
Senior Cloud Infrastructure, Network & Security Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Colombia, +1 more country.
• Assist in the implementation of a highly secure, isolated recovery environment on Google Cloud Platform.
• Execute and validate GCP organization, folder, project, and Shared VPC structures.
• Set up Shared VPC host and service projects within hub-and-spoke network architectures.
• Design and establish subnet allocation, CIDR planning, routing, and network segmentation.
• Configure Private Google Access, Cloud NAT, Cloud DNS, and secure egress patterns.
• Apply hierarchical firewall policies and default-deny network security controls.
• Set up environment and workload isolation, which includes east-west traffic restrictions and secure network boundaries.
• Implement and manage VPC Service Controls along with restricted service perimeters.
• Validate network isolation, connectivity, and potential lateral-movement exposure.
• Implement GCP IAM controls across organization, folder, project, and resource levels.
• Create and manage custom IAM roles, IAM Conditions, IAM Deny Policies, and least-privilege access models.
• Configure service accounts, service account impersonation, and secure authentication patterns.
• Implement Workload Identity Federation and validate identity boundaries across projects and environments.
• Support privileged access models, including Just-in-Time access, break-glass workflows, and zero-standing-privilege approaches.
• Integrate Secret Manager and support secure secrets and identity lifecycle management.
• Develop reusable Terraform modules and automation for GCP infrastructure, networking, IAM, and security controls.
• Contribute to Git-based infrastructure workflows, CI/CD pipelines, and policy-as-code practices.
• Validate deployed infrastructure against approved architecture and security requirements.
• Document implemented components, assumptions, risks, gaps, and recommended remediation.
• Participate in technical reviews, implementation checkpoints, security validation, and knowledge-transfer sessions.
• Collaborate with cloud architects, network engineers, and security specialists to translate architecture and security requirements into dependable, validated infrastructure.
• Senior-level hands-on experience in implementing and supporting Google Cloud Platform infrastructure in production settings.
• Strong background in GCP networking, including Shared VPC host/service project models.
• Hands-on experience with subnet allocation, CIDR planning, routing, and enterprise network segmentation.
• Experience in implementing Private Google Access, Cloud NAT, Cloud DNS, and controlled egress.
• Strong experience in setting firewall rules and hierarchical firewall policies using default-deny security models.
• Advanced knowledge of GCP IAM, including custom roles, IAM Conditions, IAM Deny Policies, and organization/folder/project inheritance.
• Experience in managing service accounts, service account impersonation, and least-privilege access models.
• Hands-on experience in implementing Workload Identity Federation.
• Familiarity with Organization Policies and VPC Service Controls.
• Strong practical experience using Terraform for provisioning and managing production GCP infrastructure.
• Experience working with Git-based workflows and CI/CD pipelines for infrastructure.
• Ability to interpret an established enterprise architecture and translate it into functional infrastructure.
• Capacity to work independently in an evolving environment with changing requirements and scope.
• Strong collaboration skills and experience working directly with cloud architects, network engineers, and security specialists.
• Proficient English communication skills, capable of participating in technical working sessions with US-based teams and clients.
• Preferred experience with Google Cloud Privileged Access Manager or similar Just-in-Time and break-glass access models.
• Preferred experience implementing Zero Trust architectures and controls designed to prevent lateral movement.
• Preferred experience with disaster recovery, cyber recovery, isolated recovery, clean-room, or air-gapped cloud environments.
• Preferred experience integrating Microsoft Entra ID with Google Cloud, including federated or dual-directory identity models.
• Preferred experience implementing Secure Web Gateway or secure egress proxy solutions.
• Preferred experience with Google Cloud Secret Manager and secrets lifecycle management.
• Preferred experience implementing policy-as-code using OPA, Sentinel, or organization policy constraints.
• Preferred experience working in regulated environments, particularly financial services, with exposure to audit and compliance requirements.
• Google Cloud certifications such as Professional Cloud Network Engineer, Professional Cloud Security Engineer, or Professional Cloud Architect are considered a plus.
• No benefits or compensation extras specified in the posting.
JSI
Coinbase
Fiserv
Avenga
Get handpicked remote jobs straight to your inbox weekly.