Senior Cloud Infrastructure, Network & Security Engineer
Posted 15hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Senior GCP engineer securing Gorilla Logic’s isolated recovery environment. Implementing cloud networking, IAM, Terraform automation, and platform security controls.
Responsibilities:
- Support implementation of a highly secure, isolated recovery environment on Google Cloud Platform
- Implement and validate GCP organization, folder, project, and Shared VPC structures
- Configure Shared VPC host and service projects within hub-and-spoke network architectures
- Design and implement subnet allocation, CIDR planning, routing, and network segmentation
- Configure Private Google Access, Cloud NAT, Cloud DNS, and secure egress patterns
- Implement hierarchical firewall policies and default-deny network security controls
- Configure environment and workload isolation, including east-west traffic restrictions and secure network boundaries
- Implement and manage VPC Service Controls and restricted service perimeters
- Validate network isolation, connectivity, and potential lateral-movement exposure
- Implement GCP IAM controls across organization, folder, project, and resource levels
- Create and manage custom IAM roles, IAM Conditions, IAM Deny Policies, and least-privilege access models
- Configure service accounts, service account impersonation, and secure authentication patterns
- Implement Workload Identity Federation and validate identity boundaries across projects and environments
- Support privileged access models, including Just-in-Time access, break-glass workflows, and zero-standing-privilege approaches
- Integrate Secret Manager and support secure secrets and identity lifecycle management
- Develop reusable Terraform modules and automation for GCP infrastructure, networking, IAM, and security controls
- Contribute to Git-based infrastructure workflows, CI/CD pipelines, and policy-as-code practices
- Validate deployed infrastructure against approved architecture and security requirements
- Document implemented components, assumptions, risks, gaps, and recommended remediation
- Participate in technical reviews, implementation checkpoints, security validation, and knowledge-transfer sessions
- Collaborate with cloud architects, network engineers, and security specialists to translate architecture and security requirements into reliable, validated infrastructure
Requirements:
- Senior-level hands-on experience implementing and supporting Google Cloud Platform infrastructure in production environments
- Strong GCP networking experience, including Shared VPC host/service project models
- Hands-on experience with subnet allocation, CIDR planning, routing, and enterprise network segmentation
- Experience implementing Private Google Access, Cloud NAT, Cloud DNS, and controlled egress
- Strong experience implementing firewall rules and hierarchical firewall policies using default-deny security models
- Advanced knowledge of GCP IAM, including custom roles, IAM Conditions, IAM Deny Policies, and organization/folder/project inheritance
- Experience managing service accounts, service account impersonation, and least-privilege access models
- Hands-on experience implementing Workload Identity Federation
- Experience with Organization Policies and VPC Service Controls
- Strong hands-on experience using Terraform to provision and manage production GCP infrastructure
- Experience working with Git-based workflows and CI/CD pipelines for infrastructure
- Ability to interpret an established enterprise architecture and translate it into working infrastructure
- Ability to work independently in an environment where requirements and scope may continue to evolve
- Strong collaboration skills and experience working directly with cloud architects, network engineers, and security specialists
- Professional English communication skills with the ability to participate in technical working sessions with US-based teams and clients
- Nice-to-have experience with Google Cloud Privileged Access Manager or comparable Just-in-Time and break-glass access models
- Nice-to-have experience implementing Zero Trust architectures and controls designed to prevent lateral movement
- Nice-to-have experience with disaster recovery, cyber recovery, isolated recovery, clean-room, or air-gapped cloud environments
- Nice-to-have experience integrating Microsoft Entra ID with Google Cloud, including federated or dual-directory identity models
- Nice-to-have experience implementing Secure Web Gateway or secure egress proxy solutions
- Nice-to-have experience with Google Cloud Secret Manager and secrets lifecycle management
- Nice-to-have experience implementing policy-as-code using OPA, Sentinel, or organization policy constraints
- Nice-to-have experience working in regulated environments, particularly financial services, with exposure to audit and compliance requirements
- Google Cloud certifications such as Professional Cloud Network Engineer, Professional Cloud Security Engineer, or Professional Cloud Architect are listed as nice to have
Benefits:
- No benefits or compensation extras specified in the posting
















