
at Deloitte
Big FourPosted 6 days ago
No clicks
This employer did not include a short summary.
- Compensation
- $141,200 – $278,300 USD
- City
- Atlanta, Boston, Charlotte, Chicago, Cincinnati, Cleveland, Columbus, Costa Mesa, Dallas, Denver, Detroit, Hartford, Houston, Kansas City, Los Angeles, McLean, Miami, Minneapolis, Nashville, New York City, Philadelphia, Pittsburgh, Raleigh, Richmond, Sacramento, San Jose, Seattle, St. Louis, Stamford, Tampa
- Country
- United States
Currency: $ (USD)
Full Job Description
Deloitte US
- Home
- Jobs
- Entry level
- Experienced
- Global Firm Roles
- Events
- Login
Google Infrastructure and Security Lead Architect
Atlanta, Georgia, United States
Boston, Massachusetts, United States
Charlotte, North Carolina, United States
Chicago, Illinois, United States
Cincinnati, Ohio, United States
Cleveland, Ohio, United States
Columbus, Ohio, United States
Costa Mesa, California, United States
Dallas, Texas, United States
Denver, Colorado, United States
Detroit, Michigan, United States
Hartford, Connecticut, United States
Houston, Texas, United States
Kansas City, Missouri, United States
Los Angeles, California, United States
McLean, Virginia, United States
Miami, Florida, United States
Minneapolis, Minnesota, United States
Nashville, Tennessee, United States
New York, New York, United States
Philadelphia, Pennsylvania, United States
Pittsburgh, Pennsylvania, United States
Raleigh, North Carolina, United States
Richmond, Virginia, United States
Sacramento, California, United States
San Jose, California, United States
Seattle, Washington, United States
St. Louis, Missouri, United States
Stamford, Connecticut, United States
Tampa, Florida, United States
Caution against fraudulent job offers. Learn more.
Position Summary
AI & Engineering leverages cutting-edge engineering capabilities to build, deploy, and operate integrated/verticalized sector solutions in software, data, AI, network, and hybrid cloud infrastructure. These solutions are powered by engineering for business advantage, transforming mission-critical operations. We enable clients to stay ahead with the latest advancements by transforming engineering teams and modernizing technology & data platforms. Our delivery models are tailored to meet each client's unique requirements.
Engineering as a Service provides complete design, implementation, and technology operations, leveraging our core engineering expertise. We transform engineering teams, modernize technology, and deliver complex programs with a product engineering approach. Our flexible delivery modelstraditional teams, pools, or podsare tailored to each clients needs, offering engineering-led advisory, implementation, and operational capabilities to accelerate innovation.
Work youll do:
- Architect and deploy highly scalable, multi-tenant GCP landing zones utilizing structured resource hierarchies (Organizations, Folders, Projects) tailored to client governance and billing requirements.
- Design centralized identity and access strategies leveraging Google Cloud Identity, Single Sign-On (SSO), and role-based access control (RBAC). Implement Context-Aware Access and the Principle of Least Privilege (PoLP) to secure human and machine identities.
- Standardize and automate the deployment of cloud infrastructure using Terraform. Develop modular, reusable infrastructure code to ensure consistent, repeatable, and auditable environment provisioning.
- Design and implement robust network topologies, including Shared VPCs, Hub-and-Spoke models, and isolated subnets to control traffic flow and minimize the blast radius of potential incidents.
- Architect highly available and secure connections between on-premises data centers and Google Cloud using Dedicated/Partner Interconnect or High Availability (HA) Cloud VPN.
- Secure inbound and outbound traffic flows by implementing Cloud Armor for WAF and DDoS protection, hierarchical firewall policies, and VPC Service Controls to prevent data exfiltration.
- Evaluate existing on-premises or multi-cloud legacy workloads to define optimal migration blueprints, utilizing industry-standard patterns.
- Architect and deploy highly scalable, multi-tenant GCP platform utilizing structured resource hierarchies (Organizations, Folders, Projects) tailored to client governance and billing requirements.
