Security Accreditation Manager

Google Google · Big Tech · Ottawa, ON +1

The Security Accreditation Manager role at Google Cloud focuses on ensuring that Google Cloud infrastructure meets the statutory requirements of the Government of Canada for security and residency. This involves managing the end-to-end accreditation package, working with product teams to translate technical realities into compliance authority, and negotiating with government authorizing officials. The role also involves leveraging AI and automation to scale the security assessment and authorization process.

What you'd actually do

  1. Ensure in-scope Google Cloud information systems meet government of Canada requirements to obtain and maintain Authorization to Operate (ATO).
  2. Own the comprehensive security assessment and authorization (SA&A) lifecycle, including the security requirements traceability matrix (SRTM) system security plan (SSP), security assessment reports (SAR) and any other documentation required to maintain ongoing security authorization.
  3. Manage the plan of action and milestones (POA&M) to track and remediate vulnerabilities identified during the security assessment process.
  4. Lead initiatives to leverage Artificial Intelligence (AI) and automation to scale the security assessment and authorization (SA&A) process, identify opportunities to reduce operational toil in evidence collection and control mapping.

Skills

Required

  • Bachelor's degree in Computer Science, Information Security, or equivalent practical experience.
  • 8 years of experience in security development, risk management, or compliance.
  • Experience managing Security Assessment and Authorization (SA&A) lifecycles for the government of Canada systems.
  • Active, or the ability to obtain, a Top Secret security clearance.

Nice to have

  • Certifications such as CISSP, CCSP, CISM, or CAP.
  • Experience in ITSG-33 security control profiles and Treasury Board (TBS) policy instruments.
  • Experience identifying and managing risks with government assessment and authorization experts, business owners, or lead security agencies.
  • Ability to author system security plans (SSP) and security requirements check lists (SRCL).
  • Excellent communication skills with the ability to translate complex technical concepts into policy-compliant language for executive stakeholders.

What the JD emphasized

  • end-to-end accreditation package
  • statutory requirements of the Government of Canada
  • Government of Canada security frameworks and control profiles
  • security assessment and authorization (SA&A) lifecycle
  • security requirements traceability matrix (SRTM) system security plan (SSP), security assessment reports (SAR)
  • plan of action and milestones (POA&M)
  • security assessment process
  • security assessment and authorization (SA&A) process
  • government of Canada requirements
  • Authorization to Operate (ATO)
  • security assessment and authorization (SA&A) lifecycle
  • security requirements traceability matrix (SRTM) system security plan (SSP), security assessment reports (SAR)
  • plan of action and milestones (POA&M)
  • security assessment process
  • security assessment and authorization (SA&A) process
  • government of Canada systems
  • security clearance