JOBSEARCHER

GCP DevOps Engineer

Contract Role - 3 to 4 month duration20 hours per week, could increase later Our client as is a U.S.-based leader in CCaaS, AI/ML, and Cloud Solutions. As a Gold Partner with Genesys and Advanced Partner with AWS, Google Cloud, and Azure, we deliver implementation, consulting, managed services, and product development that drives higher ROI for our clients. Our fully remote, agile teams are empowered to innovate—and we’re looking for a GCP DevOps Engineer to shape our next wave of intelligent and secure offerings.About the RoleRole Overview:Google Cloud Platform specialist to guide the provisioning, security, and enterprise enablement of cloud landing zones, ensuring alignment with strict organizational policies to support scalable project deployments.You will work closely with clients, our application development and design teams to ensure our clients’ and internal GCP environments meet the highest standards of reliability, compliance, and operational excellence. The ideal candidate is highly consultative, proactive, and thrives in a hands-on environment where rapid learning is the norm.Key ResponsibilitiesGCP Architecture: Design and configure secure, enterprise-ready GCP landing zones to support PoC's, Pilots, and full-scale deployments without requiring future migrations.Domain Expertise: Provide specialized knowledge in IAM and Cloud Networking.Advisory & Collaboration: Lead workshops with cross-functional client teams to review current setups, ensure adherence to best practices, and provide official strategic recommendations.Security & Compliance: Ensure all platform enablement strictly follow established enterprise security policies and proceduresDevelop and enforce cloud security baselines, guardrails, and governance policies across GCP organizations, folders, and projects.Implement and manage Infrastructure as Code (IaC) for cloud foundations, including VPC architecture, shared services, and connectivity patterns.Integrate security tooling and controls into CI/CD pipelines (shift-left security), including static analysis, secrets detection, container scanning, and policy enforcement.Lead the design and implementation of Zero Trust network architecture, identity federation, and least privilege access models.Define and manage Security Command Center (SCC), Chronicle SIEM, and other GCP-native security tooling for continuous monitoring and threat detection.Conduct threat modeling, risk assessments, and security reviews for new infrastructure patterns and cloud-native services.Collaborate with compliance teams to maintain alignment with frameworks such as CIS Benchmarks, NIST 800-53, SOC 2, FedRAMP, or equivalent.Automate security and compliance controls using policy-as-code tools (OPA/Rego, Terraform Sentinel, Forseti/Config Validator).Respond to and remediate security incidents, vulnerabilities, and misconfigurations across the cloud estate.Mentor teams on cloud security best practices and drive a culture of shared security ownership.Lead development and maintenance of standardization templates to be used for discovery by sales and implementation teams in ensuring client security requirements are well documented.Required Experience3+ years of experience in DevOps, cloud engineering, or platform/infrastructure engineering roles.3+ years of hands-on experience with Google Cloud Platform (GCP), with a focus on foundations, networking, and security.Demonstrated experience designing and deploying enterprise GCP Landing Zones (Google Cloud Foundation Toolkit, CFT, or equivalent).Strong background in cloud security architecture, identity & access management (IAM), and network security design.Proven experience integrating security into CI/CD workflows and automating policy enforcement.Experience working within regulated environments or with compliance frameworks (SOC 2, NIST, CIS, ISO 27001, or FedRAMP). Preferred ExperienceExperience with multi-cloud or hybrid connectivity (GCP Interconnect, VPN, SD-WAN).Background in SRE practices — SLOs, incident response, and chaos engineering.Contributions to open-source security or DevOps tooling.Familiarity with Google Assured Workloads or sovereign cloud requirements.Prior experience in financial services, healthcare, or government-regulated industry.HIPAAConfidential Computer InformationTechnical Capabilities Cloud Foundations & Landing ZonesGCP Organization hierarchy design (Org → Folders → Projects) including Assured Workloads foldersShared VPC, VPC Service Controls, and Private Service ConnectResource hierarchy and inheritance model for policies and billingCloud Foundation Toolkit (CFT) and/or Fabric FAST landing zone blueprintsGoogle Cloud's Architecture Framework and Well-Architected principlesSecurity & ComplianceIAM design: service accounts, Workload Identity Federation, custom roles, and least-privilege enforcementCloud Armor (WAF/DDoS), BeyondCorp Enterprise, and context-aware accessData security: CMEK, Cloud HSM, Secret Manager, DLP APISecurity Command Center (SCC) Premium — findings, threat detection, compliance dashboardsChronicle SIEM and Security Operations (SecOps) integrationsBinary Authorization and supply chain security (SLSA, Sigstore)Audit logging strategy: Cloud Audit Logs, log sinks, and retention policiesInfrastructure as Code & AutomationTerraform (advanced): modules, workspaces, remote state, Sentinel policiesGitOps workflows: ArgoCD, Flux, or equivalentPolicy-as-Code: OPA/Rego, Checkov, tfsec, KICSContainers & KubernetesGoogle Kubernetes Engine (GKE): hardening, Autopilot, node pool designContainer security: Artifact Registry scanning, Distroless images, Pod Security StandardsNetworkingVPC design: subnets, firewall rules, hierarchical firewall policiesCloud NAT, Cloud DNS, Private Google AccessHybrid connectivity: Cloud Interconnect, HA VPN, Network Connectivity CenterNetwork Intelligence Center and packet mirroringTechnologies & ToolsCATEGORY TOOLS & PLATFORMSCloud Platform Google Cloud Platform (GCP)IaC Terraform, Cloud Deployment ManagerSecurity Scanning Checkov, tfsec, Trivy, Snyk, SemgrepPolicy & Governance OPA/Rego, Sentinel, Forseti, Config ValidatorMonitoring & SIEM Chronicle, Security Command Center, Cloud Monitoring, SplunkContainer Orchestration GKE, Anthos, DockerSecrets Management Secret Manager, HashiCorp VaultIdentity & Access Cloud IAM, Workload Identity Federation, Active DirectoryVersion Control GitLab, BitbucketLanguages/Scripting Python, BashCertifications (Preferred)Google Cloud Professional Cloud Security Engineer (highly preferred)Google Cloud Professional Cloud ArchitectCertified Kubernetes Security Specialist (CKS)AWS Certified Security Specialty or Azure Security Engineer (beneficial for multi-cloud context)CISSP, CCSP, or equivalent security certification