Cloud Security Architect with IAM, GRC

CGI•Lafayette, LA
•Hybrid

About The Position

CGI is seeking a Cloud Security Architect with expertise in Identity and Access Management (IAM) and Governance, Risk, and Compliance (GRC) to lead critical workstreams. This client-facing role involves assessing IAM across Microsoft Entra ID, Active Directory, and privileged access platforms, designing data governance operating models and data protection frameworks, building regulatory registers and control mappings, evaluating third-party data risk, and assessing cloud data protection and business resilience. This is a demanding, near full-time role during the assessment phase, reporting to the Engagement Lead. The architect will collaborate with the Data Security & DLP Architect, lead six of the nine assessment domains, and be responsible for IAM assessment, data governance and protection framework, and risk, compliance, and resilience deliverables.

Requirements

  • At least 10+ years of experience spanning identity and access management, cloud security, data governance, and regulatory compliance advisory, with depth in both assessment and design/implementation.
  • Strong Microsoft Entra ID and Active Directory expertise.
  • Working knowledge of privileged access management (CyberArk or comparable) and identity governance (Saviynt or comparable).
  • Cloud security architecture experience across at least two of AWS, Azure, and GCP, including encryption and key management, storage security, cloud-native data discovery, and data residency.
  • Experience designing data governance operating models, including stewardship structures, ownership accountability, and data catalog registration workflows and ownership campaigns (Collibra strongly preferred).
  • Working knowledge of NIST 800 53, PCI DSS, HIPAA, and state privacy and public records laws, with the ability to map obligations to specific controls.
  • Familiarity with NERC CIP (particularly CIP 011) and CEII designation under FERC rules.
  • Experience with third-party and vendor data risk assessment at scale, including contractual data protection review, tiering methodology, and SOC 2 analysis.
  • Backup, recovery, and resilience assessment experience, including the ability to judge proven recovery capabilities and assess access governance from a data protection standpoint.
  • Proven stakeholder facilitation skills (40+ interviews).
  • Relevant credentials: identity (CIMP, Entra ID certification, or CyberArk/Saviynt training), cloud security (CCSP or an AWS/Azure/GCP security specialty), and governance/compliance (CDMP, DCAM, CIPP/US, CIPM, CISA, or CRISC).
  • Bachelor's degree in computer science or related field.

Nice To Haves

  • Experience with Collibra for data governance.

Responsibilities

  • Lead cross-domain business unit interviews (40-55 sessions across 14 business units) and data flow mapping workshops, gathering governance, compliance, and access evidence.
  • Own assessments for Data Governance & Registration, Analytics & AI Governance, Regulatory/Privacy/Compliance, Third Party & Vendor Data Risk, Identity & Access Management, and Business Resilience, including questionnaires, returns analysis, and follow-on questions.
  • Assess current state data governance (operating model, stewardship, ownership, registration, lifecycle management) and design the target state data protection framework (policies, standards, roles, accountability, data catalog operating model).
  • Reconcile discovery findings with data catalog and enterprise architecture baselines, triage unmanaged repositories, produce the shadow data register, and drive catalog registration and ownership assignment to at least 70% completion.
  • Produce the regulatory register and control mapping for NERC CIP, NIST 800 53, PCI DSS, HIPAA, and applicable state privacy and public records laws; review privacy operations and PIA process; and contribute regulatory interpretation of sensitive information types.
  • Analyze data risk across approximately 340 vendors, including tracker analysis, contractual coverage, tiering, and assurance gaps, and manage the vendor management evidence program.
  • Collect IAM configuration and certification evidence from Microsoft Entra ID, Active Directory, CyberArk, and Saviynt.
  • Assess role-based access control and least privilege practices across approximately 20 major applications, and review privileged access management, joiner-mover-leaver lifecycles, and various identity types (service, non-human, vendor).
  • Assess data protection controls across three cloud environments (encryption, key management, storage security, cloud-native discovery, data residency) and lead resilience reviews (backup, immutability, RTO/RPO testing, data loss scenario readiness).
  • Produce subdomain scoring and prioritized remediation plans, support discovery verification, cloud source scan scoping, enterprise deployment and target state architecture designs, and specify least privilege access to cloud environments.

Benefits

  • Competitive compensation
  • Comprehensive insurance options
  • Matching contributions through the 401(k) plan
  • Share purchase plan
  • Paid time off for vacation, holidays, and sick time
  • Paid parental leave
  • Learning opportunities and tuition assistance
  • Wellness and Well-being programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service