Cloud Security Architect with IAM, GRC

CGI

• $90K — $267K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years of experience in identity and access management, cloud security, data governance, and regulatory compliance advisory.
  • Deep expertise in Microsoft Entra ID and Active Directory, with knowledge of CyberArk or similar tools.
  • Experience in cloud security architecture across AWS, Azure, or GCP.
  • Proven ability to design data governance operating models, preferably with Collibra.
  • Familiarity with NIST 800 53, PCI DSS, HIPAA, and state privacy laws, with specific control mapping skills.
  • Experience in third-party data risk assessment and SOC 2 analysis.
  • Strong stakeholder facilitation skills, with relevant certifications in identity, cloud security, and governance.

Responsibilities

  • Lead interviews across 14 business units, conducting 40-55 sessions to gather governance and compliance evidence.
  • Own assessments for multiple domains including Data Governance, Regulatory Compliance, and Identity Management.
  • Design the target state data protection framework, including policies and accountability structures.
  • Reconcile findings against data catalogs and enterprise architecture, driving data ownership completion.
  • Produce regulatory registers and control mappings for various compliance standards.
  • Analyze data risk across approximately 340 vendors and manage vendor evidence programs.
  • Assess data protection controls in cloud environments and lead resilience reviews.

Benefits

  • Competitive compensation
  • Comprehensive insurance options
  • 401(k) matching contributions and share purchase plan
  • Paid time off for vacation, holidays, and sick leave
  • Paid parental leave
  • Learning opportunities and tuition assistance
  • Wellness and well-being programs
Full Job Description
Find similar career opportunities

Cloud Security Architect with IAM, GRC

Category: Infrastructure/Cloud

Main location: United States, Louisiana, Lafayette

Position ID:J0926-2650

Employment Type: Full Time

Position Description:

The best version of us starts with You!

We CGI is looking for a Cloud Security Architect with IAM, GRC to lead its identity, governance, compliance, and resilience workstreams.
In this client facing role you will assess identity and access management across Microsoft Entra ID, Active Directory, privileged access, and identity governance platforms; design the data governance operating model and target state data protection framework; build the regulatory register and control mapping; assess third party data risk; and evaluate cloud data protection and business resilience.

This is one of the most heavily loaded roles on the engagement, combining identity and cloud security architecture with data governance, risk, and compliance advisory, and running close to full time through the early assessment phase. You will report to the Engagement Lead, work closely with the Data Security & DLP Architect, lead six of the engagement's nine assessment domains, and own the identity and access management assessment, the data governance and data protection framework, and the risk, compliance, and resilience deliverables.

This is a Full-Time, On-Site employment opportunity located in Lafayette, LA or any CGI Office in a Hybrid Model.

Your future duties and responsibilities:

. Lead cross domain business unit interviews - approximately 40 to 55 sessions across 14 business units - and run data flow mapping workshops, gathering governance, compliance, and access evidence in the same sessions.
. Own the Data Governance & Registration, Analytics & AI Governance, Regulatory/Privacy/Compliance, Third Party & Vendor Data Risk, Identity & Access Management, and Business Resilience domain assessments, including questionnaires, returns analysis, and follow on question sets.
. Assess the data governance current state - operating model, stewardship across approximately 60 data stewards, ownership assignment, registration practice, and lifecycle management - and design the target state data protection framework: policies, standards, roles, accountability, and the data catalog operating model.
. Reconcile discovery findings against data catalog and enterprise architecture baselines, triage unmanaged repositories with owners, produce the shadow data register, and drive catalog registration and ownership assignment to at least 70% completion.
. Produce the regulatory register and control mapping across NERC CIP, NIST 800 53, PCI DSS, HIPAA, and applicable state privacy and public records laws; review privacy operations and the PIA process; and contribute regulatory interpretation of BES Cyber System Information, CEII, and public records exemptions to the sensitive information type catalog.
. Analyze data risk across a population of approximately 340 vendors - tracker analysis, contractual coverage, tiering, and assurance gaps - and run the vendor management evidence program.
. Collect IAM configuration and certification evidence from Microsoft Entra ID, Active Directory, CyberArk, and Saviynt, specifying the exports the client executes.
. Assess role-based access control and least privilege practice across approximately 20 major applications, and review privileged access management, joiner mover leaver lifecycle, and service, non-human, and vendor identities.
. Assess data protection controls across three cloud environments - encryption and key management, storage security, cloud native discovery, and data residency - and lead the resilience review of backup and immutability posture, RTO/RPO testing evidence, and data loss scenario readiness.
. Produce subdomain scoring and prioritized remediation plans across governance, regulatory, third party, identity, and resilience; support discovery verification, cloud source scan scoping, and the enterprise deployment and target state architecture designs; and help specify least privilege, read only access to the cloud environments.