- Guide development teams in modernizing applications by adopting GCP managed services, serverless computing (Cloud Run, Cloud Functions), and container orchestration platforms (Google Kubernetes Engine - GKE).
- Collaborate with data architects to ensure real-time streaming and batch ingestion pipelines (e.g., Pub/Sub, Dataflow, BigQuery) are architected with strict security boundaries and encryption standards.
- Integrate and tune Google Cloud Security Command Center (SCC Premium) to provide unified visibility into misconfigurations, vulnerabilities, and active threats.
- Architect strategies for data security at rest and in transit using Cloud KMS (including Customer-Managed Encryption Keys), GCP Secret Manager, and Cloud Data Loss Prevention (DLP).
- Develop and implement organization policies and Google Cloud Policy Library rules to establish automated security guardrails that prevent non-compliant resource deployments.
- Bachelor's degree in computer science, Information Technology, Cybersecurity, or a closely related technical field (or equivalent practical experience).
- 7-10+ years of hands-on experience in cloud architecture, infrastructure engineering, or cloud security, with a significant portion of that time dedicated to Google Cloud Platform environments.
- Strong practical experience writing and maintaining Infrastructure as Code (IaC) using Terraform, alongside familiarity with CI/CD tools (e.g., GitHub Actions, GitLab CI, Cloud Build).
- Proven track record of participating in/or leading enterprise-scale cloud migrations and modernizing legacy infrastructure.
- Ability to travel up to 50% based on the work you do and the clients and industries/sectors you serve.
- Limited immigration sponsorship may be available.
- 12+ years of comprehensive experience in cloud migration and security architecture, particularly in consulting, professional services, or client-facing advisory roles.
- Active status as a Google Cloud Professional Cloud Architect or Google Cloud Professional Cloud Security Engineer.
- Recognized cybersecurity certifications such as CISSP, CCSP, or CISM.
- Deep expertise in securing containerized workloads, Kubernetes (GKE) clusters, and microservice meshes (e.g., Anthos/Google Cloud Service Mesh).
- Strong ability to align technical designs with compliance frameworks such as NIST SP 800-53, CIS Benchmarks, SOC 2, HIPAA, or GDPR.
From developing a stand out resume to putting your best foot forward in the interview, we want you to feel prepared and confident as you explore opportunities at Deloitte. Check out recruiting tips from Deloitte recruiters.
At Deloitte, we know that great people make a great organization. We value our people and offer employees a broad range of benefits. Learn more about what working at Deloitte can mean for you.
Our inclusive culture empowers our people to be who they are, contribute their unique perspectives, and make a difference individually and collectively. It enables us to leverage different ways of thinking, ideas, and perspectives, and bring more creativity and innovation to help solve our clients' most complex challenges. This makes Deloitte one of the most rewarding places to work.
From entry-level employees to senior leaders, we believe theres always room to learn. We offer opportunities to build new skills, take on leadership opportunities and connect and grow through mentorship. From on-the-job learning experiences to formal development programs, our professionals have a variety of opportunities to continue to grow throughout their career.
Similar jobs
- Cyber Identity - CIAM Security Engineer/ConsultantMultiple Locations Cyber
- GPS HST Software Engineer IIIHermitage, Tennessee, United States Customer
- Security Operations LeadTallahassee, Florida, United States Cyber
- Project - Lead Software Engineer IIMultiple Locations AI & Engineering
- Associate Vice President, Engineering Delivery Management - Technical Project ManagerSan Diego, California, United States AI & Engineering
SCAM ALERT
Caution against fraudulent job offers!
We have been informed of instances where jobseekers are led to believe of fictitious job opportunities with Deloitte US (Deloitte). In one or more such cases, false promises of actual or potential selection, or initiation or completion of the recruitment formalities appear to have been or are being made. Some jobseekers appear to have been asked to pay money to specified bank accounts of individuals or entities as a condition of their selection for a job with Deloitte. These individuals or entities are in no way connected with Deloitte and do not represent or otherwise act on behalf of Deloitte.
