JOBSEARCHER

Principal Cloud Security Architect - Google Cloud Platform (GCP)

Overview In this role you will define and drive cloud security design across GCP and Azure to protect enterprise workloads. You will partner with cloud engineering, identity, network security, risk, and compliance teams to implement scalable security architectures. You will translate security requirements into practical, resilient cloud solutions and mentor cross-functional teams. You will influence security roadmaps and communicate risks to senior leadership. This is a hands-on, technically deep opportunity to shape ADP’s cloud security posture at scale. ResponsibilitiesDesign and evolve security architecture for GCP and other public clouds, covering threat protection, network security, data protection, and IAM.Architect secure cloud landing zones, organizational structures, subscriptions/projects, accounts, policies, and governance models.Define data security architectures including encryption, key management, secrets management, and data classification.Document security standards and best practices for GCP, Azure, and other clouds.Architect secure connectivity and segmentation across cloud, on-premises, and hybrid environments.Establish security architecture patterns, guardrails, controls, and engineering standards for GCP and Azure.Provide internal security consulting for ADP applications and IT shared services in cloud environments.Lead cross-functional teams through communication, delegation, and prioritization.Establish cloud security monitoring, logging, detection, and incident-response architectures with security operations. Key requirements10+ years in IT security/cybersecurity or related field7+ years hands-on in designing and implementing cloud security in GCP and AzureExperience architecting security for large-scale enterprise cloudsDeep knowledge of GCP security services (IAM, Organization Policy, VPC, KMS, Security Command Center, Cloud Armor, logging, workload security)Deep knowledge of Azure security services (Entra ID, Azure Policy, Defender for Cloud, Key Vault, Sentinel, Private Link, workload security)Strong understanding of cloud IAM, least privilege, RBAC, service principals, federation, identity governanceStrong understanding of cloud networking and security, segmentation, zero-trust, hybrid connectivityExperience with containers, Kubernetes, serverless, APIs, VMs, cloud-native apps securityKnowledge of cloud data protection, encryption, key management, secrets managementHands-on with IaC and automation (Terraform), policy-as-code, CI/CD, programming/scripting (Python, JS, C#, C++), and databasesExperience with cloud security posture management, vulnerability management, SIEM, threat detection, incident responseExcellent technical communication for engineers, architects, security pros, and executivesOne or more advanced cloud/security certifications (e.g., Google Professional Cloud Security Engineer, CISSP, CCSP, etc.)Experience securing Kubernetes/GKE and AKS in enterprise scaleExperience with security architecture for AI/ML and cloud-native techexcellent technical communicationleadership and cross-functional collaborationstakeholder managementGCP security architecture and servicesAzure security architecture and servicesIAM, Organization Policy, VPC, Cloud KMS