Role Overview
Serves as the dedicated Google Cloud engineer for Google Cloud Platform program, bringing deep Terraform expertise to develop, own, and deliver production-ready infrastructure automation modules, scaffolding, and implementation patterns. This role leads the design and implementation of Google Cloud Platform automation solutions tailored to needs ensuring risk mitigation and compliance across systems with deliverables that meet agreed acceptance criteria and are handed off in a state ready for operationalization.
Key Responsibilities
Develop, own, and deliver production-ready infrastructure automation modules, scaffolding, and implementation patterns.
Lead the design and implementation of Google Cloud Platform automation solutions tailored to needs, ensuring risk mitigation and compliance across systems.
Build Terraform to enforce foundational and security standards e.g., Model Armor floor settings, Cloud Run load-balancer/certificate/DNS patterns, organization and hierarchical policy, and CSPM modules.
Restructure and maintain Terraform repositories: separate global/shared policies from perimeter-specific implementations, apply lifecycle tagging, and align to a versioned shared-module strategy.
Implement drift detection (scheduled terraform plan and Cloud Asset Inventory comparisons) and shift-left IaC security scanning (Checkov/tfsec) with CI/CD policy gates (OPA/Conftest).
Contribute to IAM centralization and the Google Cloud Platform-IAM repository migration Workload Identity Federation, custom roles, PAM assignments, service-account key lifecycle, and Secrets
Manager best practices.
Deploy secure connectivity via IaC Shared VPCs, Private Service Connect endpoints, and VPC Service Controls perimeters (dry-run to enforced).
Produce clear code documentation and READMEs; participate in code-review cycles and rework with client.
Ensure deliverables meet agreed acceptance criteria and are handed off ready for operationalization.
Work closely with InfoSec, Network, and Infrastructure Automation teams to keep designs aligned and operationalizable.
Primary Deliverables
Production-ready Terraform code, modules, and scaffolding meeting agreed acceptance criteria.
Reusable, security-vetted shared modules (versioned) and repository-structure improvements.
Drift-detection and IaC security-scanning integrations within CI/CD.
Code documentation and READMEs supporting operational handoff.
Required Qualifications
Extensive cloud / infrastructure engineering experience with deep, hands-on Google Cloud Platform delivery.
Expert-level Terraform / Infrastructure-as-Code building production modules, scaffolding, and repeatable implementation patterns.
Strong Google Cloud Platform engineering skills: IAM, organization policy, Shared VPC, VPC Service Controls, Private Service Connect, and networking.
Hands-on CI/CD and policy-as-code (OPA/Conftest, Checkov, tfsec) with Git-based workflows and disciplined code review.
Security- and compliance-oriented engineering (CMEK, least privilege, PII/PCI considerations).
Strong documentation habits (READMEs, runbooks) and a handoff / operationalization mindset.
Preferred Qualifications
Google Cloud Professional certifications (Cloud Engineer, DevOps Engineer, and/or Cloud Security Engineer).
Workload Identity Federation, Privileged Access Management (PAM), and Secrets Manager experience.
Generative-AI infrastructure on Google Cloud Platform Model Armor, Model Garden, RAG Engine, and Vector Search deployment.
Cloud Asset Inventory-based drift detection and shared Terraform module ecosystems.
Exposure to Azure / AKS integration and hybrid connectivity.
Experience in large, regulated, enterprise-scale (e.g., retail) environments.
Core Technology Environment
Google Cloud Platform; Terraform / Infrastructure-as-Code (modules, scaffolding, production patterns); IAM, organization policy, Shared VPC, VPC Service Controls, Private Service Connect, and CMEK; CI/CD and policy-as-code (OPA/Conftest, Checkov, tfsec); Workload Identity Federation, PAM, and Secrets Manager; Cloud Run; Model Armor / Model Garden and Vertex AI (RAG Engine, Vector Search); and Cloud Asset Inventory for drift detection.
Engagement Details & Working Arrangement
Delivery model: Dedicated consulting resource embedded with Google Cloud Platform program, supporting the Product Teams Support workstream alongside the broader Google Cloud Platform Architecture Support and NCC Transition projects.
Location: Remote (U.S.). All work performed remotely via secure VPN/collaboration tooling.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
- Dice Id: cxbcsi
- Position Id: Job44808
- Posted 6 hours ago