JobFlexy

Technical Security and Compliance Analyst – Google – Ottawa, ON

Location: Ottawa, ON | Company: Google

Google Public Sector’s Governance, Risk and Compliance team is hiring a Technical Security and Compliance Analyst based in Ottawa, Ontario. This is a senior-level cybersecurity role within a team that supports compliance across varied public sector regulatory frameworks—bridging rigorous government compliance requirements with hands-on technical security validation in highly regulated cloud environments.

Sponsored Links

You’ll serve as a technical security leader, ensuring the security posture of specialized deployments by leading vulnerability assessments, penetration testing, and architectural reviews. The work spans everything from navigating complex Security Assessment and Authorization (SA&A) processes to partnering with engineering and operations teams on threat modeling and software supply-chain security.

About the Role: Technical Security and Compliance Analyst

At the core of this position is the need to translate complex security compliance frameworks into actionable technical engineering requirements. You’ll lead security assessments and penetration testing for Linux-based and cloud infrastructure, analyze vulnerability data, and deliver mitigation recommendations that speak clearly to both technical teams and non-technical stakeholders.

This role also carries a personnel security clearance requirement—candidates must hold or be eligible to obtain a valid clearance as a condition of employment. You’ll work across Google Cloud’s public sector deployments, supporting mission-critical infrastructure for government and education institutions across Canada and the United States.

Sponsored Links

Benefits and Salary

The compensation for this role in Canada is $128,000–$131,000 CAD annually, with a 15% bonus target, equity, and a comprehensive benefits package. Additional details about Google’s benefits can be found on their careers page. Individual pay is determined by job-related skills, experience, and relevant education or training.

Job Details

🏢 Company: Google

📍 Location: Ottawa, ON, Canada

🆔 Requisition ID: 97606019684672198

💰 Pay: $128,000–$131,000 CAD/year + 15% bonus target + equity + benefits

Responsibilities

Day-to-day, you’ll be working at the intersection of technical security validation and compliance governance—running hands-on assessments while also guiding engineering teams through complex security architecture decisions. These responsibilities require both deep technical knowledge and the ability to communicate clearly across functions.

  • Lead technical security validation, including vulnerability assessments and penetration testing, for highly regulated cloud and Linux-based environments
  • Drive Security Assessment and Authorization (SA&A) processes to secure Authorities to Operate (ATO) by translating complex security frameworks into actionable technical engineering requirements
  • Automate routine security tasks and vulnerability management workflows using scripting languages and modern configuration assessment tools
  • Partner with cross-functional teams—including product, engineering, and operations—to guide security architecture, threat modeling, and software supply-chain security
  • Analyze complex technical security data to deliver clear, actionable mitigation recommendations to both technical and non-technical stakeholders

Requirements / Skills

The ideal candidate brings a strong foundation in cybersecurity engineering with hands-on experience in regulated environments—particularly government or defence contexts. Google values professionals who can operate independently on complex assessments while collaborating effectively across teams and communicating security risks clearly at all levels.

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, a related technical field, or equivalent practical experience
  • 5 years of experience in cybersecurity, security engineering, pen testing, cloud security, or technical vulnerability assessment
  • Technical security validation experience with Linux operating systems, networking concepts, and access controls
  • Personnel Security Clearance: candidates must hold or be eligible to obtain a valid clearance as a condition of employment
  • Experience with SA&A or ATO processes in defence, government, or highly regulated environments (preferred)
  • Cloud and container security experience, including Kubernetes, containers, and distributed systems (preferred)
  • Threat modeling and automation skills using MITRE ATT&CK, manual pen testing, Python, Bash, or Ansible (preferred)
  • Knowledge of software supply-chain security, including SBOMs, SAST, and vulnerability management (preferred)
  • Industry-recognized certifications such as CISSP, OSCP, GCIH, or equivalent (preferred)

How to Apply

To apply, visit the official Google Careers job posting using the link below. Make sure your resume is up to date and tailored to reflect your cybersecurity and compliance experience before submitting.

Share This Opportunity

Know someone who might be interested? Share this job posting and help them join Google in Ottawa.

Job Summary & Tips for Applying

AI-generated summary and tips to help you highlight your strengths effectively.

Quick Summary & What to Highlight: This Technical Security and Compliance Analyst role at Google in Ottawa is perfect for candidates who excel in technical security validation, compliance framework navigation, and cloud security engineering. On your resume, emphasize any experience with SA&A or ATO processes, vulnerability assessments, and penetration testing in regulated environments. If you’ve previously worked in government, defence, or public sector cybersecurity, make sure to highlight specific achievements and responsibilities that align with this position.

Resume & Application Tips: Before applying, tailor your resume to match the job description. Include keywords like Security Assessment and Authorization, Authority to Operate, and vulnerability management that appear in the posting. Quantify your achievements where possible (e.g., “led SA&A process for 3 cloud environments, achieving ATO within 90 days” or “automated vulnerability workflows reducing remediation time by 40%”). Write a brief cover letter expressing your genuine interest in Google Public Sector and why you’re drawn to this compliance and security leadership opportunity in Ottawa. Double-check your application for spelling errors and ensure your contact information is current.

Interview Preparation: If selected for an interview, research Google Public Sector‘s mission, its work with government and education institutions, and its approach to cloud security and compliance. Prepare specific examples using the STAR method (Situation, Task, Action, Result) to demonstrate your technical security assessment and cross-functional collaboration skills. Common questions may include scenarios about navigating complex compliance frameworks, communicating risk to non-technical stakeholders, and leading penetration testing engagements. Dress appropriately for a professional technology and government sector environment, arrive 10–15 minutes early (or log in early for virtual interviews), and bring copies of your resume. Prepare thoughtful questions about the role’s scope, the GRC team structure, and security clearance timelines. After the interview, send a thank-you email within 24 hours reiterating your interest in the position.

Recommended Job Offers

More Google openings near Ottawa, ON