03 Oct
|
Google Canada
|
Ottawa
03 Oct
Google Canada
Ottawa
Google Public Sector's Governance, Risk and Compliance team is hiring a Technical Security and Compliance Analyst based in Ottawa, Ontario . This is a senior-level cybersecurity role within a team that supports compliance across varied public sector regulatory frameworks—bridging rigorous government compliance requirements with hands‑on technical security validation in highly regulated cloud environments . You’ll serve as a technical security leader , ensuring the security posture of specialized deployments by leading vulnerability assessments, penetration testing, and architectural reviews.
The work spans everything from navigating complex Security Assessment and Authorization (SA&A;) processes to partnering with engineering and operations teams on threat modeling and software supply‑chain security.
About the Role: Technical Security and Compliance Analyst At the core of this position is the need to translate complex security compliance frameworks into actionable technical engineering requirements. You’ll lead security assessments and penetration testing for Linux-based and cloud infrastructure, analyze vulnerability data, and deliver mitigation recommendations that speak clearly to both technical teams and non‑technical stakeholders. This role also carries a personnel security clearance requirement —candidates must hold or be eligible to obtain a valid clearance as a condition of employment.
You’ll work across Google Cloud's public sector deployments, supporting mission‑critical infrastructure for government and education institutions across Canada and the United States. The compensation for this role in Canada is $128,000–$131,000 CAD annually ,
with a 15% bonus target , equity, and a comprehensive benefits package. Individual pay is determined by job-related skills, experience, and relevant education or training.
Pay: $128,000–$131,000 CAD/year + 15% bonus target + equity + benefits Day-to-day, you’ll be working at the intersection of technical security validation and compliance governance—running hands‑on assessments while also guiding engineering teams through complex security architecture decisions. These responsibilities require both deep technical knowledge and the ability to communicate clearly across functions. Lead technical security validation, including vulnerability assessments and penetration testing , for highly regulated cloud and Linux‑based environments Drive Security Assessment and Authorization (SA&A;) processes to secure Authorities to Operate (ATO) by translating complex security frameworks into actionable technical engineering requirements Automate routine security tasks and vulnerability management workflows using scripting languages and up-to-date configuration assessment tools Partner with cross‑functional teams—including product, engineering, and operations—to guide security architecture, threat modeling, and software supply‑chain security Analyze complex technical security data to deliver clear,
actionable mitigation recommendations to both technical and non‑technical stakeholders The ideal candidate brings a strong foundation in cybersecurity engineering with hands‑on experience in regulated environments—particularly government or defence contexts.
Google values professionals who can operate independently on complex assessments while collaborating effectively across teams and communicating security risks clearly at all levels. ~ Bachelor's degree in Cybersecurity, Computer Science, Information Technology, a related technical field, or equivalent practical experience ~5 years of experience in cybersecurity, security engineering, pen testing, cloud security, or technical vulnerability assessment ~ Technical security validation experience with Linux operating systems, networking concepts, and access controls ~ Personnel Security Clearance : candidates must hold or be eligible to obtain a valid clearance as a condition of employment ~ Cloud and container security experience , including Kubernetes, containers, and distributed systems (preferred) ~ Threat modeling and automation skills using MITRE ATT&CK;, manual pen testing, Python, Bash, or Ansible (preferred) ~ Knowledge of software supply‑chain security , including SBOMs, SAST, and vulnerability management (preferred) ~ Industry-recognised security certifications such as CISSP, OSCP, GCIH, or equivalent.
Experience navigating security frameworks and leading Security Assessment and Authorization (SA&A;) or Authority to Operate (ATO) processes in defense, government, or highly regulated environments.
#
📌 Technical Security and Compliance Analyst (Ottawa)
🏢 Google Canada
📍 Ottawa