GCP Enterprise Engineer - Remote
Key details
- Work type
- remote
- Employment
- contract
Job Description
Role Overview Serves as the dedicated Google Cloud engineer for GCP program, bringing deep Terraform expertise to develop, own, and deliver production-ready infrastructure automation modules, scaffolding, and implementation patterns.
This role leads the design and implementation of GCP automation solutions tailored to needs ensuring risk mitigation and compliance across systems with deliverables that meet agreed acceptance criteria and are handed off in a state ready for operationalization.
Key Responsibilities Develop, own, and deliver production-ready infrastructure automation modules, scaffolding, and implementation patterns. Lead the design and implementation of GCP automation solutions tailored to needs, ensuring risk mitigation and compliance across systems.
Build Terraform to enforce foundational and security standards e.g., Model Armor floor settings, Cloud Run load-balancer/certificate/DNS patterns, organization and hierarchical policy, and CSPM modules.
Restructure and maintain Terraform repositories: separate global/shared policies from perimeter-specific implementations, apply lifecycle tagging, and align to a versioned shared-module strategy.
Implement drift detection (scheduled terraform plan and Cloud Asset Inventory comparisons) and shift-left IaC security scanning (Checkov/tfsec) with CI/CD policy gates (OPA/Conftest).
Contribute to IAM centralization and the GCP-IAM repository migration Workload Identity Federation, custom roles, PAM assignments, service-account key lifecycle, and Secrets Manager best practices.
Deploy secure connectivity via IaC Shared VPCs, Private Service Connect endpoints, and VPC Service Controls perimeters (dry-run to enforced). Produce clear code documentation and READMEs; participate in code-review cycles and rework with client.
Ensure deliverables meet agreed acceptance criteria and are handed off ready for operationalization. Work closely with InfoSec, Network, and Infrastructure Automation teams to keep designs aligned and operationalizable.
Primary Deliverables Production-ready Terraform code, modules, and scaffolding meeting agreed acceptance criteria. Reusable, security-vetted shared modules (versioned) and repository-structure improvements. Drift-detection and IaC security-scanning integrations within CI/CD.
Code documentation and READMEs supporting operational handoff. Required Qualifications Extensive cloud / infrastructure engineering experience with deep, hands-on Google Cloud Platform delivery.
Expert-level Terraform / Infrastructure-as-Code building production modules, scaffolding, and repeatable implementation patterns. Strong GCP engineering skills: IAM, organization policy, Shared VPC, VPC Service Controls, Private Service Connect, and networking.
Hands-on CI/CD and policy-as-code (OPA/Conftest, Checkov, tfsec) with Git-based workflows and disciplined code review. Security- and compliance-oriented engineering (CMEK, least privilege, PII/PCI considerations).
Strong documentation habits (READMEs, runbooks) and a handoff / operationalization mindset. Preferred Qualifications Google Cloud Professional certifications (Cloud Engineer, DevOps Engineer, and/or Cloud Security Engineer).
Workload Identity Federation, Privileged Access Management (PAM), and Secrets Manager experience. Generative-AI infrastructure on GCP Model Armor, Model Garden, RAG Engine, and Vector Search deployment.
Cloud Asset Inventory-based drift detection and shared Terraform module ecosystems. Exposure to Azure / AKS integration and hybrid connectivity. Experience in large, regulated, enterprise-scale (e.g., retail) environments.
Core Technology Environment Google Cloud Platform; Terraform / Infrastructure-as-Code (modules, scaffolding, production patterns); IAM, organization policy, Shared VPC, VPC Service Controls, Private Service Connect, and CMEK; CI/CD and policy-as-code (OPA/Conftest, Checkov, tfsec); Workload Identity Federation, PAM, and Secrets Manager; Cloud Run; Model Armor / Model Garden and Vertex AI (RAG Engine, Vector Search); and Cloud Asset Inventory for drift detection.
Engagement Details & Working Arrangement Delivery model: Dedicated consulting resource embedded with GCP program, supporting the Product Teams Support workstream alongside the broader GCP Architecture Support and NCC Transition projects. Location: Remote (U.S.).
All work performed remotely via secure VPN/collaboration tooling.
Trust-check this listing
Verify scam risk and ghost-job signals before you apply.
Related roles
Browse more remote Software Engineer jobs, or every remote job category.
Source: Google Jobs • Last updated 3d ago