Design, implement, and maintain GCP infrastructure following best practices and platform standards.
Build and maintain Terraform modules and IaC patterns that are reusable, tested, and integrated into CI/CD pipelines.
Develop and operate automation for deployments and platform tooling using Cloud Build, GitHub Actions, and related tooling.
Implement and enforce cloud security controls: IAM least-privilege, Workload Identity, Secret Manager integrations, and organization policies.
Engineer GCP networking solutions including Shared VPC, VPC Service Controls, Private Service Connect, Cloud NAT and hybrid connectivity options.
Integrate observability and alerting (Cloud Operations Suite, Grafana, Datadog) and participate in incident response, root cause analysis, and remediation.
Maintain runbooks, SOPs, and technical documentation; mentor and coach junior engineers.
Qualifications
7+ years of cloud or infrastructure engineering experience with at least 3 years of hands-on GCP experience at enterprise scale.
Proven experience with Terraform and Infrastructure as Code, including module design, remote state, and CI/CD integration.
Strong programming/scripting skills in Python, Go, and Bash for automation and tooling tasks.
Familiarity with GCP services such as GKE, Cloud Run, Compute Engine, BigQuery, Pub/Sub, Cloud Storage, Cloud Composer, and network/security features like Cloud Armor.
Practical knowledge of IAM, Workload Identity, Secret Manager, Security Command Center, and policy-as-code approaches.
Hands-on experience with observability tools (Grafana, Cloud Operations Suite, Datadog) and SLO/SLI fundamentals.
Experience working in regulated environments and implementing controls for HIPAA, PCI, or SOC 2 compliance.
Preferred Qualifications
Google Professional Cloud Architect or Professional Cloud DevOps Engineer certification.
HashiCorp Terraform Associate certification.
FinOps experience: committed use discounts, rightsizing, and cost allocation tagging