We would like to clarify that:
- At Deloitte, ethics and integrity are fundamental and not negotiable.
- We are against corruption and neither offer bribes nor accept them, nor induce or permit any other party to make or receive bribes on our behalf.
- We have not authorized any party or person to collect any money from jobseekers in any form whatsoever for promises of getting jobs in Deloitte.
- We consider candidates on merit and that we provide an equal opportunity to eligible applicants.
- No one other than designated Deloitte personnel (e.g., a Deloitte recruiter or Deloitte hiring partner) is permitted to extend any job offer from Deloitte.
Anyone who at any time has made or makes any payment to any party in exchange for promises of job or selection for a job with Deloitte or any matter related to this (including those for registration, verification or security deposit) or otherwise engages with any such person who has made or makes fraudulent promises or offers, does so (or has done so) entirely at their own risk. Deloitte takes no responsibility or liability for any such unauthorized or fraudulent actions or engagements. We encourage jobseekers to exercise caution.
- About Deloitte
- Terms of use
- Privacy
- Data Privacy Framework
- Do Not Sell or Share My Personal Information
- Cookies
- Legal information for job seekers and ADA
- Labor condition applications
- Assistance for people with disabilities
2026. See Terms of Use for more information.
Deloitte refers to one or more of Deloitte Touche Tohmatsu Limited, a UK private company limited by guarantee ("DTTL"), its network of member firms, and their related entities. DTTL and each of its member firms are legally separate and independent entities. DTTL (also referred to as "Deloitte Global") does not provide services to clients. In the United States, Deloitte refers to one or more of the US member firms of DTTL, their related entities that operate using the "Deloitte" name in the United States and their respective affiliates. Certain services may not be available to attest clients under the rules and regulations of public accounting. Please see www.deloitte.com/about to learn more about our global network of member firms.
SIMILAR OPPORTUNITIES
Google Infrastructure and Security Lead Architect
Compensation
$141,200 – $278,300 USD
City: Atlanta, Boston, Charlotte, Chicago, Cincinnati, Cleveland, Columbus, Costa Mesa, Dallas, Denver, Detroit, Hartford, Houston, Kansas City, Los Angeles, McLean, Miami, Minneapolis, Nashville, New York City, Philadelphia, Pittsburgh, Raleigh, Richmond, Sacramento, San Jose, Seattle, St. Louis, Stamford, Tampa
Country: United States

This employer did not include a short summary.
Full Job Description
Deloitte US
- Home
- Jobs
- Entry level
- Experienced
- Global Firm Roles
- Events
- Login
Google Infrastructure and Security Lead Architect
Atlanta, Georgia, United States
Boston, Massachusetts, United States
Charlotte, North Carolina, United States
Chicago, Illinois, United States
Cincinnati, Ohio, United States
Cleveland, Ohio, United States
Columbus, Ohio, United States
Costa Mesa, California, United States
Dallas, Texas, United States
Denver, Colorado, United States
Detroit, Michigan, United States
Hartford, Connecticut, United States
Houston, Texas, United States
Kansas City, Missouri, United States
Los Angeles, California, United States
McLean, Virginia, United States
Miami, Florida, United States
Minneapolis, Minnesota, United States
Nashville, Tennessee, United States
New York, New York, United States
Philadelphia, Pennsylvania, United States
Pittsburgh, Pennsylvania, United States
Raleigh, North Carolina, United States
Richmond, Virginia, United States
Sacramento, California, United States
San Jose, California, United States
Seattle, Washington, United States
St. Louis, Missouri, United States
Stamford, Connecticut, United States
Tampa, Florida, United States
Caution against fraudulent job offers. Learn more.
