Cloud Security Architect with IAM, GRC
Lafayette, IN - USA
Job Summary
The best version of us starts with You!
We CGI is looking for a Cloud Security Architect with IAM GRC to lead its identity governance compliance and resilience workstreams.
In this client facing role you will assess identity and access management across Microsoft Entra ID Active Directory privileged access and identity governance platforms; design the data governance operating model and target state data protection framework; build the regulatory register and control mapping; assess third party data risk; and evaluate cloud data protection and business resilience.
This is one of the most heavily loaded roles on the engagement combining identity and cloud security architecture with data governance risk and compliance advisory and running close to full time through the early assessment phase. You will report to the Engagement Lead work closely with the Data Security & DLP Architect lead six of the engagements nine assessment domains and own the identity and access management assessment the data governance and data protection framework and the risk compliance and resilience deliverables.
This is a Full-Time On-Site employment opportunity located in Lafayette LA or any CGI Office in a Hybrid Model.
.Lead cross domain business unit interviews approximately 40 to 55 sessions across 14 business units and run data flow mapping workshops gathering governance compliance and access evidence in the same sessions.
.Own the Data Governance & Registration Analytics & AI Governance Regulatory/Privacy/Compliance Third Party & Vendor Data Risk Identity & Access Management and Business Resilience domain assessments including questionnaires returns analysis and follow on question sets.
.Assess the data governance current state operating model stewardship across approximately 60 data stewards ownership assignment registration practice and lifecycle management and design the target state data protection framework: policies standards roles accountability and the data catalog operating model.
.Reconcile discovery findings against data catalog and enterprise architecture baselines triage unmanaged repositories with owners produce the shadow data register and drive catalog registration and ownership assignment to at least 70% completion.
.Produce the regulatory register and control mapping across NERC CIP NIST 800 53 PCI DSS HIPAA and applicable state privacy and public records laws; review privacy operations and the PIA process; and contribute regulatory interpretation of BES Cyber System Information CEII and public records exemptions to the sensitive information type catalog.
.Analyze data risk across a population of approximately 340 vendors tracker analysis contractual coverage tiering and assurance gaps and run the vendor management evidence program.
.Collect IAM configuration and certification evidence from Microsoft Entra ID Active Directory CyberArk and Saviynt specifying the exports the client executes.
.Assess role-based access control and least privilege practice across approximately 20 major applications and review privileged access management joiner mover leaver lifecycle and service non-human and vendor identities.
.Assess data protection controls across three cloud environments encryption and key management storage security cloud native discovery and data residency and lead the resilience review of backup and immutability posture RTO/RPO testing evidence and data loss scenario readiness.
.Produce subdomain scoring and prioritized remediation plans across governance regulatory third party identity and resilience; support discovery verification cloud source scan scoping and the enterprise deployment and target state architecture designs; and help specify least privilege read only access to the cloud environments.
At least 10 years of experience spanning across identity and access management cloud security data governance and regulatory compliance advisory with genuine depth in both assessment and design/implementation experience.
. Strong Microsoft Entra ID and Active Directory depth plus working knowledge of privileged access management (CyberArk or comparable) and identity governance (Saviynt or comparable).
. Cloud security architecture across at least two of AWS Azure and GCP: encryption and key management storage security cloud native data discovery and data residency.
. Experience designing not only assessing data governance operating models including stewardship structures ownership accountability and data catalog registration workflows and ownership campaigns (Collibra strongly preferred).
. Working knowledge of NIST 800 53 PCI DSS HIPAA and state privacy and public records laws with the ability to map obligations to specific controls rather than control families; familiarity with NERC CIP (particularly CIP 011) and CEII designation under FERC rules.
. Third party and vendor data risk assessment at scale including contractual data protection review tiering methodology and SOC 2 analysis including complementary user entity controls.
. Backup recovery and resilience assessment experience including the ability to judge whether a recovery capability has been proven rather than documented and to assess access governance from a data protection standpoint.
