CGI logo

Cloud Security Architect with IAM, GRC

CGIApplies on LinkedInEngineering & Development
Hiring from
United States
Work type
Hybrid
Posted
Oct 3, 2026
Is this job info correct?
Position Description

The best version of us starts with You!

We CGI is looking for a Cloud Security Architect with IAM, GRC to lead its identity, governance, compliance, and resilience workstreams.

In this client facing role you will assess identity and access management across Microsoft Entra ID, Active Directory, privileged access, and identity governance platforms; design the data governance operating model and target state data protection framework; build the regulatory register and control mapping; assess third party data risk; and evaluate cloud data protection and business resilience.

This is one of the most heavily loaded roles on the engagement, combining identity and cloud security architecture with data governance, risk, and compliance advisory, and running close to full time through the early assessment phase. You will report to the Engagement Lead, work closely with the Data Security & DLP Architect, lead six of the engagement's nine assessment domains, and own the identity and access management assessment, the data governance and data protection framework, and the risk, compliance, and resilience deliverables.

This is a Full-Time, On-Site employment opportunity located in Lafayette, LA or any CGI Office in a Hybrid Model.

Your future duties and responsibilities

  • Lead cross domain business unit interviews — approximately 40 to 55 sessions across 14 business units — and run data flow mapping workshops, gathering governance, compliance, and access evidence in the same sessions.
  • Own the Data Governance & Registration, Analytics & AI Governance, Regulatory/Privacy/Compliance, Third Party & Vendor Data Risk, Identity & Access Management, and Business Resilience domain assessments, including questionnaires, returns analysis, and follow on question sets.
  • Assess the data governance current state — operating model, stewardship across approximately 60 data stewards, ownership assignment, registration practice, and lifecycle management — and design the target state data protection framework: policies, standards, roles, accountability, and the data catalog operating model.
  • Reconcile discovery findings against data catalog and enterprise architecture baselines, triage unmanaged repositories with owners, produce the shadow data register, and drive catalog registration and ownership assignment to at least 70% completion.
  • Produce the regulatory register and control mapping across NERC CIP, NIST 800 53, PCI DSS, HIPAA, and applicable state privacy and public records laws; review privacy operations and the PIA process; and contribute regulatory interpretation of BES Cyber System Information, CEII, and public records exemptions to the sensitive information type catalog.
  • Analyze data risk across a population of approximately 340 vendors — tracker analysis, contractual coverage, tiering, and assurance gaps — and run the vendor management evidence program.
  • Collect IAM configuration and certification evidence from Microsoft Entra ID, Active Directory, CyberArk, and Saviynt, specifying the exports the client executes.
  • Assess role-based access control and least privilege practice across approximately 20 major applications, and review privileged access management, joiner mover leaver lifecycle, and service, non-human, and vendor identities.
  • Assess data protection controls across three cloud environments — encryption and key management, storage security, cloud native discovery, and data residency — and lead the resilience review of backup and immutability posture, RTO/RPO testing evidence, and data loss scenario readiness.
  • Produce subdomain scoring and prioritized remediation plans across governance, regulatory, third party, identity, and resilience; support discovery verification, cloud source scan scoping, and the enterprise deployment and target state architecture designs; and help specify least privilege, read only access to the cloud environments.

Required Qualifications To Be Successful In This Role

At least 10+ years of experience spanning across identity and access management, cloud security, data governance, and regulatory compliance advisory, with genuine depth in both assessment and design/implementation experience.

