GCP Security Architect (Canada)

GCP Security Architect (Canada)

25 Aug
|
Intuitive AI
|
Canada

25 Aug

Intuitive AI

Canada

About us:

Intuitive.AI is one of the fastest-growing (INC 5000, CRN) Cloud & SDx solution and services companies supporting enterprise customers on a global scale. Intuitive is an "Engineering Company" delivering measurable value and key business outcomes.

Intuitive Superpowers

- DataOps & AI/ML
- Cloud Native, AppSecOps, DevSecOps
- Cloud Migration & Transformation

- Cloud FinOps
- Cybersecurity (App/Data/Infra) & GRC
- SDx & Digital Workspace

We are proud to partner with some of the world's leading enterprises and serve 200+ customers across different industry verticals. We have achieved many milestones along the way, including being recognized as a top-10 fast-growth 150 IT company in the Americas by CRN in 2022 and being named one of America's fastest-growing private companies by INC 5000 in 2022. That’s not all! Even CIO Review awarded us as the Most Promising Cloud Migration Company and Artificial Intelligence Solutions Provider in 2022.

About the job:

Title: Cloud Security Architect (GCP)

Location: Remote across Canada

Role Summary A solutioning-focused architect who owns GCP security architecture end-to-end: landing zone security design, hardening standards, governance frameworks, encryption strategy, and control-mapping deliverables for platform and workload onboarding. This role drives security strategy and standards across the GCP environment, and is accountable for security sign-off on architecture designs and overall security posture.

Key Responsibilities

- Design secure GCP landing zone architecture: organization hierarchy, network topology (VPC/Shared VPC segmentation), identity structure, and baseline security guardrails (Org Policies, SCC posture) for new environments.
- Define GCP service hardening standards aligned to CIS benchmarks and vendor best practices covering Compute Engine, GKE, Cloud SQL, Cloud Storage, serverless,



and networking.
- Own the least-privilege design strategy across environments: role design, service-account patterns, workload identity federation, and privileged access governance.
- Design the encryption strategy (CMEK key hierarchy, rotation policy, encryption-in-transit standards) and the retention/immutability/ransomware-protection model for backup and DR architecture.
- Architect VPC Service Controls perimeter models and access-level strategy for sensitive workloads and shared services, including violation-detection and dry-run tuning approach.
- Design DR/BCP security architecture: replication path hardening, failover security, and network segmentation for cross-region resilience.
- Define policy-as-code governance strategy (OPA / Org Policy libraries) and threat assessments for platform capabilities such as self-service provisioning or fleet/ownership models.
- Lead security-focused Architecture Design Reviews (ADRs); produce control mapping documentation and drive sign-off with security, compliance, and architecture stakeholders.
- Ensure designs map cleanly to compliance frameworks (SOC2, HIPAA, PCI-DSS) without owning enterprise-wide policy definition.
- Serve as the primary security architecture point of contact across engineering, platform, and governance teams.

Required Skills & Experience

- 8+ years in cybersecurity architecture, with 4+ years designing security controls for GCP.
- Proven experience architecting GCP landing zones,



organization/folder/project structure, network segmentation, and identity governance for enterprise environments.
- Deep knowledge of GCP IAM design patterns, Resource Manager hierarchy, Cloud KMS/CMEK strategy, and encryption governance (in-transit and at-rest).
- Experience designing VPC Service Controls perimeter strategies, including access-level design and violation-analysis approaches.
- Experience designing DR/BCP and backup security architecture: replication hardening, failover security, immutability, retention-lock, and ransomware protection.
- Experience defining GCP service hardening standards against CIS/industry benchmarks.
- Familiarity with policy-as-code frameworks (OPA, Org Policy) at a governance/design level, defining policy libraries and guardrails, not just implementing rules.
- Experience leading Architecture Design Reviews and producing artifacts that pass enterprise security review boards.
- Strong stakeholder management across security, compliance, and engineering teams.
- Working understanding of compliance frameworks (HIPAA, PCI-DSS, SOC2) and how they translate into cloud control requirements.

Preferred Skills

- Azure Security (optional but valued): experience architecting Azure landing zones, Azure Policy/Blueprints, Azure AD/Entra ID governance, and Key Vault-based encryption strategy — valuable for organizations running hybrid or multi-cloud GCP/Azure environments.
- GCP security certifications (Skilled Cloud Security Engineer, Professional Cloud Architect).
- Experience securing internal developer platforms or service catalogs — governance-as-a-service, fleet/ownership models, cost-attribution security.
- Experience with Infrastructure-as-Code-based resource provisioning via terraform and managing DevSecOps environments.

📌 GCP Security Architect (Canada)
🏢 Intuitive AI
📍 Canada

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: gcp security architect (canada) / canada

Subscribe to this job alert:

Get the latest job offers by email for: gcp security architect (canada) / canada