. Proven stakeholder facilitation at volume (40 interviews) and relevant credentials: identity (CIMP Entra ID certification or CyberArk/Saviynt training) cloud security (CCSP or an AWS/Azure/GCP security specialty) and governance/compliance (CDMP DCAM CIPP/US CIPM CISA or CRISC).
Education: Bachelors degree in computer science on related field.
#LI-ARK1
CGI is required by law in some jurisdictions to include a reasonable estimate of the compensation range for this role. The determination of this range includes various factors not limited to skill set level experience relevant training and licensure and certifications. To support the ability to reward for merit-based performance CGI typically does not hire individuals at or near the top of the range for their role. Compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range for this role in the U.S. is $90700.00 $267800.00.
CGIs benefits are offered to eligible professionals on their first day of employment to include:
. Competitive compensation
. Comprehensive insurance options
. Matching contributions through the 401(k) plan and the share purchase plan
. Paid time off for vacation holidays and sick time
. Paid parental leave
. Learning opportunities and tuition assistance
. Wellness and Well-being programs
- Data Governance
- Access Management
- Cloud architecture
- Compliance
- Identity Governance Admin
Together as owners lets turn meaningful insights into action.
Life at CGI is rooted in ownership teamwork respect and belonging. Here youll reach your full potential because
You are invited to be an owner from day 1 as we work together to bring our Dream to life. Thats why we call ourselves CGI Partners rather than employees. We benefit from our collective success and actively shape our companys strategy and direction.
Your work creates value. Youll develop innovative solutions and build relationships with teammates and clients while accessing global capabilities to scale your ideas embrace new opportunities and benefit from expansive industry and technology expertise.
Youll shape your career by joining a company built to grow and last. Youll be supported by leaders who care about your health and well-being and provide you with opportunities to deepen your skills and broaden your horizons.
Come join our teamone of the largest IT and business consulting services firms in the world.
Qualified applicants will receive consideration for employment without regard to their race ethnicity ancestry color sex religion creed age national origin citizenship status disability pregnancy medical condition military and veteran status marital status sexual orientation or perceived sexual orientation gender gender identity and gender expression familial status or responsibilities reproductive health decisions political affiliation genetic information height weight or any other legally protected status or characteristics to the extent required by applicable federal state and/or local laws where we do business.
CGI provides reasonable accommodations to qualified individuals with disabilities. If you need an accommodation to apply for a job in the U.S. please email the CGI U.S. Employment Compliance mailbox at . You will need to reference the Position ID of the position in which you are interested. Your message will be routed to the appropriate recruiter who will assist you. Please note this email address is only to be used for those individuals who need an accommodation to apply for a job. Emails for any other reason or those that do not include a Position ID will not be returned.
We make it easy to translate military experience and skills! Click here to be directed to our site that is dedicated to veterans and transitioning service members.
All CGI offers of employment in the U.S. are contingent upon the ability to successfully complete a background investigation. Background investigation components can vary dependent upon specific assignment and/or level of US government security clearance held. Dependent upon role and/or federal government security clearance requirements and in accordance with applicable laws some background investigations may include a credit check. CGI will consider for employment qualified applicants with arrests and conviction records in accordance with all local regulations and ordinances.
CGI will not discharge or in any other manner discriminate against employees or applicants because they have inquired about discussed or disclosed their own pay or the pay of another employee or applicant. However employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information unless the disclosure is (a) in response to a formal complaint or charge (b) in furtherance of an investigation proceeding hearing or action including an investigation conducted by the employer or (c) consistent with CGIs legal duty to furnish information.
Required Experience:
Staff IC
About Company
The COMPANY is one of the few end-to-end consulting firms with the scale, reach, capabilities and commitment to meet clients’ enterprise digital transformation needs. Our 77,500 consultants and professionals work side-by-side with clients in 10 industries across more than 400 location ... View more