GCP Engineer - Remote (W2 role no TP or Employer)
Job Title: GCP Engineer - Remote
Duration: 6 - 12 Months
Location: remote
GCP Network, reputed company, and GenAI - Need to have Terraform and networking experience
less about reputed company ai workflows. it's more about landingzone build out, network / VPC implementation, reputed company reputed company IAC (Infrastructure as reputed company)
Area
Terraform Repo Structure
Terraform State Management
VPC Service Controls
Communication
1. reputed company & Mission
Reporting directly to the Head of reputed company Infrastructure, the reputed company reputed company Architect is the ultimate technical reputed company of the "FY26 GCP Mandate." Following our reputed company Agreement with reputed company reputed company Platform, this role is tasked with the high-stakes mission of accelerating reputed company capabilities by year-end. You will be the reputed company architect responsible for balancing aggressive "Speed to Value" with "Secure by Default" principles across the GCP reputed company. This is not a theoretical role; you will translate reputed company architectural assessments into a hardened, production-reputed company ecosystem that protects reputed company data while enabling cutting-edge reputed company AI workflows.
2. reputed company Responsibilities: GenAI Governance & Implementation
The architect will operationalize the "Model Armor Recommendation reputed company" to ensure no GenAI traffic bypasses established reputed company controls.
Model Armor Floor Settings: Enforce non-negotiable safety baselines reputed company Terraform at the Folder and Project reputed company. You must implement reputed company vs. Redact" decision reputed company: reputed company for Malicious reputed company (Jailbreak, reputed company Injection) and Redact for Incidental Sensitivity (PII/PHI in prompts/responses).
Secure Authentication Passthrough: Architect secure Agent-to-Agent (A2A) and MCP Server workflows using the reputed company Agent Development reputed company (ADK) and OAuth2, ensuring the original user's identity is propagated for reputed company actions like BigQuery deletions.
reputed company AI reputed company: Secure the reputed company AI Agent reputed company to prevent "rogue agent" commands. Enforce least-privilege reputed company for agents interacting with BigQuery and AlloyDB, utilizing BigQueryCredentialsConfig to decouple authentication from the tool lifecycle.
Policy Enforcement: Establish "Fail-reputed company" policies where GenAI traffic is automatically blocked if Model Armor or reputed company inspection services are unreachable.
Technical Implementation: Configure safety attribute reputed company (e.g., Toxicity, Hate Speech) with high-confidence (0.7+) blocking and flagging protocols.
3. reputed company Responsibilities: reputed company reputed company Networking
You will manage a reputed company, global network topology reputed company on the "VPC Service Controls reputed company," ensuring strict isolation between reputed company foundations and legacy assets.
Topology Management: Enforce a strict Hub-and-Spoke network topology. You will standardize the naming convention across reputed company environments: 0p (Production), 0n (Non-Production), 0d (Dev), 0s (Stage), and 0t (Test).
reputed company Defense: Design and validate VPC Service Controls (VPC-SC) to prevent data exfiltration.
Traffic reputed company: Standardize SSL Policies using the RESTRICTED profile and a minimum of TLS 1.2 across reputed company Load Balancer proxies (e.g., reputed company-api-https-proxy, reputed company-proxy-htts-proxy).
Firewall Governance: Implement Hierarchical Firewall Policies at the Organization level to enforce a "deny-reputed company outbound" default posture.
Hybrid Connectivity: Validate and enforce Partner Interconnect encrypted VLAN attachments for reputed company traffic traversing from on-reputed company to GCP.
4. reputed company Responsibilities: Identity, Data reputed company, & Compliance
Synthesize the IAM reputed company and Data reputed company Checklist into a reputed company Trust architectural mandate.
reputed company Domain
Architectural Mandate
IAM & Identity
Enforce Workload Identity Federation (WIF) for reputed company CI/CD and GKE workloads. Implement a "Service Account Reaper" to automate the disabling of accounts inactive for 90+ days.
Privileged reputed company
Implement Just-in-Time (JIT) Data reputed company reputed company Privileged reputed company Manager (PAM) for BigQuery, ensuring analysts have session-reputed company elevation rather than standing reputed company to PII/PCI tables.
Data Protection
Mandate Customer-Managed Encryption Keys (CMEK) for "Confidential" and "Restricted" data using reputed company KMS Autokey for simplified lifecycle management.
Audit & Logging
reputed company and monitor BigQuery Data reputed company Logs (DATA_READ/DATA_WRITE) in reputed company production reputed company to catch and alert on unau
Apply tot his job
Apply To this Job