热门公司

招聘

职位Google

Security and Compliance Specialist

Google

Security and Compliance Specialist

Google

·

On-site

·

Full-time

·

2w ago

About the job

As a part of the CISO Risk and Compliance organization, the Cloud CISO Public Sector team supports Google Cloud by managing risks, ensuring accountability, defining and enforcing compliance standards, monitoring controls, and collaborating with stakeholders to meet evolving security, privacy and compliance requirements.

In this role, you will provide the mandatory separation of duties ensuring that our security controls are not just designed correctly, but are operating effectively in practice. You will sit at the intersection of engineering and compliance, validating technical controls through rigorous testing and evidence gathering. You will be the primary defender of our compliance posture during external audits, translating engineering data into audit-proof evidence. Your vigilance in monitoring for insider threats and maintaining audit readiness is key to sustaining our trusted status with government customers.

Google Cloud accelerates every organization’s ability to digitally transform its business and industry. We deliver enterprise-grade solutions that leverage Google’s cutting-edge technology, and tools that help developers build more sustainably. Customers in more than 200 countries and territories turn to Google Cloud as their trusted partner to enable growth and solve their most critical business problems.

The Canada base salary range for this full-time position is CAD 162,000-166,000 + bonus + equity + benefits. Our salary ranges are determined by role, level, and location. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training.

Please note that the compensation details listed in Canada role postings reflect the base salary only, and do not include bonus, equity, or benefits. Learn more about benefits at Google.

Responsibilities

  • Execute walkthroughs and sampling of security controls to validate operating effectiveness, providing security control assessment and validation separate from the engineering build team.

  • Maintain an audit-ready evidence repository and lead the response to external government assessments.

  • Sustain authorization posture through continuous monitoring, annual assessments, and change management processes aligned with government requirements.

  • Manage remediation plans and track the resolution of control deficiencies.

  • Perform Control Operating Effectiveness testing aligned with IT Audit methodologies (e.g., ISO 27001, SOC 2) applied to Government of Canada frameworks.

Minimum qualifications

  • Bachelor's degree in Information Systems, Accounting, Business, or equivalent practical experience.

  • 8 years of experience in IT Audit, Compliance, or Risk Management.

  • Experience performing Security Control Assessment and Control Operating Effectiveness testing.

  • Ability to obtain a Top Secret security clearance.

Preferred qualifications

  • Certifications such as CISA, CCSP, CISSP, or CIA.

  • Experience with IT Audit methodologies (e.g., ISO 27001, SOC 2, CSA STAR).

  • Experience managing Remediation Plans or Plan of Action and Milestones (PoA&M) tracking.

  • Familiarity with Insider Threat indicators and physical access log reviews.

  • Knowledge of Government of Canada regulatory instruments, with the ability to operationalize TBS policies and directives related to security, privacy, and information management.

总浏览量

0

申请点击数

0

模拟申请者数

0

收藏

0

关于Google

Google

Google

Public

Google specializes in internet-related services and products, including search, advertising, and software.

10,001+

员工数

Mountain View

总部位置

$1,700B

企业估值

评价

3.7

25条评价

工作生活平衡

3.8

薪酬

4.2

企业文化

3.4

职业发展

3.9

管理层

2.8

68%

推荐给朋友

优点

Excellent compensation and benefits

Smart and talented colleagues

Great perks and work flexibility

缺点

Management and leadership issues

Bureaucracy and slow processes

Constantly changing priorities and reorganizations

薪资范围

57,502个数据点

Mid/L4

Senior/L5

Mid/L4 · Technical Program Manager

1,213份报告

$365,196

年薪总额

基本工资

$187,658

股票

$130,822

奖金

$46,717

$242,776

$576,787

面试经验

9次面试

难度

3.4

/ 5

时长

14-28周

录用率

44%

体验

正面 0%

中性 56%

负面 44%

面试流程

1

Application Review

2

Online Assessment/Technical Screen

3

Phone Screen

4

Onsite/Virtual Interviews

5

Team Matching

6

Offer

常见问题

Coding/Algorithm

System Design

Behavioral/STAR

Technical Knowledge

Product Sense