Job Description:Partner with Cloud Engineering, Architecture, DevOps, Risk, and Governance teams to embed security controls into cloud platforms, standards, and deployment pipelines. Act as the primary subject matter expert and trusted advisor for GCP security assurance, posture management, cloud risk governance, and cloud security strategy. Influence stakeholders across multiple organizations to drive adoption of security capabilities, remediation priorities, and risk reduction initiatives.
Responsibilities:- Design and execute the Cloud Security Assurance (CSA) strategy for GCP environments in alignment with enterprise security objectives and cloud adoption priorities.
- Integrate CSA activities with cloud governance routines, ensuring consistent governance, transparency, and leadership visibility into cloud risk and control effectiveness.
- Maintain ongoing visibility into the cloud business roadmap to anticipate emerging risks, influence secure architecture decisions, and align security priorities with business initiatives.
- Provide technical leadership and coordination for a focused group of cloud security SMEs responsible for posture management, workload protection, and cloud risk governance activities.
- Drive cloud security technology requirements and lead technology initiatives, including tool implementation, integration, automation, and operational maturity efforts.
- Provide oversight of vulnerability identification, security posture management, and vulnerability analysis processes across GCP projects, services, and workloads.
- Establish and govern operational processes for triage, prioritization, escalation, and remediation tracking of high-risk cloud findings.
- Own cloud security posture, vulnerability, and risk metrics, including executive reporting, trend analysis, and audit-ready documentation.
Required Qualifications:- Deep understanding of Google Cloud Platform services, architectures, and security controls.
- Strong knowledge of cloud security posture management, vulnerability management, and workload protection concepts.
- Experience integrating cloud security assurance activities with governance, risk, and compliance frameworks.
- Working knowledge of cloud threat landscapes, attack paths, and risk-based prioritization methodologies.
- Experience leading CSPM, CWPP, SSPM, and related cloud security technologies.
- Understanding of DevSecOps practices and integration of security controls into CI/CD pipelines.
- Proven ability to lead complex cross-functional technology initiatives and influence outcomes across multiple stakeholder groups.
- Ability to translate technical cloud risks into clear business impact for executive, audit, and risk audiences.
- Strong analytical, qualitative, and quantitative reasoning skills.
- Demonstrated technical leadership and mentorship experience.
- Ability to operate independently on complex, high-visibility initiatives.
- Excellent written and verbal communication skills with the ability to influence technical and non-technical audiences.
Desired Qualifications:- CISSP, CISM, CCSP
- Google Professional Cloud Security Engineer certification
- Google Professional Cloud Architect certification
- SANS or GIAC cloud and security certifications
- Experience supporting regulated environments and audit engagements
- Bachelor's degree in a technical or security-related field
Skills:- Critical Thinking
- Customer and Client Focus
- Information Systems Management
- Problem Solving
- Threat Analysis
- Cyber Security
- Policies, Procedures, and Guidelines Management
- Quality Assurance
- Risk Analytics
- Technology System Assessment
- Business Acumen
- Business Intelligence
- Data Privacy and Protection
- Data and Trend Analysis
- Stakeholder Management
Shift:1st shift (United States of America)
Hours Per Week: 40
Pay Transparency detailsUS - IL - Chicago - 540 W Madison St - Bank Of America Plaza (IL4540)
Pay and benefits information
Pay range
$145,000.00 - $192,500.00 annualized salary, offers to be determined based on experience, education and skill set.
Discretionary incentive eligible
This role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company.
Benefits
This role is currently benefits eligible. We provide industry-leading benefits, access to paid time off, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.