> Markdown version of [/jobs/ext/3006398-google-infrastructure-and-security-lead-architect](https://www.wearedevelopers.com/jobs/ext/3006398-google-infrastructure-and-security-lead-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Google Infrastructure and Security Lead Architect - **Company:** Deloitte T.T.L. - **Location:** Columbus, OH, United States - **Experience:** Expert - **Salary:** $141,200.0 - $278,300.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, BigQuery, Cloud Computing, Cloud Computing Security, Cloud Database, Cloud Engineering, Software Documentation, CompTIA Security+, Cyber Security, Information Systems, Continuous Delivery, Continuous Integration, Data Centers, Data Security, DDoS Mitigation, Data Flow Control, Github, Network Topologies, Internet Security, Subnetting, Virtual Private Networks (VPN), Information Systems Security Architecture Professional, Systems Development Life Cycle, Role-Based Access Control, Migration Manager, Single Sign-On, Software Engineering, Data Streaming, User-Centered Design, Network Switches, Google Cloud, Computer Network Operations, Data Ingestion, Istio, System Availability, Multi-Cloud, HybridCloud, Firewalls (Computer Science), Build Server, Amazon Virtual Private Cloud (VPC), Containerization, Gitlab-ci, Kubernetes, Information Technology, Cybercrime, Data Management, CIS Benchmarks, Firewall Services Module, Terraform, Devsecops, Serverless Computing, Cisco, Microservices - **Published:** September 19, 2026 - **Apply:** https://www.careerbuilder.com/job-details/google-infrastructure-and-security-lead-architect-columbus-oh--8f01022b-367e-4d8a-9381-adc2172ca7d6 ## About the Role * Bachelor's degree in computer science, Information Technology, Cybersecurity, or a closely related technical field (or equivalent practical experience). * 7-10+ years of hands-on experience in cloud architecture, infrastructure engineering, or cloud security, with a significant portion of that time dedicated to Google Cloud Platform environments. * Strong practical experience writing and maintaining Infrastructure as Code (IaC) using Terraform, alongside familiarity with CI/CD tools (e.g., GitHub Actions, GitLab CI, Cloud Build). * Proven track record of participating in/or leading enterprise-scale cloud migrations and modernizing legacy infrastructure. * Ability to travel up to 50% based on the work you do and the clients and industries/sectors you serve. * Limited immigration sponsorship may be available., * 12+ years of comprehensive experience in cloud migration and security architecture, particularly in consulting, professional services, or client-facing advisory roles. * Active status as a Google Cloud Professional Cloud Architect or Google Cloud Professional Cloud Security Engineer. * Recognized cybersecurity certifications such as CISSP, CCSP, or CISM. * Deep expertise in securing containerized workloads, Kubernetes (GKE) clusters, and microservice meshes (e.g., Anthos/Google Cloud Service Mesh). * Strong ability to align technical designs with compliance frameworks such as NIST SP 800-53, CIS Benchmarks, SOC 2, HIPAA, or GDPR., Access Control, Artificial Intelligence (AI), Automation, Benchmarking, Billing, Blueprints, CCSP - Cisco Certified Security Professional, CISM - Certified Information Security Manager, CISSP - Certified Information Systems Security Professional, Cloud Architecture, Cloud Computing, Computer Science, Computer Security, Consulting, Continuous Deployment/Delivery, Continuous Integration, Cryptography, Customer Relations, Customer Support/Service, Denial of Service (DoS), Financial Management, Firewalls, GCP (Good Clinical Practices), GitHub, HIPAA (Health Insurance Portability and Accountability Act), High Availability, Hybrid Cloud, Incentive Programs, Industry Standards, Information Technology & Information Systems, Information/Data Security (InfoSec), Internet Security, Loss Prevention, Maintain Compliance, Microservices, Migration Strategy, Network Operations Center, Network Topology, Operations Processes, Operations Security (OPSEC), Policy Development, Policy Implementation, Product Engineering, Product Programs, Professional Services, Reengineering, Scalable System Development, Security Architecture, Security Attacks, Security Design, Single Sign-On (SSO), Software Development, Software Engineering, Subnet, Technical Delivery, Technical Leadership, Technical Operations, Technical Strategy, Technical/Engineering Design, U.S. National Institute of Standards and Technology (NIST), User Documentation, VPN (Virtual Private Network), Willing to Travel, Writing Skills ## Description Join our AI & Engineering team in transforming technology platforms, driving innovation, and helping make a significant impact on our clients' success. You'll work alongside talented professionals reimagining and re-engineering operations and processes that are critical to businesses. Your contributions can help clients improve financial performance, accelerate new digital ventures, and fuel