
  • Networking
  • Access Controls
  • Security Frameworks
  • SA&A
  • ATO
  • Threat Modeling
  • Python
  • Bash
  • Ansible
  • Software Supply-chain Security
  • Bill Of Materials
  • Static Application Security Testing (SAST)
  • Cross-Functional Collaboration
  • MITRE ATT&CK Framework
  • Accountability
  • Technical Validation
  • Workflow Management
  • Technical Engineering
  • Google Cloud Platform (GCP)
  • Digital Transformation
  • IT Security Architecture
  • Supply Chain Security
  • Assessment And Authorization
  • Automation
  • Bash (Scripting Language)
  • Certified Information Systems Security Professional
  • Communication
  • Computer Science
  • Information Technology
  • Cyber Security
  • Equities
  • GIAC Certifications
  • GIAC Certified Incident Handler
  • Governance
  • Governance Risk Management And Compliance
  • Python (Programming Language)
  • Operations
  • Offensive Security Certified Professional
  • Product Engineering
  • Security Requirements Analysis
  • Tooling
  • Vulnerability Assessments
  • Vulnerability Management
  • Security Clearance

Domaines d’emploi

  • Security & Safety
  • Technology
  • Software
  • Government & Public Sector
  • Engineering
  • Security and Compliance Analyst
  • Technical Consultant / Analyst
  • Systems Analysts
  • Computer Systems Analysts

D’autres postes auxquels postuler directement

Des possibilités semblables publiées par des employeurs qui recrutent sur Jobs.ca, sans formulaire externe.

Voir tous les postes à candidature simplifiée