Senior Google Cloud Infrastructure, Network & Security Engineer (IRE) - AA, Remote: Colombia - Costa Rica , Fulltime.
Software Development · 501-1,000 employees
About the role
You will design and implement secure, isolated recovery environments on Google Cloud Platform, focusing on networking, IAM, and infrastructure automation. The role involves collaborating with architects and security specialists to translate requirements into validated, reliable cloud infrastructure using Terraform.
What they look for
Requirements
Candidates must have senior-level hands-on experience with GCP infrastructure, specifically in networking, IAM, and security controls. Proficiency in Terraform, Git-based workflows, and professional English communication skills are required to support US-based teams.
Full description
Gorilla Logic is looking for a Senior Google Cloud Infrastructure, Network & Security Engineer to join our team and support the implementation of a highly secure, isolated recovery environment on Google Cloud Platform (GCP).
This is a hands-on infrastructure engineering role focused equally on GCP networking and GCP IAM/security. You will work within an established enterprise cloud architecture to implement secure network segmentation, identity and access controls, infrastructure automation, and platform security using technologies such as Shared VPC, IAM, Organization Policies, VPC Service Controls, Workload Identity Federation, and Terraform.
You will collaborate closely with cloud architects, network engineers, and security specialists to translate existing architecture and security requirements into reliable, validated infrastructure.
What You’ll Do
- Implement and validate GCP organization, folder, project, and Shared VPC structures.
- Configure Shared VPC host and service projects within hub-and-spoke network architectures.
- Design and implement subnet allocation, CIDR planning, routing, and network segmentation.
- Configure Private Google Access, Cloud NAT, Cloud DNS, and secure egress patterns.
- Implement hierarchical firewall policies and default-deny network security controls.
- Configure environment and workload isolation, including east-west traffic restrictions and secure network boundaries.
- Implement and manage VPC Service Controls and restricted service perimeters.
- Validate network isolation, connectivity, and potential lateral-movement exposure.
- Implement GCP IAM controls across organization, folder, project, and resource levels.
- Create and manage custom IAM roles, IAM Conditions, IAM Deny Policies, and least-privilege access models.
- Configure service accounts, service account impersonation, and secure authentication patterns.
- Implement Workload Identity Federation and validate identity boundaries across projects and environments.
- Support privileged access models, including Just-in-Time access, break-glass workflows, and zero-standing-privilege approaches.
- Integrate Secret Manager and support secure secrets and identity lifecycle management.
- Develop reusable Terraform modules and automation for GCP infrastructure, networking, IAM, and security controls.
- Contribute to Git-based infrastructure workflows, CI/CD pipelines, and policy-as-code practices.
- Validate deployed infrastructure against approved architecture and security requirements.
- Document implemented components, assumptions, risks, gaps, and recommended remediation.
- Participate in technical reviews, implementation checkpoints, security validation, and knowledge-transfer sessions.
What You Bring
- Senior-level hands-on experience implementing and supporting Google Cloud Platform infrastructure in production environments.
- Strong GCP networking experience, including Shared VPC host/service project models.
- Hands-on experience with subnet allocation, CIDR planning, routing, and enterprise network segmentation.
- Experience implementing Private Google Access, Cloud NAT, Cloud DNS, and controlled egress.
- Strong experience implementing firewall rules and hierarchical firewall policies using default-deny security models.
- Advanced knowledge of GCP IAM, including custom roles, IAM Conditions, IAM Deny Policies, and organization/folder/project inheritance.
- Experience managing service accounts, service account impersonation, and least-privilege access models.
- Hands-on experience implementing Workload Identity Federation.
- Experience with Organization Policies and VPC Service Controls.
- Strong hands-on experience using Terraform to provision and manage production GCP infrastructure.
- Experience working with Git-based workflows and CI/CD pipelines for infrastructure.
- Ability to interpret an established enterprise architecture and translate it into working infrastructure.
- Ability to work independently in an environment where requirements and scope may continue to evolve.
- Strong collaboration skills and experience working directly with cloud architects, network engineers, and security specialists.
- Professional English communication skills with the ability to participate in technical working sessions with US-based teams and clients.
Nice to Have
- Experience with Google Cloud Privileged Access Manager (PAM) or comparable Just-in-Time and break-glass access models.
- Experience implementing Zero Trust architectures and controls designed to prevent lateral movement.
- Experience with disaster recovery, cyber recovery, isolated recovery, clean-room, or air-gapped cloud environments.
- Experience integrating Microsoft Entra ID with Google Cloud, including federated or dual-directory identity models.
- Experience implementing Secure Web Gateway or secure egress proxy solutions.
- Experience with Google Cloud Secret Manager and secrets lifecycle management.
- Experience implementing policy-as-code using technologies such as OPA, Sentinel, or organization policy constraints.
- Experience working in regulated environments, particularly financial services, with exposure to audit and compliance requirements.
- Google Cloud certifications such as Professional Cloud Network Engineer, Professional Cloud Security Engineer, or Professional Cloud Architect.
Similar roles
-
Senior Security Engineer - DevSecOps
carsales Sydney, New South Wales, Australia
-
Lead Cloud Security Engineer (DevSecOps)
Bilue Taguig, National Capital District, Philippines
-
Senior Security Engineer - Detection Engineering
LinkedIn United States · $129K–$212K/yr
-
Security Engineer
AlertMedia Austin, Texas, United States
-
F-35 Air Systems Information System Security Engineer | Active Secret clearance
General Dynamics Information Technology Eglin AFB, Florida, United States · $128K–$172K/yr
-
Full-Stack Engineers (Cybersecurity): Feedback On CI/CD Workflows
Terac United States · $218K/yr