Principal Cloud Security Architect - Google Cloud Platform; GCP
Listed on 2026-09-04
-
IT/Tech
Cybersecurity, Cloud Computing: Infrastructure & Operations, Systems Engineer, Information Security & Data Protection
Principal Cloud Security Architect - Google Cloud Platform (GCP)
The Cyber Security Architecture (CSA) team within ADP's Global Security Organization (GSO) is responsible for the research, design, and standardization of ADP's integrated global protection and security infrastructure. The CSA team is responsible for leading these efforts for ADP worldwide across a broad set of security disciplines providing an integrated security ecosystem to detect, defend, and respond to business impacting cyber and physical security, data protection, and fraud prevention.
The CSA team must have strong skills in conducting technical analysis of security and business problems, as well as threats, incidents, investigations, and other general security related issues.
We are seeking a Principal Cloud Security Architect to join our Cyber Security Architecture team and serve as a senior technical authority for securing cloud environments across the enterprise's Google Cloud Platform (GCP) and Microsoft Azure environment. This role will define and drive cloud security architecture, engineering standards, and security solutions across a complex global enterprise environment. The successful candidate will have deep hands-on expertise designing and implementing security capabilities in GCP and Azure, with the ability to translate enterprise security requirements into scalable, resilient, and practical technical architectures.
The Principal Cloud Security Architect will partner closely with cloud engineering, infrastructure, application development, identity, network security, risk, and compliance teams. This is a highly technical role requiring strong architecture skills, technical leadership, and the ability to influence security outcomes across the ADP organization.
Responsibilities:
- Design and evolve the security architecture of GCP and other public clouds including configuration, threat protection, network security, data protection and Identity and Access Management.
- Architect secure cloud landing zones, organizational structures, subscriptions/projects, accounts, policies, and governance models.
- Define cloud data security architectures, including encryption, key management, secrets management, data classification, and protection of sensitive workloads.
- Document security standards, requirements, and best practices for the use of GCP, Azure and other public clouds.
- Architect secure connectivity and segmentation across cloud, on-premises, and hybrid environments.
- Establish security architecture patterns, guardrails, controls, and engineering standards for GCP and Azure environments.
- Providing internal security consulting services for ADP applications, and IT shared services in GCP and other public clouds.
- Motivate and lead cross functional teams through effective communication, delegation, and prioritization.
- Establish cloud security monitoring, logging, detection, and incident-response architectures in partnership with security operations teams.
- Evaluate emerging cloud technologies and security capabilities and determine their applicability to enterprise environments.
- Influence technology strategy and security roadmaps across a global enterprise and communicate complex technical risks and recommendations to senior leadership.
To Succeed in This Role:
- You'll have a bachelors degree or equivalent.
Preferred Experience:
- 10+ years of experience in IT Security/cybersecurity, cloud security, security architecture, infrastructure security, or a closely related discipline.
- 7+ years of hands-on experience designing and implementing cloud security solutions, with significant expertise in both GCP and Azure.
- Demonstrated experience architecting security solutions for large-scale enterprise cloud environments.
- Deep technical knowledge of GCP security architecture and services, including IAM, organization/resource hierarchy, VPC security, Organization Policy, VPC Service Controls, Cloud KMS, Security Command Center, Cloud Armor, logging, monitoring, and workload security.
- Deep technical knowledge of Azure security architecture and services, including Entra , Azure Policy, Defender for Cloud, Key Vault, networking/security controls, Sentinel, Private Link, and workload security.
- Strong understanding of cloud identity and access management, including least privilege, RBAC, privileged access, workload identities, service principals/service accounts, federation, and identity governance.
- Strong understanding of cloud networking and security, including segmentation, firewalls, private connectivity, DNS, routing, ingress/egress controls, zero-trust architectures, and hybrid connectivity.
- Experience designing security controls for containers, Kubernetes, serverless workloads, APIs, VMs, and cloud-native applications.
- Strong understanding of cloud data protection, encryption, key management, secrets management, and data security architectures.
- Hands-on experience with Infrastructure as Code and automation, preferably Terraform, and experience implementing security through…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).