Security Accreditation Manager
Security Accreditation Manager
- linkCopy link
- emailEmail a friend
Minimum qualifications:
- Bachelor's degree in Computer Science, Information Security, or equivalent practical experience.
- 8 years of experience in security engineering, risk management, or compliance.
- Experience managing Security Assessment and Authorization (SA&A) lifecycles for the government of Canada systems.
- Active, or the ability to obtain, a Top Secret security clearance.
Preferred qualifications:
- Certifications such as CISSP, CCSP, CISM, or CAP.
- Experience in ITSG-33 security control profiles and Treasury Board (TBS) policy instruments.
- Experience identifying and managing risks with government assessment and authorization experts, business owners, or lead security agencies.
- Ability to author system security plans (SSP) and security requirements check lists (SRCL).
- Excellent communication skills with the ability to translate complex technical concepts into policy-compliant language for executive stakeholders.
About the job
The Cloud Cloud Chief Information Security Officer (CISO) Public Sector team is part of the CISO Risk and Compliance organization. The Risk and Compliance team supports Google Cloud by managing risks, ensuring accountability, defining and enforcing compliance standards, monitoring controls, and collaborating with stakeholders to meet evolving security, privacy and compliance requirements.
The Cloud CISO team ensures government and regulated industries can confidently use Google Cloud for workloads with strict security and residency requirements.
As the Security and Compliance Lead, you will bridge the gap between complex hyperscale cloud engineering and rigorous Government of Canada security frameworks and control profiles.
In this role, you will be responsible for the end-to-end accreditation package, ensuring that Google Cloud infrastructure meets the statutory requirements of the Government of Canada. You will work horizontally across engineering and product teams to translate technical reality into compliance authority, negotiating directly with government authorizing officials to enable the delivery of critical services.
Responsibilities
- Ensure in-scope Google Cloud information systems meet government of Canada requirements to obtain and maintain Authorization to Operate (ATO).
- Own the comprehensive security assessment and authorization (SA&A) lifecycle, including the security requirements traceability matrix (SRTM) system security plan (SSP), security assessment reports (SAR) and any other documentation required to maintain ongoing security authorization.
- Manage the plan of action and milestones (POA&M) to track and remediate vulnerabilities identified during the security assessment process.
- Lead initiatives to leverage Artificial Intelligence (AI) and automation to scale the security assessment and authorization (SA&A) process, identify opportunities to reduce operational toil in evidence collection and control mapping.
Information collected and processed as part of your Google Careers profile, and any job applications you choose to submit is subject to Google's Applicant and Candidate Privacy Policy.
Google is proud to be an equal opportunity and affirmative action employer. We are committed to building a workforce that is representative of the users we serve, creating a culture of belonging, and providing an equal employment opportunity regardless of race, creed, color, religion, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition (including breastfeeding), expecting or parents-to-be, criminal histories consistent with legal requirements, or any other basis protected by law. See also Google's EEO Policy, Know your rights: workplace discrimination is illegal, Belonging at Google, and How we hire.
If you have a need that requires accommodation, please let us know by completing our Accommodations for Applicants form.
Google is a global company and, in order to facilitate efficient collaboration and communication globally, English proficiency is a requirement for all roles unless stated otherwise in the job posting.
To all recruitment agencies: Google does not accept agency resumes. Please do not forward resumes to our jobs alias, Google employees, or any other organization location. Google is not responsible for any fees related to unsolicited resumes.