GCP Architect
Net2Source (N2S)
GCP Architect
Remote Role
Job Description:
GCP Organization & Multi-Tenant Foundation
Own the GCP organization design end-to-end: folder hierarchy (Platform-Infrastructure, Customer-Hosting/Americas/EMEA/APAC, Engineering, OF, SE, PM, project naming conventions, IAM group model (sav-eic-* Google Groups - Least-privilege role bindings), and Organization Polloy framework (region constraints, external IP restrictions, SA key prevention, domain-restricted sharing, uniform bucket access)
Define and document the per-customer tenant isolation model: dedicated GCP project + VPC
+ GKE cluster per environment (prod/nonprod) - full billing, permission, and operational isolation. Own trade-off analysis between this model and namespace-level isolation as customer count grows
Resolve the critical open gaps in the current architecture: IPAM tooling selection, ArgoCD sharding strategy at 50-100+ clusters, PKIstrategy for SC2, Well-Architected Framework compliance gaps between MVP and production paths
Networking & CGNAT Architecture
Own the CGNAT (RFC 6598, 100.64.0.0/10) per-tenant addressing design: /23 CIDR
allocation framework (App /24, Web /25, Mgmt /26, GKE Master /28, PSA /24), IPAM tooling selection and integration into the provisioning pipeline
Design the full Connect 2.0 (SC2) architecture: HA OpenVPN topology (primary + secondary
VM per tenant, different zones, CGNAT side), PKIstrategy (GP CA Service Root CA + Issuing CA), per-tenant certificate lifecycle (generation, rotation, expiry alerting, revocation).
Firestore tenant config schema, Cloud Function orchestration (connect-health-probe, connect-failover, connect-failback), and . ovpn dual-endpoint bundle design
Define VPC routing Logic: custom node tags - active SC2 VI For RFC-1918 ranges, pod-traf
Page
10 / 14
/24 route preced
+
Private Service Access onfLicts
Acchitent Fl.cemaLl model denu-hu-default tan-hased Lancess/encess
VPC.
What We're Looking For
Required:
- 8-12 years of infrastructure / platform engineering, with 3+ years as a principal-level technical authority on a production cloud platform
- Deep GCP expertise - you have designed GCP organizations, multi-tenant GKE environments, VPC architectures, and IAM models for production workloads; you can defend design decisions in an Org Policy discussion as readily as a Terraform code review
- Terraform mastery - multi-module design patterns, per-tenant factory modules, complex for each + dynamic blocks, state isolation strategy, module versioning; you have written Terraform that other engineers build on
- ArgoCD at scale - ApplicationSets, multi-cluster agent/pull model, promotion gates, RBAC, HA- you have operated ArgoCD across 20+ clusters, not just installed it
- Multi-tenant networking depth - CIDR management, IPAM tooling, VPC peering/PSC design, CGNAT or equivalent overlapping-address problem solving; you have solved customer CIDR conflict at scale
- Security architecture - VPC Service Controls, Binary Authorization, Cloud KMS/CMEK, Workload Identity, IAP zero-trust, least-privilege IAM; you have designed the security model for a compliance-audited SaaS platform
- Distributed systems intuition - you can evaluate trade-offs between Consul/Vault on VMs vs. containerized, between Elasticsearch and OpenSearch, between service mesh and no service mesh, and produce a written rationale that holds up under scrutiny
- Strong written communication: architecture documents, decision records, and design
- Distributed systems intuition - you can evaluate trade-offs between Consul/Vault on VMs vs. containerized, between Elasticsearch and OpenSearch, between service mesh and no service mesh, and produce a written rationale that holds up under scrutiny
- Strong written communication: architecture documents, decision records, and design reviews are your primary output alongside code
Strong Plus:
- HA VPN / OpenVPN architecture with per-tenant PKi at scale (cert lifecycle, rotation automation, GCP CA Service)
- EU Sovereign Cloud experience: GCP Assured Workloads, AWS EU Sovereign, Azure EU, SecNumCloud, BSI C5, GDPR DPA design
- HOK/BYOK with external KMS (Thales CipherTrust, HSM) - architectural experience, not just theoretical
- Temporal.io workflow architecture for multi-step provisioning orchestration
- Experience building agentic or Al-augmented infrastructure pipelines
- SOC2 Type II, ISO 27001, or PCI-DSS architecture-to-controls mapping (you've been in the audit room)
- Elasticsearch / OpenSearch cluster architecture at production scale
