← Back to jobs
Milwaukee, WI, USA
No related jobs found
Key Responsibilities
• Design and deploy an enterprise landing zone covering organization, folder, and project structure, IAM, connectivity, logging, and security integrations, aligned to landing zone best practices.
• Migrate unmanaged Google accounts to managed identities and implement Entra-to-Google identity sync with full SSO and MFA.
• Consolidate projects into a single billing account to enable FinOps invoicing and chargeback.
• Establish network guardrails including public IP blocking policies, centralized VPCs and hub architecture, and private access and endpoints.
• Centralize audit logging and monitoring and integrate enterprise security tooling such as Wiz and CrowdStrike.
• Implement platform components as code (Terraform) with reusable, secure, policy-enforced modules.
• Document standards and operational runbooks to support handoff to platform and cloud operations teams.
Required Qualifications
• Hands-on GCP platform engineering experience, including Cloud Identity, IAM, org policy, VPC networking, and billing administration.
• Identity federation experience with Microsoft Entra ID, SSO, and MFA.
• Infrastructure as code proficiency with Terraform.
• Working knowledge of cloud security posture management and log and monitoring centralization.
• Experience taking a cloud environment from POC to enterprise-governed state.
Preferred
• Experience operating a second cloud (Azure) at enterprise scale.
• FinOps and chargeback model experience.
• Familiarity with Wiz, CrowdStrike, and manufacturing or regulated enterprise environments
Bachelor's degree
No related jobs found
← Back to jobs