Key Responsibilities
- Design and own the target-state cloud architecture compute, networking, data, and security layers for a cloud‑native, AI‑enabled application platform, and translate it into infrastructure‑as‑code (Terraform or equivalent).
- Define the Kubernetes, container registry, database, object storage, secrets management, and networking topology, and guide implementation teams through build‑out.
- Architect and continuously improve CI/CD pipelines and source‑control workflows to automate build, test, and deployment of backend, frontend, and AI‑agent services.
- Design identity and access strategy (RBAC/IAM, managed identities, key/secret stores) that enforces least privilege while remaining operable at scale.
- Define the observability strategy — logging, monitoring, tracing, and alerting — for application, container, and AI/LLM runtime metrics.
- Architect the integration of AI/RAG components (knowledge bases, agents, vector search, model endpoints) with the platform's data and API layers.
- Lead root‑cause analysis and drive resolution of complex deployment, connectivity, and performance issues across compute, network, and data layers.
- Establish infrastructure standards, reference architectures, and reusable modules; maintain deployment documentation, runbooks, and environment configuration across dev/test/prod.
- Evaluate architecture for cost efficiency, scalability, resilience, and disaster recovery, and recommend improvements.
- Partner with application, security, and AI engineering leads to align infrastructure decisions with product and business goals, and mentor engineers on cloud and DevOps best practices.
- Design and provision the GKE cluster and supporting VPC/subnet topology (private/public subnets, plus additional subnets for data pipelines, agents, serverless, and private build pools).
- Architect the data layer using AlloyDB (PostgreSQL-compatible), Google Cloud Storage (GCS), and Artifact Registry for application and function container images.
- Set up Cloud Run services for application logic, APIs, and backend services.
- Design DNS and ingress via Cloud DNS and Load Balancer, and configure Private Service Connect / Private Google Access and GCP Service Accounts.
- Design the secrets and credential strategy using Secret Manager, and define Cloud Logging for logs, metrics, and tracing.
- Architect a RAG pipeline using Cloud Dataflow, and deploy/scale AI-ML services on Vertex AI, confirming regional compatibility across services.
- Establish infrastructure‑as‑code standards, backend configs, and environment variable structures across landing‑zone, infra‑provisioning, and app‑provisioning modules.
- Architect Cloud Build pipelines for CI/CD automation, and review the architecture periodically for cost, security, and resilience improvements.
Required Technical Skills
Google Cloud Platform (GCP) Compute & Orchestration: GKE, Kubernetes, Compute Engine VM (jump host) Data & Storage: AlloyDB (PostgreSQL-compatible), Google Cloud Storage (GCS) Serverless & Integration: Cloud Run, Artifact Registry Networking: VPC, Private Service Connect, Private Google Access, Cloud DNS, Load Balancer / Ingress AI / ML: Vertex AI, Gemini models, Cloud Dataflow (RAG pipeline) Security & Identity: Secret Manager, GCP Service Accounts, IAM, SSO integration CI/CD: Cloud Build, Infrastructure‑as‑code tooling, Git‑based source control Runtime / Dev Portal: Internal developer portal tooling, Node.js, PostgreSQL