Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

GCP Architect

Net2Source (N2S)

GCP Architect

Remote Role

Job Description:

GCP Organization & Multi-Tenant Foundation

Own the GCP organization design end-to-end: folder hierarchy (Platform-Infrastructure, Customer-Hosting/Americas/EMEA/APAC, Engineering, OF, SE, PM, project naming conventions, IAM group model (sav-eic-* Google Groups - Least-privilege role bindings), and Organization Polloy framework (region constraints, external IP restrictions, SA key prevention, domain-restricted sharing, uniform bucket access)

Define and document the per-customer tenant isolation model: dedicated GCP project + VPC

+ GKE cluster per environment (prod/nonprod) - full billing, permission, and operational isolation. Own trade-off analysis between this model and namespace-level isolation as customer count grows

Resolve the critical open gaps in the current architecture: IPAM tooling selection, ArgoCD sharding strategy at 50-100+ clusters, PKIstrategy for SC2, Well-Architected Framework compliance gaps between MVP and production paths

Networking & CGNAT Architecture

Own the CGNAT (RFC 6598, 100.64.0.0/10) per-tenant addressing design: /23 CIDR

allocation framework (App /24, Web /25, Mgmt /26, GKE Master /28, PSA /24), IPAM tooling selection and integration into the provisioning pipeline

Design the full Connect 2.0 (SC2) architecture: HA OpenVPN topology (primary + secondary

VM per tenant, different zones, CGNAT side), PKIstrategy (GP CA Service Root CA + Issuing CA), per-tenant certificate lifecycle (generation, rotation, expiry alerting, revocation).

Firestore tenant config schema, Cloud Function orchestration (connect-health-probe, connect-failover, connect-failback), and . ovpn dual-endpoint bundle design

Define VPC routing Logic: custom node tags - active SC2 VI For RFC-1918 ranges, pod-traf

Page

10 / 14

/24 route preced

+

Private Service Access onfLicts

Acchitent Fl.cemaLl model denu-hu-default tan-hased Lancess/encess

VPC.

What We're Looking For

Required:

  • 8-12 years of infrastructure / platform engineering, with 3+ years as a principal-level technical authority on a production cloud platform
  • Deep GCP expertise - you have designed GCP organizations, multi-tenant GKE environments, VPC architectures, and IAM models for production workloads; you can defend design decisions in an Org Policy discussion as readily as a Terraform code review
  • Terraform mastery - multi-module design patterns, per-tenant factory modules, complex for each + dynamic blocks, state isolation strategy, module versioning; you have written Terraform that other engineers build on
  • ArgoCD at scale - ApplicationSets, multi-cluster agent/pull model, promotion gates, RBAC, HA- you have operated ArgoCD across 20+ clusters, not just installed it
  • Multi-tenant networking depth - CIDR management, IPAM tooling, VPC peering/PSC design, CGNAT or equivalent overlapping-address problem solving; you have solved customer CIDR conflict at scale
  • Security architecture - VPC Service Controls, Binary Authorization, Cloud KMS/CMEK, Workload Identity, IAP zero-trust, least-privilege IAM; you have designed the security model for a compliance-audited SaaS platform
  • Distributed systems intuition - you can evaluate trade-offs between Consul/Vault on VMs vs. containerized, between Elasticsearch and OpenSearch, between service mesh and no service mesh, and produce a written rationale that holds up under scrutiny
  • Strong written communication: architecture documents, decision records, and design
  • Distributed systems intuition - you can evaluate trade-offs between Consul/Vault on VMs vs. containerized, between Elasticsearch and OpenSearch, between service mesh and no service mesh, and produce a written rationale that holds up under scrutiny
  • Strong written communication: architecture documents, decision records, and design reviews are your primary output alongside code

Strong Plus:

  • HA VPN / OpenVPN architecture with per-tenant PKi at scale (cert lifecycle, rotation automation, GCP CA Service)
  • EU Sovereign Cloud experience: GCP Assured Workloads, AWS EU Sovereign, Azure EU, SecNumCloud, BSI C5, GDPR DPA design
  • HOK/BYOK with external KMS (Thales CipherTrust, HSM) - architectural experience, not just theoretical
  • Temporal.io workflow architecture for multi-step provisioning orchestration
  • Experience building agentic or Al-augmented infrastructure pipelines
  • SOC2 Type II, ISO 27001, or PCI-DSS architecture-to-controls mapping (you've been in the audit room)
  • Elasticsearch / OpenSearch cluster architecture at production scale
  • Google Cloud Professional Cloud Architect certification (required within 90 days if not already held)
Vacancy posted 17 hours ago
Similar jobs that could be interesting for youBased on the GCP Architect in San Francisco, CA vacancy
  •  ...Job Description: Cloud Platform Expertise: Deep understanding of Google Cloud Platform (GCP) services, including compute, storage, networking, databases, analytics, machine learning, and serverless offerings. Architectural Design: Ability to design robust, scalable, secure... 
    Suggested