Required qualifications to be successful in this role:

At least 10+ years of experience spanning across identity and access management, cloud security, data governance, and regulatory compliance advisory, with genuine depth in both assessment and design/implementation experience.

. Strong Microsoft Entra ID and Active Directory depth, plus working knowledge of privileged access management (CyberArk or comparable) and identity governance (Saviynt or comparable).
. Cloud security architecture across at least two of AWS, Azure, and GCP: encryption and key management, storage security, cloud native data discovery, and data residency.
. Experience designing - not only assessing - data governance operating models, including stewardship structures, ownership accountability, and data catalog registration workflows and ownership campaigns (Collibra strongly preferred).
. Working knowledge of NIST 800 53, PCI DSS, HIPAA, and state privacy and public records laws, with the ability to map obligations to specific controls rather than control families; familiarity with NERC CIP (particularly CIP 011) and CEII designation under FERC rules.
. Third party and vendor data risk assessment at scale, including contractual data protection review, tiering methodology, and SOC 2 analysis including complementary user entity controls.
. Backup, recovery, and resilience assessment experience, including the ability to judge whether a recovery capability has been proven rather than documented, and to assess access governance from a data protection standpoint.
. Proven stakeholder facilitation at volume (40+ interviews) and relevant credentials: identity (CIMP, Entra ID certification, or CyberArk/Saviynt training), cloud security (CCSP or an AWS/Azure/GCP security specialty), and governance/compliance (CDMP, DCAM, CIPP/US, CIPM, CISA, or CRISC).

Education: Bachelor's degree in computer science on related field.

#LI-ARK1

CGI is required by law in some jurisdictions to include a reasonable estimate of the compensation range for this role. The determination of this range includes various factors not limited to skill set, level, experience, relevant training, and licensure and certifications. To support the ability to reward for merit-based performance, CGI typically does not hire individuals at or near the top of the range for their role. Compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range for this role in the U.S. is $90,700.00 $267,800.00.

CGI's benefits are offered to eligible professionals on their first day of employment to include:
. Competitive compensation
. Comprehensive insurance options
. Matching contributions through the 401(k) plan and the share purchase plan
. Paid time off for vacation, holidays, and sick time
. Paid parental leave
. Learning opportunities and tuition assistance
. Wellness and Well-being programs

Skills:
  • Data Governance
  • Access Management
  • Cloud architecture
  • Compliance
  • Identity Governance Admin

Similar Jobs

More Jobs at CGI

  • Software Developer (Mid-Level)
    $89K — $156K *
    Houston, TX 77084 (Harris County)
    Information Technology
    In-Person
  • ARGO Developer
    $62K — $139K *
    Mobile, AL 36695 (Mobile County)
    Finance & Insurance
    In-Person
  • ARGO Developer
    $62K — $139K *
    Atlanta, GA 30349 (Fulton County)
    Finance & Insurance
    In-Person
  • ARGO Developer
    $62K — $139K *
    Columbia, SC 29223 (Richland County)
    Finance & Insurance
    In-Person
  • ARGO Developer
    $62K — $139K *
    Knoxville, TN 37918 (Knox County)
    Finance & Insurance
    In-Person

More Information Technology Jobs

Find similar Cloud Security Architect with IAM, GRC jobs: