GCP Enterprise Engineer - Remote

Calance Consulting Corporation
United States
19 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
$166,400.0 - $208,000.0
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Microsoft Azure Cloud Computing Cloud Computing Security Cloud Engineering Software Documentation Code Review Cyber Security Continuous Integration DevOps Domain Name System (DNS) Federated Identity Management
+13 more
Identity and Access Management Virtual Private Networks (VPN) Role-Based Access Control Runbook Search Technologies Policy as Code Google Cloud Load Balancing Generative AI Amazon Virtual Private Cloud (VPC) Git Flow Infrastructure Automation Frameworks Terraform

Job description

Serves as the dedicated Google Cloud engineer for GCP program, bringing deep Terraform expertise to develop, own, and deliver production-ready infrastructure automation modules, scaffolding, and implementation patterns. This role leads the design and implementation of GCP automation solutions tailored to needs ensuring risk mitigation and compliance across systems with deliverables that meet agreed acceptance criteria and are handed off in a state ready for operationalization., Develop, own, and deliver production-ready infrastructure automation modules, scaffolding, and implementation patterns. Lead the design and implementation of GCP automation solutions tailored to needs, ensuring risk mitigation and compliance across systems. Build Terraform to enforce foundational and security standards e.g., Model Armor floor settings, Cloud Run load-balancer/certificate/DNS patterns, organization and hierarchical policy, and CSPM modules. Restructure and maintain Terraform repositories: separate global/shared policies from perimeter-specific implementations, apply lifecycle tagging, and align to a versioned shared-module strategy. Implement drift detection (scheduled terraform plan and Cloud Asset Inventory comparisons) and shift-left IaC security scanning (Checkov/tfsec) with CI/CD policy gates (OPA/Conftest). Contribute to IAM centralization and the GCP-IAM repository migration Workload Identity Federation, custom roles, PAM assignments, service-account key lifecycle, and Secrets

Manager best practices. Deploy secure connectivity via IaC Shared VPCs, Private Service Connect endpoints, and VPC Service Controls perimeters (dry-run to enforced). Produce clear code documentation and READMEs; participate in code-review cycles and rework with client. Ensure deliverables meet agreed acceptance criteria and are handed off ready for operationalization. Work closely with InfoSec, Network, and Infrastructure Automation teams to keep designs aligned and operationalizable.

Primary Deliverables Production-ready Terraform code, modules, and scaffolding meeting agreed acceptance criteria. Reusable, security-vetted shared modules (versioned) and repository-structure improvements. Drift-detection and IaC security-scanning integrations within CI/CD. Code documentation and READMEs supporting operational handoff., Google Cloud Platform; Terraform / Infrastructure-as-Code (modules, scaffolding, production patterns); IAM, organization policy, Shared VPC, VPC Service Controls, Private Service Connect, and CMEK; CI/CD and policy-as-code (OPA/Conftest, Checkov, tfsec); Workload Identity Federation, PAM, and Secrets Manager; Cloud Run; Model Armor / Model Garden and Vertex AI (RAG Engine, Vector Search); and Cloud Asset Inventory for drift detection. Engagement Details & Working Arrangement Delivery model: Dedicated consulting resource embedded with GCP program, supporting the Product Teams Support workstream alongside the broader GCP Architecture Support and NCC Transition projects. Location: Remote (U.S.). All work performed remotely via secure VPN/collaboration tooling.

Requirements

Extensive cloud / infrastructure engineering experience with deep, hands-on Google Cloud Platform delivery. Expert-level Terraform / Infrastructure-as-Code building production modules, scaffolding, and repeatable implementation patterns. Strong GCP engineering skills: IAM, organization policy, Shared VPC, VPC Service Controls, Private Service Connect, and networking. Hands-on CI/CD and policy-as-code (OPA/Conftest, Checkov, tfsec) with Git-based workflows and disciplined code review. Security- and compliance-oriented engineering (CMEK, least privilege, PII/PCI considerations). Strong documentation habits (READMEs, runbooks) and a handoff / operationalization mindset.

Preferred Qualifications Google Cloud Professional certifications (Cloud Engineer, DevOps Engineer, and/or Cloud Security Engineer). Workload Identity Federation, Privileged Access Management (PAM), and Secrets Manager experience. Generative-AI infrastructure on GCP Model Armor, Model Garden, RAG Engine, and Vector Search deployment. Cloud Asset Inventory-based drift detection and shared Terraform module ecosystems. Exposure to Azure / AKS integration and hybrid connectivity. Experience in large, regulated, enterprise-scale (e.g., retail) environments.

Benefits & conditions

3.63.6 out of 5 stars Remote $80 - $100 an hour - Contract

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · WWC Europe 2026

2:50 min

Introduction and the value of runbooks

Hila Fish · WWC 2023

5:02 min

Mapping Git flow branches to application tester segments

Majid Hajian · LIVE

3:46 min

Navigating a career in cloud transformation consulting

Piet Van Dongen · LIVE

3:53 min

Introduction to git flow and clean feature branches

Johannes Haux · WWC 2022

1:32 min

Structuring automated incident workflows between runbooks and raw models

Aram Hakobyan Aram Hakobyan +1 · WWC Europe 2026

Videos

See all

Related articles

See all