Cywarden, Inc.
Website:
cywarden.com
Job details:
About the Role
Cywarden is seeking a GCP Cloud Architect to own architecture, governance, operations, and optimization of enterprise Google Cloud environments within a larger multi-cloud (AWS-primary) managed services engagement for regulated-industry clients. The role owns GCP end to end — org policy and IAM through workloads, cost, and security posture — while working hand-in-hand with our AWS and Azure architecture teams as one delivery pod: shared operating roster, one ITSM queue (ServiceNow), one observability plane (Datadog), unified governance standards, and jointly-owned cross-cloud connectivity. You will serve as the L3 escalation and architecture authority for GCP, co-own the interconnectivity fabric that ties GCP to AWS and Azure, and contribute to cross-cloud automation and FinOps.
Key Responsibilities
- GCP Governance: Design and manage resource hierarchy (organizations, folders, projects), organization policy constraints, IAM roles and groups, and labeling standards aligned to a cross-cloud tagging taxonomy defined jointly with the AWS and Azure architects; bring loosely-governed project estates under consistent, enforceable policy
- Cross-Cloud Interconnectivity (co-owned): Design, operate, and troubleshoot the connectivity fabric between GCP, AWS, and on-premises — Cloud Router/BGP and HA VPN/Interconnect on the GCP side, terminating into an AWS Transit Gateway hub — including routing design, CIDR planning to prevent overlaps, DNS resolution across clouds and on-premises AD, and joint incident diagnosis with the AWS team when a cross-cloud path degrades
- AWS & Azure Coordination: Work daily with AWS and Azure counterparts on shared concerns — unified tagging and policy enforcement, consolidated security-findings register, identity federation (enterprise AD/Entra ID as the common source), migration assessments for workloads moving between clouds, and consistent runbook/automation standards so all clouds operate as one estate, not three
- Identity & Access: Operate identity federated from enterprise Active Directory / Entra ID (Cloud Identity/GCDS or Entra federation), coordinating with the Azure/identity team on sync health and conditional-access impacts; design service-account lifecycles with least privilege, workload identity, and no long-lived keys; quarterly access reviews with audit evidence
- Workload Operations: 24×7 operational ownership of GCP workloads (Compute Engine, GKE, Cloud Storage, BigQuery, Cloud SQL) — monitoring, incident response, patching via VM Manager/OS Config aligned to the engagement-wide patching calendar, backup validation, and capacity planning
- Security Posture: Manage Security Command Center findings with severity-based remediation SLAs, normalized into the same ServiceNow-tracked remediation register as AWS Security Hub and Azure Defender findings; enforce encryption, public-access prevention, and data-residency controls
- Observability Integration: Feed GCP metrics and logs into Datadog (per-project integrations, Pub/Sub log sinks) with cost-aware filtering, matching the dashboard and alerting conventions established across AWS and Azure
- IaC & Automation: Build and maintain Terraform for GCP (project factory, org policy as code, module libraries) in shared GitLab CI/CD following the engagement's common module conventions and review gates, with OIDC/workload identity federation — no stored credentials; contribute Python automation to the shared toil-reduction backlog
- FinOps: Own GCP cost optimization end to end — BigQuery cost governance, rightsizing, committed-use discounts (CUDs) sized to workload stability, idle-resource cleanup — reported through the unified multi-cloud cost review alongside AWS and Azure savings workstreams
- Compliance & Advisory: Operate within regulated-industry controls (GxP/SOX-aligned) — change control, documented evidence, audit support; provide honest workload-placement guidance in an AWS-primary estate, including supporting cross-cloud migration waves planned with the AWS team
Technical Skills
GCP: Resource Manager, org policies, IAM, Cloud Identity, VPC/Cloud Router/HA VPN/Interconnect, Compute Engine, GKE, Cloud Storage, BigQuery, Cloud SQL, Pub/Sub, Security Command Center, Cloud Asset Inventory, VM Manager, Cloud Billing/CUDs. Cross-cloud (working knowledge expected): AWS networking (Transit Gateway, Site-to-Site VPN, Route 53 hybrid DNS), Azure identity (Entra ID, AD Connect), cross-cloud routing and DNS design. Engineering: Terraform (google provider depth), GitLab CI/CD, Python, gcloud SDK. Operations: Datadog, ServiceNow, incident/change management.
Experience & Qualifications
- 8–12+ years in infrastructure/cloud engineering; 4+ years hands-on GCP architecture and operations in enterprise, multi-project environments
- Demonstrated experience operating GCP connected to AWS and/or Azure estates — cross-cloud networking, federated identity, and shared tooling — not GCP in isolation
- Strong Terraform-managed GCP experience; production operations under change control with SLA-driven incident response (P1/P2)
- Proven collaborator across platform teams — comfortable co-owning designs, escalations, and standards with AWS and Azure architects rather than working a silo
- Preferred: Google Professional Cloud Architect (required within 90 days if not held); Professional Cloud Network/Security Engineer, AWS or Azure associate-level certification, Terraform Associate, ITIL
- Preferred: pharmaceutical, life sciences, healthcare, financial services, or other regulated-industry experience
Key Deliverables / KPIs
- GCP governance maturity: org-policy coverage, labeling compliance ≥95% against the shared taxonomy, clean access-review evidence
- Cross-cloud connectivity: documented interconnect architecture, zero unplanned cross-cloud connectivity outages attributable to GCP-side change, joint runbooks with the AWS team
- Security posture: SCC findings remediated within SLA in the unified register; zero unmanaged service-account keys
- Observability: full estate coverage in Datadog, consistent with cross-cloud conventions
- FinOps: measurable GCP savings reported in the unified multi-cloud cost review
- Terraform coverage of the GCP estate with peer-reviewed, pipeline-deployed changes under shared module standards
About Cywarden
Cywarden is a global technology and cybersecurity partner delivering 24×7 multi-cloud operations, security, and AI-enabled transformation for regulated enterprises.
Locations: Mohali, Delhi or Pune - India
Click on Apply to know more.