GCP Cloud architect

Wipro

Singapore

On-site

SGD 120,000 - 180,000

Full time

10 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Wipro is seeking a Cloud IaC Engineer to design, build, and maintain Terraform modules for core GCP services such as GKE, Cloud Run, BigQuery, and Cloud Storage. The role emphasizes infrastructure as code standards, a private module registry, and automated CI/CD pipelines with policy guardrails.

You will implement policy-as-code, manage remote Terraform state, and help materialize a self-service Service Catalog with blueprints for common patterns.

Qualifications

  • Experience designing Terraform modules for GCP services with reusable patterns.
  • Experience implementing IaC with CI/CD pipelines in cloud environments.
  • Familiarity with policy-as-code, security guardrails, and compliance automation.
  • Experience managing Terraform state at scale with remote backends and environments.

Responsibilities

  • Design and maintain reusable Terraform modules for GCP services (GKE, Cloud Run, BigQuery, Cloud SQL, Pub/Sub, Storage).
  • Establish IaC standards, module versioning, and a private registry.
  • Implement automated CI/CD pipelines for infrastructure with plan/apply gating and drift detection.
  • Embed policy-as-code using OPA/Rego or similar to enforce security guardrails.
  • Manage Terraform state at scale with remote backends and environment isolation.
  • Build and operate a self-service Service Catalog for cloud building blocks.
  • Create templates and blueprints for common patterns (microservice on GKE, events on Pub/Sub + Cloud Run, data pipelines on BigQuery).
  • Integrate catalog with identity, tickets, and observability tooling.
  • Design landing zone networking and security controls (Shared VPC, VPC Service Controls, Cloud NAT, Private Service Connect).

Skills

Terraform
GCP
GKE
Cloud Run
BigQuery
Cloud SQL
Pub/Sub
VPC networking
IAM
KMS
Cloud Storage

Tools

Cloud Build
GitHub Actions
GitLab CI
OPA (Rego)
Sentinel
GCP Organization Policies

Job description

  • Design, build, and maintain reusable Terraform modules for core GCP services — GKE, Cloud Run, BigQuery, Cloud SQL, Pub/Sub, VPC networking, IAM, KMS, and Cloud Storage.
  • Establish IaC standards, module versioning strategy, and a private module registry.
  • Implement automated CI/CD pipelines for infrastructure (Cloud Build, GitHub Actions, or GitLab CI) with plan/apply gating, drift detection, and policy validation.
  • Embed Policy-as-Code using Open Policy Agent (OPA/Rego), Sentinel, or GCP Organization Policies to enforce security and compliance guardrails.
  • Manage Terraform state at scale (remote backends, workspace strategy, state isolation per environment).

Service Catalog

  • Build and operate a self-service Service Catalog (e.g., Backstage, GCP Service Catalog, or equivalent) where developers can provision approved cloud building blocks on demand.
  • Create golden-path templates and blueprints for common patterns: microservice on GKE, event-driven workload on Pub/Sub + Cloud Run, data pipeline on BigQuery, etc.
  • Wrap Terraform modules into catalog items with parameterized inputs, approval workflows, and guardrail checks.
  • Integrate the catalog with identity (Cloud Identity / Workforce Identity), ticketing, and observability tooling.

Security & Networking

  • Design and operate landing zone networking: org hierarchy, folder/project structure, Shared VPC, hub-and-spoke topology, hybrid connectivity (Cloud Interconnect / VPN), and Private Service Connect.
  • Implement network segmentation and egress controls using VPC Service Controls, firewall policies (hierarchical and network), Cloud NAT, and Private Google Access.
  • Build secure-by-default modules covering IAM least-privilege, Workload Identity Federation, service account hygiene, and short-lived credentials.
  • Embed encryption and key management patterns using Cloud KMS, CMEK/CSEK, and Secret Manager.
  • Operationalize Security Command Center, Cloud Armor, Identity-Aware Proxy, and Binary Authorization for workload protection.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GCP Cloud Architect: Terraform & IaC Automation Leader
GCP Cloud Architect: Terraform & IaC Automation Leader

Wipro • Singapore

On-site
SGD 120,000 - 180,000
Cloud Engineer (GCP)
Cloud Engineer (GCP)

Unison Group • Singapore

On-site
SGD 100,000 - 140,000
GCP & Kubernetes Infra Architect | IaC & Secure CloudOps
GCP & Kubernetes Infra Architect | IaC & Secure CloudOps

WORLD PARTNERS SOLUTION PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000
Cloud Infrastructure Engineer/ DevOps Specialist
Cloud Infrastructure Engineer/ DevOps Specialist

WORLD PARTNERS SOLUTION PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000
Senior cloud Engineer
Senior cloud Engineer

Searce Inc • Singapore

On-site
SGD 90,000 - 150,000
Cloud Engineer
Cloud Engineer

Optimum Solutions Pte Ltd • Singapore

On-site
SGD 180,000 - 240,000
Cloud Engineer (GCP)
Cloud Engineer (GCP)

Hong Kong Unison Limited • Singapore

On-site
SGD 90,000 - 150,000
GCP Infrastructure Lead: Cloud Architecture & Automation
GCP Infrastructure Lead: Cloud Architecture & Automation

* • Singapore

On-site
SGD 180,000 - 240,000
Cloud DevOps Engineer, Banking (1-year renewable contract)
Cloud DevOps Engineer, Banking (1-year renewable contract)

EVOLUTION RECRUITMENT SOLUTIONS PTE. LTD. • Singapore

On-site
SGD 110,000 - 170,000
CLOUD ENGINEER
CLOUD ENGINEER

RFNET TECHNOLOGIES PTE LTD • Singapore

On-site
SGD 120,000 - 170,000