Position Summary
AI & Engineering leverages cutting-edge engineering capabilities to build, deploy, and operate integrated/verticalized sector solutions in software, data, AI, network, and hybrid cloud infrastructure. These solutions are powered by engineering for business advantage, transforming mission-critical operations. We enable clients to stay ahead with the latest advancements by transforming engineering teams and modernizing technology & data platforms. Our delivery models are tailored to meet each client's unique requirements.
Engineering as a Service provides complete design, implementation, and technology operations, leveraging our core engineering expertise. We transform engineering teams, modernize technology, and deliver complex programs with a product engineering approach. Our flexible delivery modelstraditional teams, pools, or podsare tailored to each clients needs, offering engineering-led advisory, implementation, and operational capabilities to accelerate innovation.
Work youll do:
- Architect and deploy highly scalable, multi-tenant GCP landing zones utilizing structured resource hierarchies (Organizations, Folders, Projects) tailored to client governance and billing requirements.
- Design centralized identity and access strategies leveraging Google Cloud Identity, Single Sign-On (SSO), and role-based access control (RBAC). Implement Context-Aware Access and the Principle of Least Privilege (PoLP) to secure human and machine identities.
- Standardize and automate the deployment of cloud infrastructure using Terraform. Develop modular, reusable infrastructure code to ensure consistent, repeatable, and auditable environment provisioning.
- Design and implement robust network topologies, including Shared VPCs, Hub-and-Spoke models, and isolated subnets to control traffic flow and minimize the blast radius of potential incidents.
- Architect highly available and secure connections between on-premises data centers and Google Cloud using Dedicated/Partner Interconnect or High Availability (HA) Cloud VPN.
- Secure inbound and outbound traffic flows by implementing Cloud Armor for WAF and DDoS protection, hierarchical firewall policies, and VPC Service Controls to prevent data exfiltration.
- Evaluate existing on-premises or multi-cloud legacy workloads to define optimal migration blueprints, utilizing industry-standard patterns.
- Architect and deploy highly scalable, multi-tenant GCP platform utilizing structured resource hierarchies (Organizations, Folders, Projects) tailored to client governance and billing requirements.
- Guide development teams in modernizing applications by adopting GCP managed services, serverless computing (Cloud Run, Cloud Functions), and container orchestration platforms (Google Kubernetes Engine - GKE).
- Collaborate with data architects to ensure real-time streaming and batch ingestion pipelines (e.g., Pub/Sub, Dataflow, BigQuery) are architected with strict security boundaries and encryption standards.
- Integrate and tune Google Cloud Security Command Center (SCC Premium) to provide unified visibility into misconfigurations, vulnerabilities, and active threats.
- Architect strategies for data security at rest and in transit using Cloud KMS (including Customer-Managed Encryption Keys), GCP Secret Manager, and Cloud Data Loss Prevention (DLP).
- Develop and implement organization policies and Google Cloud Policy Library rules to establish automated security guardrails that prevent non-compliant resource deployments.
- Bachelor's degree in computer science, Information Technology, Cybersecurity, or a closely related technical field (or equivalent practical experience).
- 7-10+ years of hands-on experience in cloud architecture, infrastructure engineering, or cloud security, with a significant portion of that time dedicated to Google Cloud Platform environments.
- Strong practical experience writing and maintaining Infrastructure as Code (IaC) using Terraform, alongside familiarity with CI/CD tools (e.g., GitHub Actions, GitLab CI, Cloud Build).
- Proven track record of participating in/or leading enterprise-scale cloud migrations and modernizing legacy infrastructure.
- Ability to travel up to 50% based on the work you do and the clients and industries/sectors you serve.
- Limited immigration sponsorship may be available.
- 12+ years of comprehensive experience in cloud migration and security architecture, particularly in consulting, professional services, or client-facing advisory roles.
- Active status as a Google Cloud Professional Cloud Architect or Google Cloud Professional Cloud Security Engineer.
- Recognized cybersecurity certifications such as CISSP, CCSP, or CISM.
