Principal Security Architect, UK Security Operations
Must be a British citizen to meet customer and compliance requirements, including potential access to classified information. Minimum qualifications:
- Bachelor's degree in Computer Science, Cybersecurity, a related technical field, or equivalent practical experience.
- 8 years of experience in a customer-facing advisory role designing multi-cloud environments (e.g., IaaS, PaaS, and SaaS).
- Experience in defining secure architectural patterns and integrating security practices across the software development lifecycle (DevSecOps).
- Experience automating security controls and processes, including Infrastructure as Code (IaC) tools.
- Experience in critical security domains (e.g., network security, identity security, data security, application security).
- Previous or currently active UK Developed Vetting (DV) security clearance.
- Certifications in CISSP, CCSP, or relevant cloud-specific security credentials.
- Experience leading comprehensive threat modeling exercises and conducting detailed risk assessments for customer systems to identify security vulnerabilities.
- Experience in securing modern cloud-native architectures, including containerisation technologies (e.g., Kubernetes, Docker) and serverless computing.
- Experience in evaluating the integration of a range of security tools, such as SIEM, WAF, DLP, and CSPM.
- Understanding of security concerns associated with Generative AI and suitable mitigation strategies.
- Ability to articulate security concepts and recommendations to both technical and non-technical executive stakeholders.
- Act as the primary trusted security advisor for key public sector customers, providing consultation on security architecture, risk management, and compliance.
- Build and maintain, collaborative relationships with customer stakeholders (from technical teams to C-level), understanding their unique security needs and effectively communicating Google's security capabilities and best practices.
- Lead the design and review of secure solutions for customers on cloud platforms, ensuring secure configurations and demonstrating compliance pathways. Foster a security-aware culture within customer organisations, advocating security-by-design principles.
- Guide customers on security best practices, including embedding security into their CI/CD pipelines (DevSecOps) and adopting security automation.
- Guide customers in identifying, assessing, and mitigating cloud security risks specific to their environments and workloads. Translate security standards and regulations into practical, achievable implementation plans for customer architectures.