    TechDigital Group

    San Francisco, CA
    2 days ago
  •  ...Platform Expert to design and implement robust cloud solutions on Google Cloud Platform. This role involves leveraging expertise in GCP services, automation tools like Terraform, and scripting languages to optimize cloud operations. You'll be at the forefront of cloud... 
    Suggested

    TechDigital Group

    San Francisco, CA
    2 days ago
  •  ...technologists committed to refining and mastering their craft. As an Architect for the Snowflake CoE you will be expected to: Lead a small to...  ...on at least one of the main cloud providers (AWS, Azure, and GCP). Maintain “active” status of a Snowflake SnowPro Core... 
    Suggested
    Temporary work
    Local area

    Slalom

    San Francisco, CA
    3 days ago
  •  ...CA Duration: Long term contract Description As an Enterprise Architect, you will be responsible for managing Enterprise‑wide solutions...  ..., ML) Experience with one or more public clouds MS Azure, AWS, GCP Experience with modern microservices architecture using Service... 
    Suggested
    Long term contract

    GSPANN Technologies, Inc

    San Francisco, CA
    3 days ago
  • Job Description: Minimum Requirements/Desired Requirements: BS or MS in Computer Science or related field 5+ years of experience in cloud technologies. Experience with at least one of the JVM languages (Java or Scala), Docker, Kubernetes, Ansible, Jenkins, Nagios, AWS, ...
    Suggested

    TechDigital Group

    San Bruno, CA
    1 day ago
  •  ...RESTful APIs, SOAP services, and data transformation (DataWeave) Excellent communication and problem-solving skills Nice to Have MuleSoft certification(s) Experience with cloud platforms (AWS, Azure, or GCP) Exposure to CI/CD pipelines and DevOps practices #J-18808-Ljbffr... 

    Compunnel

    San Francisco, CA
    2 days ago
  •  ...AI/ML/data systems and platforms. Proven experience in building and deploying cloud-based solutions on platforms like AWS, Azure, or GCP. Deep understanding of container technologies. In-depth knowledge of enterprise cloud security principles and best practices. Solid understanding... 

    JBA International

    San Francisco, CA
    2 days ago
  •  ...responsibilities About the Role We are seeking a Senior AI Architect - Enterprise Integrations to join our growing AI practice. As...  ...Preferred Skills Familiarity with cloud platforms (Azure, AWS, or GCP) and cloud-native deployment patterns Experience with RAG (... 
    Worldwide

    IBM

    San Francisco, CA
    4 days ago
  •  ...Infrastructure Engineer to enhance their cloud infrastructure. The role requires over 8 years of experience with strong expertise in GCP or AWS, Kubernetes, and programming skills in Java or Python. The successful candidate will collaborate with various teams to ensure... 
    Flexible hours

    HighNote

    San Francisco, CA
    2 days ago
  •  ...services, fortune, public utility, as well as regularly partnering with Big 4 SI partners. Job Title: Cloud Architect Contractor - GCP Onboarding Automation & Terraform Location: San Francisco, CA (W2 Only) Role Description As a Cloud Architect... 
    For contractors
    Local area

    DTI

    San Francisco, CA
    2 days ago
  • $120k - $230k

     ...REACT POSTGRES VERCEL GCP Software Engineer SF, CA Apply Full-time On-site $120k - $230k About this role Recruiting is the highest-leverage action any company can take. Hundreds of billions are spent on staffing and recruiting per year because of how difficult... 
    Full time
    Visa sponsorship

    ESR Healthcare

    San Francisco, CA
    2 days ago
  •  ...accessibility for our internal teams. We are looking for a hands‑on AI Architect to deliver technical designs and implementations of internal AI...  ...: Hands‑on experience deploying services on AWS, Azure, or GCP. Integration & Business Skills: Enterprise Platforms: Proven... 

    IBM Computing

    San Francisco, CA
    3 days ago
  •  ...services. Applicants should have 5+ years of backend software engineering experience, proficiency in Python, and the ability to collaborate with clients to understand their needs. Experience with Django, GCP, and Kubernetes is preferred. #J-18808-Ljbffr RST Recruitment

    RST Recruitment

    San Francisco, CA
    2 days ago
  • $153k - $222k

     ...to remove blockers and accelerate customer deployment. About The Job As a Outcome Customer Engineer (OCE) in Google Cloud Platform (GCP), you will drive initial and ongoing business ramp for our customers, clearing blockers and ensuring they get the maximum benefit from... 
    Full time

    Google

    San Francisco, CA
    2 days ago
  • $105k - $151k

     ...the future of businesses of all sizes use technology to connect with customers, employees and partners. As a Google Cloud Platform (GCP) Outcome Customer Engineer (OCE), you will drive initial and ongoing revenue ramp for our customers, clearing blockers and ensuring they... 
    Full time
    Temporary work

    Google

    San Francisco, CA
    2 days ago
  • $164.7k - $266k

     ...management (CLM). What you'll do We are seeking a Lead AI Architect to turn enterprise data, metadata, relationships, and business...  ...Experience with cloud-native AI and data services across AWS, Azure, or GCP Familiarity with enterprise AI search and knowledge platforms... 
    Contract work
    Work at office
    Local area
    Remote work
    2 days per week

    DocuSign

    San Francisco, CA
    1 day ago
  •  ...leading identity security firm is seeking an AI Infrastructure Architect to build and evolve AI infrastructure for securing digital identities...  ...or software engineering, with deep expertise in AWS or GCP, and a hands-on approach to development. #J-18808-Ljbffr... 