growth through innovation. AI & Engineering leverages cutting-edge engineering capabilities to build, deploy, and operate integrated/verticalized sector solutions in software, data, AI, network, and hybrid cloud infrastructure. These solutions are powered by engineering for business advantage, transforming mission-critical operations. We enable clients to stay ahead with the latest advancements by transforming engineering teams and modernizing technology & data platforms. Our delivery models are tailored to meet each client's unique requirements. Engineering as a Service provides complete design, implementation, and technology operations, leveraging our core engineering expertise. We transform engineering teams, modernize technology, and deliver complex programs with a product engineering approach. Our flexible delivery models-traditional teams, pools, or pods-are tailored to each client's needs, offering engineering-led advisory, implementation, and operational capabilities to accelerate innovation. Recruiting for this role ends on 10-31-2026 Work you'll do: As a Google Cloud (GCP) Infrastructure & Security Lead Architect, you will serve as a strategic technical leader and trusted advisor for our enterprise clients, guiding them through complex cloud transformation journeys. In this role, you will bridge the gap between high-level business objectives and deep technical execution, focusing on building scalable, highly available, and deeply secure cloud environments. You will be responsible for the end-to-end design and implementation of foundational cloud architectures, from establishing secure multi-tenant landing zones and robust networking topologies to guiding application migration strategies. A critical component of this role is embedding security by design-leveraging Google Cloud's advanced security portfolio to protect workloads, secure data, and maintain continuous compliance against evolving cyber threats. You will collaborate closely with development, operations, and security teams to foster a culture of automation and DevSecOps excellence. Responsibilities include: * Architect and deploy highly scalable, multi-tenant GCP landing zones utilizing structured resource hierarchies (Organizations, Folders, Projects) tailored to client governance and billing requirements. * Design centralized identity and access strategies leveraging Google Cloud Identity, Single Sign-On (SSO), and role-based access control (RBAC). Implement Context-Aware Access and the Principle of Least Privilege (PoLP) to secure human and machine identities. * Standardize and automate the deployment of cloud infrastructure using Terraform. Develop modular, reusable infrastructure code to ensure consistent, repeatable, and auditable environment provisioning. * Design and implement robust network topologies, including Shared VPCs, Hub-and-Spoke models, and isolated subnets to control traffic flow and minimize the blast radius of potential incidents. * Architect highly available and secure connections between on-premises data centers and Google Cloud using Dedicated/Partner Interconnect or High Availability (HA) Cloud VPN. * Secure inbound and outbound traffic flows by implementing Cloud Armor for WAF and DDoS protection, hierarchical firewall policies, and VPC Service Controls to prevent data exfiltration. * Evaluate existing on-premises or multi-cloud legacy workloads to define optimal migration blueprints, utilizing industry-standard patterns. * Architect and deploy highly scalable, multi-tenant GCP platform utilizing structured resource hierarchies (Organizations, Folders, Projects) tailored to client governance and billing requirements. * Guide development teams in modernizing applications by adopting GCP managed services, serverless computing (Cloud Run, Cloud Functions), and container orchestration platforms (Google Kubernetes Engine - GKE). * Collaborate with data architects to ensure real-time streaming and batch ingestion pipelines (e.g., Pub/Sub, Dataflow, BigQuery) are architected with strict security boundaries and encryption standards. * Integrate and tune Google Cloud Security Command Center (SCC Premium) to provide unified visibility into misconfigurations, vulnerabilities, and active threats. * Architect strategies for data security at rest and in transit using Cloud KMS (including Customer-Managed Encryption Keys), GCP Secret Manager, and Cloud Data Loss Prevention (DLP). * Develop and implement organization policies and Google Cloud Policy Library rules to establish automated security guardrails that prevent non-compliant resource deployments. ## Related Videos - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves](https://www.wearedevelopers.com/videos/100220-rate-limiting-using-ebpf-and-istio-how-to-protect-your-saas-customers-from-themselves) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Top Must-Visit Developer Conferences in the US in 2026](https://www.wearedevelopers.com/magazine/679-top-must-visit-developer-conferences-in-the-us-in-2026)