Careers
Careers

job details

Back to jobs search

Jobs search results

3,363 jobs matched
Showing 61 to 80 of 3363 rows
Back to jobs search

Technical Security and Compliance Analyst

GoogleOttawa, ON, Canada; Toronto, ON, Canada; +2 more; +1 moreRemote eligible

This posting is for a new vacancy.

Google utilizes AI tools to assist in assessing candidates in our hiring processes.
Note: By applying to this position you will have an opportunity to share your preferred working location from the following:

In-office locations: Ottawa, ON, Canada; Toronto, ON, Canada.
Remote location(s): Alberta, CA.

Minimum qualifications:

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, a related technical field, or equivalent practical experience.
  • 5 years of experience in cybersecurity, security engineering, pen testing, cloud security, or technical vulnerability assessment.
  • Experience performing technical security validation, with Linux operating systems, networking concepts, and access controls.
  • Candidates must hold or be eligible to obtain a valid Personnel Security Clearance as a condition of employment.

Preferred qualifications:

  • Experience navigating security frameworks and leading Security Assessment and Authorization (SA&A) or Authority to Operate (ATO) processes in defense, government, or highly regulated environments.
  • Experience assessing and securing modern infrastructure, including cloud platforms, Kubernetes, containers, and distributed systems.
  • Experience with threat modeling (e.g., MITRE ATT&CK), manual pen testing, security assessment tooling, and automating security workflows using Python, Bash, or Ansible.
  • Knowledge of software supply-chain security, including Software Bill of Materials (SBOMs), Static Application Security Testing (SAST), and vulnerability management.
  • Excellent communication and cross-functional collaboration skills, complemented by industry-recognized security certifications (e.g., CISSP, OSCP, GCIH, or equivalent).

About the job

The Google Public Sector (GPS) Governance, Risk and Compliance team enables GPS business with public sector customers by supporting compliance across varied compliance regimes. We serve as a trusted advisor to the business by ensuring that public sector risk exposure is transparent and proactively managed. We promote the growth of Google Cloud’s Public Sector business by driving accountability, consistency, efficiency, and governance.

As a Security and Compliance Specialist within the Governance, Risk, and Compliance (GRC) team, you will serve as a technical security leader for critical, highly regulated cloud environments. You will ensure the security posture of specialized deployments, bridging the gap between rigorous compliance frameworks and technical validation. In this role, you will lead security assessments, vulnerability analysis, and architectural reviews to support mission-critical infrastructure. You will work closely with engineering, operations, and external partners to navigate complex security requirements and achieve required authorizations.

Google Public Sector brings the magic of Google to the mission of government and education with solutions purpose-built for enterprises. We focus on helping United States public sector institutions accelerate their digital transformations, and we continue to make significant investments and grow our team to meet the complex needs of local, state and federal government and educational institutions.

Individual pay is determined by factors including job-related skills, experience, and relevant education or training.

Canada: $128000 - $131000 (CAD) + 15% bonus target + equity + benefits

Learn more about benefits at Google.

Responsibilities

  • Lead technical security validation, including vulnerability assessments and penetration testing, for highly regulated cloud and Linux-based environments.
  • Drive Security Assessment and Authorization (SA&A) processes to secure Authorities to Operate (ATO) by translating complex security frameworks into actionable technical engineering requirements.
  • Automate routine security tasks and vulnerability management workflows using scripting languages and modern configuration assessment tools.
  • Partner with cross-functional teams—including product, engineering, and operations—to guide security architecture, threat modeling, and software supply-chain security.
  • Analyze complex technical security data to deliver clear, actionable mitigation recommendations to both technical and non-technical stakeholders.

Information collected and processed as part of your Google Careers profile, and any job applications you choose to submit is subject to Google's Applicant and Candidate Privacy Policy.

Google is proud to be an equal opportunity and affirmative action employer. We are committed to building a workforce that is representative of the users we serve, creating a culture of belonging, and providing an equal employment opportunity regardless of race, creed, color, religion, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition (including breastfeeding), expecting or parents-to-be, criminal histories consistent with legal requirements, or any other basis protected by law. See also Google's EEO Policy, Know your rights: workplace discrimination is illegal, Belonging at Google, and How we hire.

If you have a need that requires accommodation, please let us know by completing our Accommodations for Applicants form.

Google is a global company and, in order to facilitate efficient collaboration and communication globally, English proficiency is a requirement for all roles unless stated otherwise in the job posting.

To all recruitment agencies: Google does not accept agency resumes. Please do not forward resumes to our jobs alias, Google employees, or any other organization location. Google is not responsible for any fees related to unsolicited resumes.

Equity is granted exclusively and discretionarily by Alphabet Inc. on the basis of an agreement concluded between you and Alphabet Inc. Alphabet Inc. is your sole contractual partner with respect to equity grants. GSU grants are not guaranteed, are discretionary, are subject to approval by the Alphabet Inc. board of directors or its delegate, the terms of the relevant Alphabet Inc. stock plan, and your grant agreement. They have no impact on statutory payments. Current or past grants do not confer an acquired right.

Google apps
Main menu