Cloud Security Architecture Lead Analyst
Listed on 2026-01-01
-
IT/Tech
Cybersecurity, Systems Engineer
About Citi
Citi, the leading global bank, has approximately 200 million customer accounts and does business in more than 160 countries and jurisdictions. Citi provides consumers, corporations, governments, and institutions with a broad range of financial products and services, including consumer banking and credit, corporate and investment banking, securities brokerage, transaction services, and wealth management. As a bank with a brain and a soul, Citi creates economic value that is systemically responsible and in our clients’ best interests.
As a financial institution that touches every region of the world and every sector that shapes your daily life, our Enterprise Operations & Technology teams are charged with a mission that rivals any large tech company. Our technology solutions are the foundations of everything we do from keeping the bank safe, managing global resources, and providing the technical tools our workers need to be successful to designing our digital architecture and ensuring our platforms provide a first‑class customer experience.
We reimagine client and partner experiences to deliver excellence through secure, reliable, and efficient services. Our commitment to diversity includes a workforce that represents the clients we serve from all walks of life, backgrounds, and origins. We foster an environment where the best people want to work. We value and demand respect for others, promote individuals based on merit, and ensure opportunities for personal development are widely available to all.
of the Role
The Cloud Security Architecture Lead Analyst is responsible for defining and driving the Google Cloud Platform (GCP) security architecture across Citi’s global cloud initiatives, ensuring compliance with financial regulations, internal controls, and industry best practices. You will partner with Infrastructure Teams, Application Developers, Compliance Officers, and Risk Managers to embed secure design principles and mitigate evolving cloud threats in a highly regulated environment.
You will also drive a variety of engineering activities including the design, acquisition and deployment of hardware, software and network infrastructure in coordination with the Technology team. The overall objective of this role is to lead efforts to ensure quality standards are being met within existing and planned framework.
- Cloud Security Strategy: Develop and implement a comprehensive security strategy for Google Cloud that aligns with the organization’s business goals and compliance standards, such as GDPR, SOC 2, and HIPAA.
- Architecture Design: Develop security infrastructure architectures and frameworks, focusing on protecting sensitive data and mitigating risks across networks, storage, applications, and authentication services using automation across a hybrid cloud architecture.
- Data Security and Encryption: Design and enforce encryption and rest and in transit between all compute boundaries.
- Vulnerability Management: Proactively monitor GCP environments for vulnerabilities, manage threat detection, and ensure prompt response to potential security incidents.
- Cross‑Functional
Collaboration:
Work closely with engineering, development, SRE, and operations teams to enforce security policies and integrate security best practices into the development lifecycle. - Team Leadership and Training: Guide the security team, promote security awareness across the organization, and ensure compliance with industry standards (e.g., ISO 27001, NIST).
- 6 years of experience in a Security Architecture role.
- 6 years of experience in a Cloud Security Engineering role.
- GCP Expertise: In-depth understanding of GCP core infrastructure services, security services, encryption practices, and compliance frameworks. Deep understanding of GCP IAM, RBAC, Cloud Identity and Zero‑trust principles for managing secure access to data and applications in the cloud. Expertise in GCP networking, including VPC subnets, firewall configurations, Google Cloud VPN, etc.
- Scripting and Configuration Management: Experience with scripting and configuration management tools like Bash, Python, Ansible, Puppet, and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).