    Okta, Inc.

    San Francisco, CA
    2 days ago
  •  ...Description: Role: Head AI Architect Location: San Francisco, CA (Bay Area) Job Description: A full-stack AI...  ...Lifecycle Management •Cloud AI Infrastructure (Azure, AWS, GCP) •Foundation Models, LangChain/LLMOps •... 

    TEPHRA

    San Francisco, CA
    4 days ago
  • $94.43k - $202.75k

     ...Spark your curiosity and ignite your career at The Lighthouse. KPMG is currently seeking a Senior Associate, Full StackDevelopment - GCP for our Consulting Organization. Responsibilities: Design and implement scalable and robust software systems in Java, Python,... 
    Full time
    H1b
    Local area

    KPMG

    San Francisco, CA
    more than 2 months ago
  •  ...foundation and implement security controls. The ideal candidate will have over 8 years of experience in cloud infrastructure, especially GCP, with significant expertise in container orchestration and application security. Responsibilities include designing cloud... 

    Mandolin

    San Francisco, CA
    3 days ago
  • $209.5k - $307.26k

     ...customers. We want 6sense to be the best chapter of your career. Staff Architect Role Overview We’re looking for a Staff Architect to lead...  ...learnings) Experience with a major cloud platform (AWS, GCP, or Azure). Ability to influence across teams through clear communication... 
    Full time

    6sense

    San Francisco, CA
    2 days ago
  •  ...Francisco. The candidate will cultivate key relationships, drive joint business outcomes, and ensure the success of solutions within the GCP ecosystem. Ideal applicants should possess 5-10 years of experience in channel roles and have a strong grasp of business development... 

    Pumpandsave

    San Francisco, CA
    1 day ago
  • A leading healthcare technology firm in San Francisco is seeking a DevSecOps leader to design and manage cloud infrastructure on GCP. You will implement robust security protocols and enhance developer productivity while safeguarding sensitive healthcare data. Ideal candidates... 

    Mandolin

    San Francisco, CA
    17 hours ago
  • A leading AI governance platform company is seeking a Staff DevOps Engineer to manage a multi-tenant SaaS platform across AWS and GCP. This role involves designing large-scale Kubernetes clusters, utilizing Infrastructure-as-Code, and building observability solutions. The... 

    WitnessAI

    San Francisco, CA
    2 days ago
  • $90.71k - $113.37k

    If you think your skills, experience and aspirations make you a good match for this position, we encourage you to apply. ABOUT THE ROLE This position will be a member of our multi-disciplinary team, collaborating with design and technical leadership and will...
    For contractors
    Work experience placement
    Work at office
    Remote work
    Flexible hours

    CannonDesign

    San Francisco, CA
    2 days ago
  •  ...Enovia Architect Company Description INENT Inc. focuses on understanding, addressing and resolving Talent Acquisition, Engagement and Management needs. The core team has over many years of experience in a variety of industries and management disciplines. We serve our... 

    Inent Inc

    San Francisco, CA
    17 hours ago
  • $108k - $135k

     ...Mid-Market Revenue Architect Austin | Chicago | New York City | Salt Lake City | San Francisco Gong harnesses the power of AI to transform how revenue teams win. The Gong Revenue AI Operating System unifies data, insights, and workflows into a single, trusted system... 
    Work at office
    Remote work
    Work from home
    Flexible hours

    Gong.io

    San Francisco, CA
    4 days ago
  • $85k - $125k

     ...Architect Department: Architecture Employment Type: Permanent - Full Time Location: San Francisco Reporting To: Peter Sokoloff Compensation: $85,000 - $125,000 / year Description As an Architect at Foster + Partners , you will help shape... 
    Permanent employment
    Full time
    Local area
    Flexible hours

    Foster + Partners

    San Francisco, CA
    3 days ago
  •  ...perspectives, experiences, abilities, and expertise that advance both the work we do, and the world we share. Position Summary The Architect - Designer IV role requires an individual dedicated to collaboration, critical thinking, and developing great design solutions.... 
    Work at office
    Remote work
    Work from home
    Flexible hours

    Harley Ellis Devereaux

    San Francisco, CA
    3 days ago
  •  ...iCloud Architect - Cognizant/Apple - SF Bay Area Description of sourcing need iCloud architecture has kept evolving since Apple released it in 2011. It was a replacement for the MobileMe service launched in early 2000. Most of this architecture has not been... 

    Info Way Solutions

    San Francisco, CA
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to GCP Architect. Be the first to apply!