- Migration leadership & execution: Design and implement a seamless, low-downtime migration strategy from AWS to GCP across compute, storage, databases, and networking.
- Architecture & Infrastructure as Code (IaC): Standardize GCP infrastructure using Terraform/Terragrunt, establishing best practices for modules, state management, and CI/CD pipelines.
- Security & compliance: Establish robust GCP security controls, including Identity and Access Management (IAM), Organization Policies, and security auditing.
- Secrets, keys & Kubernetes security: Design and manage the enterprise-grade secrets lifecycle and encryption strategy using HashiCorp Vault, GCP Secret Manager, and Cloud KMS: generation, envelope encryption, rotation, versioning, revocation, and auditable access for every credential in the platform. Apply deep expertise in GKE security: Workload Identity, Vault Agent, Pod Security Standards, network policies, admission control, image signing, and vulnerability scanning in the pipeline.
- Cost optimization & FinOps: Architect GCP workloads for optimal cost efficiency from day one, leveraging committed use discounts, auto-scaling, right-sizing, and cost monitoring guardrails.
- Technical leadership: Lead the DevOps function: own architectural decisions, run code reviews for infrastructure changes, and set engineering standards for the team.
- CI/CD & automation: Design and maintain automated deployment pipelines (GitHub Actions, GitLab CI, or Cloud Build) for infrastructure and applications.
- Experience: 5+ years of experience in DevOps/SRE roles, with at least 3+ years of hands-on experience designing and managing GCP infrastructure.
- Migration expertise: Proven track record of leading complex, production-grade migrations from AWS to GCP.
- AWS knowledge: Deep understanding of AWS architecture (EC2, S3, RDS, EKS, IAM) to effectively map and transition services to native GCP equivalents.
- Infrastructure as Code: Expert-level proficiency with Terraform and GitOps practices.
- Security standards: Hands-on experience implementing Zero Trust security models, least-privilege IAM, network isolation, and secret management in GCP.
- Secrets & encryption: Production experience running HashiCorp Vault or GCP Secret Manager with Cloud KMS or an HSM for signing and envelope encryption, including rotation without downtime and OIDC-based short-lived credentials for CI/CD instead of long-lived keys.
- Kubernetes security: Hands-on experience securing production GKE or EKS clusters: Workload Identity / IRSA, Pod Security Standards, network policies, secrets operators, and image signing and scanning.
- Leadership skills: Demonstrated experience mentoring junior/mid-level engineers and delegating technical workflows effectively.
Preferred certifications & skills
- Google Cloud Certified: Professional Cloud Architect or Professional Cloud DevOps Engineer
- Hands-on experience with FinOps tools (GCP Cost Management, Kubecost, Infracost)
- Experience with container orchestration (GKE) and service mesh architectures (Istio/Anthos Service Mesh)
#J-18808-Ljbffr…