- Google Cloud Professional Cloud Architect certification (required within 90 days if not already held)
$90k - $110k
...IA Interior Architects translates client goals, brand and culture into powerful environments built around people, processes, technologies and business drivers. Our clients in diverse markets worldwide require high-performance, visually compelling and sustainable environments...SuggestedContract workWork experience placementImmediate startWorldwide$15k
...move quickly. Initially work as a senior individual contributor, architect solutions across on-premise Linux environments, Kubernetes... ...with cloud IAM platforms (AWS IAM / Identity Center, Azure AD, GCP IAM) including roles, policies, federation, and service accounts...SuggestedWork at officeLocal area- ...Role Title: Workday Finance Architect Job Description :Key Responsibilities (Strategy & Configuration ~)Record to Report (R2R): Own the Financial Data Model (FDM). Configure Business Processes for Journals, Fixed Assets, and Allocations. Design the period-close...Suggested
- ...Job Description Job Description Senior RPA Architect (UiPath) Sacramento (or open to relocation) We are looking for a Senior RPA... ...REFramework , CI/CD , Git , and cloud platforms (AWS, Azure, GCP) ~ Proven experience designing reusable, secure, and compliant...SuggestedRelocation
- ...Job Title: Automation Architect & Performance Architect Location: Onsite - Oakland / San Francisco (SFO), CA [Remote is also fine... ...integration. Experience with cloud platforms (AWS, Azure, or GCP). Strong understanding of microservices architecture, APIs,...SuggestedFull timeRemote work
- ...Role Title: Workday Finance Architect Job Description :Key Responsibilities (Strategy & Configuration ~)Record to Report (R2R): Own the Financial Data Model (FDM). Configure Business Processes for Journals, Fixed Assets, and Allocations. Design the period-close...
- ...Number of position : 8 W2 Contract Only I, Salman Shaikh would like to share a job opportunity as Digital Workplace - M365 Architect based in Alameda, CA (Day 1 onsite) location for a W2 Contract Only / Full time position. *** In case, if you...Permanent employmentFull timeContract workLocal areaWork visa
- ...Job Summary: We are seeking a highly experienced GIS Architect to lead the design, implementation, and optimization of enterprise geospatial... ...managing GIS solutions in cloud environments (AWS, Azure, or GCP) • Knowledge of GIS server platforms, portals, and enterprise...
$70 - $110 per hour
...global nonprofit organization is seeking a Google Cloud Platform Architect to lead projects involving virtualization and cloud-native... ...week. Candidates must have a minimum of 3 years' experience with GCP, a minimum of 2 full lifecycle project implementations, and a valid...Hourly pay2 days per week$91.52k - $109.2k
...Job Type Full-time Description RRM Design Group is currently seeking a full-time Senior Landscape Architect to join our Landscape Architecture team! If you have experience working on public and private sector projects and have been part of a landscape...Full timeWork at office- Job Title :- Tech Architect/ Manager Employment Type :- W2 Duration :- Long Term Visa Type :- All Visa applicable which are ready for W2 Location... ...Metrics. Extensive experience with cloud services: GCP (GKE, Pub/Sub, Cloud SQL, Cloud Storage, Redis/MemCache). Strong...3 days per week
$182k - $259k
...experiences. Develop and publish data engineering best practices and patterns. EXPERIENCE / KNOWLEDGE & SKILLS Proven experience architecting and implementing lakehouse architectures on AWS data technologies (Glue, Lake Formation, Redshift, Athena) and Databricks....Local areaFlexible hours- ...We are seeking a Strategic Data Solutions Architect to help enterprise organizations modernize their data ecosystems and build AI-ready solutions within the Salesforce platform. This role combines enterprise architecture, data quality strategy, and client-facing leadership...Work at office2 days per week1 day per week
$90k - $115k
Senior Designer PYATOK architecture + urban design seeks a full-time Senior Designer with experience in multi-family housing design. This is not a remote position. We offer competitive salaries and benefits (medical, dental and vision; holidays; PTO and paid volunteer ...Full time$165k - $190k