- Deep expertise in securing containerized workloads, Kubernetes (GKE) clusters, and microservice meshes (e.g., Anthos/Google Cloud Service Mesh).
- Strong ability to align technical designs with compliance frameworks such as NIST SP 800-53, CIS Benchmarks, SOC 2, HIPAA, or GDPR.
From developing a stand out resume to putting your best foot forward in the interview, we want you to feel prepared and confident as you explore opportunities at Deloitte. Check out recruiting tips from Deloitte recruiters.
At Deloitte, we know that great people make a great organization. We value our people and offer employees a broad range of benefits. Learn more about what working at Deloitte can mean for you.
Our inclusive culture empowers our people to be who they are, contribute their unique perspectives, and make a difference individually and collectively. It enables us to leverage different ways of thinking, ideas, and perspectives, and bring more creativity and innovation to help solve our clients' most complex challenges. This makes Deloitte one of the most rewarding places to work.
From entry-level employees to senior leaders, we believe theres always room to learn. We offer opportunities to build new skills, take on leadership opportunities and connect and grow through mentorship. From on-the-job learning experiences to formal development programs, our professionals have a variety of opportunities to continue to grow throughout their career.
Similar jobs
- Cyber Identity - CIAM Security Engineer/ConsultantMultiple Locations Cyber
- GPS HST Software Engineer IIIHermitage, Tennessee, United States Customer
- Security Operations LeadTallahassee, Florida, United States Cyber
- Project - Lead Software Engineer IIMultiple Locations AI & Engineering
- Associate Vice President, Engineering Delivery Management - Technical Project ManagerSan Diego, California, United States AI & Engineering
SCAM ALERT
Caution against fraudulent job offers!
We have been informed of instances where jobseekers are led to believe of fictitious job opportunities with Deloitte US (Deloitte). In one or more such cases, false promises of actual or potential selection, or initiation or completion of the recruitment formalities appear to have been or are being made. Some jobseekers appear to have been asked to pay money to specified bank accounts of individuals or entities as a condition of their selection for a job with Deloitte. These individuals or entities are in no way connected with Deloitte and do not represent or otherwise act on behalf of Deloitte.
We would like to clarify that:
- At Deloitte, ethics and integrity are fundamental and not negotiable.
- We are against corruption and neither offer bribes nor accept them, nor induce or permit any other party to make or receive bribes on our behalf.
- We have not authorized any party or person to collect any money from jobseekers in any form whatsoever for promises of getting jobs in Deloitte.
- We consider candidates on merit and that we provide an equal opportunity to eligible applicants.
- No one other than designated Deloitte personnel (e.g., a Deloitte recruiter or Deloitte hiring partner) is permitted to extend any job offer from Deloitte.
Anyone who at any time has made or makes any payment to any party in exchange for promises of job or selection for a job with Deloitte or any matter related to this (including those for registration, verification or security deposit) or otherwise engages with any such person who has made or makes fraudulent promises or offers, does so (or has done so) entirely at their own risk. Deloitte takes no responsibility or liability for any such unauthorized or fraudulent actions or engagements. We encourage jobseekers to exercise caution.
- About Deloitte
- Terms of use
- Privacy
- Data Privacy Framework
- Do Not Sell or Share My Personal Information
- Cookies
- Legal information for job seekers and ADA
- Labor condition applications
- Assistance for people with disabilities
2026. See Terms of Use for more information.
Deloitte refers to one or more of Deloitte Touche Tohmatsu Limited, a UK private company limited by guarantee ("DTTL"), its network of member firms, and their related entities. DTTL and each of its member firms are legally separate and independent entities. DTTL (also referred to as "Deloitte Global") does not provide services to clients. In the United States, Deloitte refers to one or more of the US member firms of DTTL, their related entities that operate using the "Deloitte" name in the United States and their respective affiliates. Certain services may not be available to attest clients under the rules and regulations of public accounting. Please see www.deloitte.com/about to learn more about our global network of member firms.




