Sr. Google Cloud Engineer
Experience: 7+ years
Job Type: Fulltime
Location: Chennai
Role Overview
We are seeking a Sr. Google Cloud Engineer with strong handson expertise in designing, building, and operating scalable, highly available, secure, and disasterrecoveryready infrastructure on Google Cloud Platform (GCP).
Key Responsibilities
Cloud Architecture & Landing Zone
- Design and implement scalable, highly available, and DRready GCP infrastructure
- Own GCP Landing Zone design and implementation, including:
- Resource hierarchy (Org, Folders, Projects)
- Shared VPC architecture and network segmentation
- Security guardrails, governance, and standards
- Define best practices for multiproject and multienvironment GCP architectures
Networking, Private Connectivity & Security
- Design and operate secure private connectivity patterns, including:
- Private Service Connect (PSC)
- Private Service Access (PSA)
- Design, build, and operate GCP networking, including:
- VPCs, subnets, routing, firewall rules
- Cloud Routers
- HA VPN
- Hybrid connectivity (onprem GCP)
- Implement Serverless VPC Access for Cloud Run and other serverless workloads
- Design and manage Cloud DNS
- Configure log sinks and log router pipelines for centralized logging and compliance
Identity, Security & Governance
- Implement and manage IAM, including:
- Service Accounts
- Leastprivilege role design
- Workload Identity
- Implement advanced security controls:
- VPC Service Controls (VPCSC)
- IdentityAware Proxy (IAP)
- Cloud Armor (WAF & DDoS protection)
- Binary Authorization
- Model Armor for AI/ML workloads
- Manage encryption and secrets using Cloud KMS / Key Rings
- Design and integrate infrastructurelevel Palo Alto NGFW in GCP
Certificates, TLS & Access
- Design and implement TLS/SSL certificate lifecycle management using:
- Google Certificate Manager
- Managed and selfmanaged certificates
- Ensure secure ingress for load balancers, GKE, and Cloud Run workloads
Compute, Serverless & CI/CD Platforms
- Provision and operate:
- Compute Engine
- GKE (Google Kubernetes Engine)
- Cloud Run
- Design and implement enterprise GitLab infrastructure, including HA, DR, security, and backups
- Manage Artifact Registry for container images and build artifacts
Data, Messaging & Analytics
- Design and operate:
- Cloud SQL
- AlloyDB
- BigQuery
- Firestore
- Firebase
- Google Cloud Storage (GCS)
- Build data pipelines using Dataflow
- Design eventdriven and asynchronous architectures using:
- Pub/Sub
- Eventarc
- Cloud Tasks
- Cloud Scheduler
- Design and operate API platforms using Apigee
Caching, AI/ML & Performance
- Design and manage inmemory caching using Memorystore (Redis)
- Support highperformance workloads, including:
- Enable and support AI/ML platforms, including:
- Vertex AI
- LLM model hosting and integrations
- Drive capacity planning and optimization to ensure scalability, performance, and cost efficiency
Infrastructure Automation, Operations & Governance
- Design, implement, and operate a selfhosted OpenTofu (Opensource Terraform) platform for Infrastructure as Code (IaC)
- Build and manage IaC pipelines using Terraform and OpenTofu
- Troubleshoot and resolve complex infrastructure issues across networking, security, compute, data, and platform services
- Design and implement OS patching strategies, including automation and compliance
- Design and implement enterprise backup and disaster recovery strategies
- Participate in incident, problem, and change management processes
- Provide operational support for production and nonproduction environments
- Drive knowledge sharing and team enablement through training, documentation, and walkthroughs
- Maintain architecture documentation, standards, runbooks, and SOPs
Required Technical Skills
- Google Cloud Platform (GCP)
- Landing Zone architecture & implementation
- IAM, Service Accounts, Workload Identity
- Private Service Connect (PSC), Private Service Access (PSA)
- Serverless VPC Access
- VPC Service Controls, IAP, Cloud Armor, Binary Authorization
- Cloud KMS / Key Rings
- Palo Alto NGFW
- VPC, Cloud Router, HA VPN, Cloud DNS
- Certificate Manager / TLS lifecycle
- Compute Engine, GKE, Cloud Run
- GitLab, Artifact Registry
- Firestore, Firebase
- BigQuery, Dataflow, Looker
- Pub/Sub, Eventarc, Cloud Tasks, Cloud Scheduler
- Apigee
- Memorystore (Redis)
- Vertex AI, LLM models
- Backup & DR architecture
- Capacity optimization
- Terraform, OpenTofu
- Linux / Unix
- Python, Bash
- Cloud Monitoring, Logging, Log Sinks
Soft Skills
- Strong cloud architecture and systemsthinking mindset
- Ability to design for scale, availability, security, and DR
- Excellent communication and documentation skills
- High ownership and accountability
- Strong collaboration across Team (App,DevOps,SRE &InfoSec)
- Proactive, automationfirst, continuousimprovement mindset
Qualifications & Experience
- Bachelors or Masters degree in Computer Science, Engineering, or equivalent experience
- 7+ years of experience in Cloud Engineering, Infrastructure Engineering, or Platform Engineering
- Proven experience managing enterprisescale GCP environments
- Strong experience designing HA, DR, and secure cloud platforms
Preferred Qualifications
- Google Cloud Professional certifications (Cloud Architect, DevOps Engineer)
- Experience in regulated or large enterprise environments
- Multiproject and multiregion GCP experience
- Exposure to FinOps / cloud cost optimization
- Familiarity with Agile / Scrum methodologies