...We are seeking a highly experienced Senior Data & AI Solution Architect to lead the design and implementation of scalable data platforms... ...architecture for data and AI workloads on cloud platforms (AWS, Azure, or GCP). Implement scalable pipelines using technologies such as...- ...Job Title - MSPP Architect Location - Oakland, CA Contract Overall Exp - 15 years JD:- As a Senior Architect, you will play a pivotal role in designing and implementing innovative solutions that drive business success. With a focus on leveraging...Contract work
- Fivetran, Inc. is seeking a Process Analyst to support documentation and analysis of workflows in Oakland. This role involves cross-functional collaboration and creating clear, organized documentation for operational efficiency. Ideal candidates have 3–5 years of experience...Remote work
$91.3k - $158.7k
...Architect Position at Lionakis Do you thrive in a creative, collaborative environment where ideas flow freely and innovation is encouraged? Are you looking to join a firm that takes real action toward advancing Equity, Diversity, and Inclusion? We're seeking Architects...For contractorsWork at officeFlexible hours- ...Licensed Architect Opportunity Lowney Architecture is looking for a licensed architect to lead technical delivery and coordination across multiple project types. This role offers autonomy, leadership responsibility, and the opportunity to mentor staff while contributing...Work at office
- ...faster and more efficiently by acting as a platform, not a traditional architecture company. Each project is paired with external Architects of Record (AORs) and Engineers of Record (EORs) who bring local jurisdiction expertise. They own design decisions and QA/QC,...H1bWork at officeLocal areaImmediate startWork visaFlexible hours
- ...Role: Okta Architect Location: Oakland / Mountain View CA (100% Onsite) Key Responsibilities: Lead the transition of applications/services from Okta to a new IDP. Manage the consolidation of applications/services between services, including data migration...
$118k - $160k
...on iconic hospitality and retail projects. As our diverse client base and project work continue to grow, we are seeking a Project Architect with 10+ years of experience to join our team. Your Role As a Project Architect in Gensler Oakland's Lifestyle...For contractorsLocal area- ...Job Description Build work that matters. Lead projects that leave a legacy. We’re looking for a Licensed Architect who’s ready to take ownership of meaningful projects and play a key role in shaping the built environment. This is an opportunity to work...For contractors
- ...Overview National Award-Winning Studio & Winner of Design Firm of the Year is actively seeking a Project Architect for their Berkeley or Folsom office. With over 19 offices across the U.S., the award-winning architecture + design firm specializes in K-12 through college...Work at office
$150k - $180k
...API Solution Architect Full time Alameda, CA/ Santa Clara, CA (Onsite) Web Cam Interview $150-$180K/Yr Educational Qualification Educational Qualification ~ BE/Btech Job Overview As an API / Solutions Architect, you will be responsible for designing...Full time$106.66k - $143.37k
...Job Type Full-time Description Are you an experienced architect with a passion for designing impactful civic, public safety, or educational spaces? RRM Design Group is seeking a talented and motivated Senior Architect to play a pivotal role in our forward...Full timeContract workWork experience placement- ...Overview: Role: Sr N/w Architect Location: Oakland, CA • 10+ years of experience in operations and managing Network devices, firewalls infrastructure. • 10+ years of experience installing and building Network infrastructure. • In-depth knowledge of network...
$192k - $208k
The University of California seeks an Organizational Consultant 5 to provide high-level advisory services and lead complex strategic engagements. This role demands a minimum of 10 years in management consulting, focusing on initiatives involving senior leaders. The ideal...- ...Marketing Architect - Apps & AI Front-End Technical Lead (Digital and Marketing Product, Commercial Technologies) Location: Alameda, CA Job Type: Long Term Rolling Contract Position Summary: We are seeking a Marketing Architect with experience in the...Long term contractContract workLocal area
- Alameda Health System in Oakland, California seeks a Senior Total Rewards Programs Administrator to oversee compensation and benefits programs. The role involves administering total rewards plans, collaborating across departments, conducting market analysis, and ensuring...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to GCP Architect. Be the first to apply!