  • Strong Microsoft Entra ID and Active Directory depth, plus working knowledge of privileged access management (CyberArk or comparable) and identity governance (Saviynt or comparable).
  • Cloud security architecture across at least two of AWS, Azure, and GCP: encryption and key management, storage security, cloud native data discovery, and data residency.
  • Experience designing — not only assessing — data governance operating models, including stewardship structures, ownership accountability, and data catalog registration workflows and ownership campaigns (Collibra strongly preferred).
  • Working knowledge of NIST 800 53, PCI DSS, HIPAA, and state privacy and public records laws, with the ability to map obligations to specific controls rather than control families; familiarity with NERC CIP (particularly CIP 011) and CEII designation under FERC rules.
  • Third party and vendor data risk assessment at scale, including contractual data protection review, tiering methodology, and SOC 2 analysis including complementary user entity controls.
  • Backup, recovery, and resilience assessment experience, including the ability to judge whether a recovery capability has been proven rather than documented, and to assess access governance from a data protection standpoint.
  • Proven stakeholder facilitation at volume (40+ interviews) and relevant credentials: identity (CIMP, Entra ID certification, or CyberArk/Saviynt training), cloud security (CCSP or an AWS/Azure/GCP security specialty), and governance/compliance (CDMP, DCAM, CIPP/US, CIPM, CISA, or CRISC).

Education: Bachelor's degree in computer science on related field.

CGI is required by law in some jurisdictions to include a reasonable estimate of the compensation range for this role. The determination of this range includes various factors not limited to skill set, level, experience, relevant training, and licensure and certifications. To support the ability to reward for merit-based performance, CGI typically does not hire individuals at or near the top of the range for their role. Compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range for this role in the U.S. is $90,700.00 $267,800.00.

CGI's benefits are offered to eligible professionals on their first day of employment to include:

  • Competitive compensation
  • Comprehensive insurance options
  • Matching contributions through the 401(k) plan and the share purchase plan
  • Paid time off for vacation, holidays, and sick time
  • Paid parental leave
  • Learning opportunities and tuition assistance
  • Wellness and Well-being programs

Together, as owners, let’s turn meaningful insights into action.

Life at CGI is rooted in ownership, teamwork, respect and belonging. Here, you’ll reach your full potential because…

You are invited to be an owner from day 1 as we work together to bring our Dream to life. That’s why we call ourselves CGI Partners rather than employees. We benefit from our collective success and actively shape our company’s strategy and direction.

Your work creates value. You’ll develop innovative solutions and build relationships with teammates and clients while accessing global capabilities to scale your ideas, embrace new opportunities, and benefit from expansive industry and technology expertise.

You’ll shape your career by joining a company built to grow and last. You’ll be supported by leaders who care about your health and well-being and provide you with opportunities to deepen your skills and broaden your horizons.

Come join our team—one of the largest IT and business consulting services firms in the world.

Qualified applicants will receive consideration for employment without regard to their race, ethnicity, ancestry, color, sex, religion, creed, age, national origin, citizenship status, disability, pregnancy, medical condition, military and veteran status, marital status, sexual orientation or perceived sexual orientation, gender, gender identity, and gender expression, familial status or responsibilities, reproductive health decisions, political affiliation, genetic information, height, weight, or any other legally protected status or characteristics to the extent required by applicable federal, state, and/or local laws where we do business.

CGI provides reasonable accommodations to qualified individuals with disabilities. If you need an accommodation to apply for a job in the U.S., please email the CGI U.S. Employment Compliance mailbox at US_Employment_Compliance@cgi.com. You will need to reference the Position ID of the position in which you are interested. Your message will be routed to the appropriate recruiter who will assist you. Please note, this email address is only to be used for those individuals who need an accommodation to apply for a job. Emails for any other reason or those that do not include a Position ID will not be returned.

We make it easy to translate military experience and skills! Click here to be directed to our site that is dedicated to veterans and transitioning service members.

All CGI offers of employment in the U.S. are contingent upon the ability to successfully complete a background investigation. Background investigation components can vary dependent upon specific assignment and/or level of US government security clearance held. Dependent upon role and/or federal government security clearance requirements, and in accordance with applicable laws, some background investigations may include a credit check. CGI will consider for employment qualified applicants with arrests and conviction records in accordance with all local regulations and ordinances.

CGI will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with CGI’s legal duty to furnish information.

Similar jobs

Apply on LinkedIn