💼 Full-time🗓 2026-07-29
Rewrite
## About the role
We are looking for a Google Cloud Platform (GCP) Platform/Cloud Engineer to design, implement, and operate a secure, scalable GCP foundation and application platform built around Cloud Run. The role focuses on GCP Landing Zone, Shared VPC networking, IAM and security controls, and a container-first CI/CD pipeline using Cloud Build and Docker, with secrets managed using Secret Manager and artifacts/logs stored in GCS.
## Responsibilities
### GCP Landing Zone & Foundation
* Design and implement a GCP Landing Zone aligned with enterprise standards (org/folder/project structure, guardrails, environments such as dev/test/prod).
* Establish baseline cloud governance: naming conventions, project provisioning patterns, network segmentation, and operational best practices.
### Shared VPC & Networking (Subnets)
* Implement and manage Shared VPC architecture (host and service projects).
* Design and configure VPC networks and subnets across environments/regions, ensuring proper segmentation and routing.
* Apply secure network practices (least privilege access to networks, controlled service project attachments).
### Cloud Run Platform Engineering
* Build and operate services on Cloud Run (deployment patterns, scaling, revisions/traffic splitting where applicable).
* Ensure secure runtime configuration (service identity, egress controls, minimal permissions).
### CI/CD with Cloud Build + Docker
* Create and maintain CI/CD pipelines using Cloud Build for containerized workloads.
* Build, test, and package applications using Docker, enforcing standard container best practices.
* Automate deployments to Cloud Run through repeatable pipeline steps.
### Secrets & Configuration Management
* Manage application secrets using Secret Manager (rotation strategy, access control, secret injection patterns).
* Ensure secrets are never embedded in code, images, or build logs.
### IAM Access & GCP Security
* Implement IAM policies using least privilege principles (service accounts, role bindings, and workload identities as applicable).
* Establish access models for teams, environments, and service accounts (break-glass, approvals, separation of duties).
* Apply GCP security hardening practices, audit readiness, and operational security controls.
### GCS (Storage) & Platform Utilities
* Configure and manage GCS buckets for artifacts, logs, build outputs, or application storage needs.
* Implement secure bucket controls (permissions, lifecycle, retention policies where required).
## Requirements
* Experience level:
* Strong hands-on experience with GCP services specifically:
* Cloud Run
* Cloud Build
* Secret Manager
* IAM
* GCS (Cloud Storage)
* Shared VPC, VPC, Subnets
* GCP Security (least privilege, policy guardrails, secure-by-default patterns)
* Strong containerization experience:
* Docker (build optimization, security scanning practices, multi-stage builds preferred)
* Experience building secure foundations / landing zones on GCP.
* Experience designing and operating enterprise cloud networking patterns with Shared VPC.
## Soft Skills
* Strong documentation mindset (clear runbooks, architecture notes, onboarding guides).
* Ability to collaborate with app teams and security teams to implement guardrails without slowing delivery.
* Ownership and operational excellence: proactive risk identification and remediation.
Sourced via wellfound · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.