via Indeed
$120K - 160K a year
Design and build cloud infrastructure foundation including network topology, security model, and project structure.
Expertise in cloud infrastructure architecture with strong GCP and AWS skills, hands-on security and networking experience, and mentoring capabilities.
The person in this seat owns how the cloud foundation is built: landing zone and project structure, network topology and connectivity back to on-premises, and the security model that everything else inherits. They are also expected to lift the rest of the engineering team up rather than sit on what they know. What we are looking for: Infrastructure architecture, not application architecture This is the sharpest line the hiring manager drew, and it is the fastest way to screen someone out. He is not interested in how many applications a candidate has deployed into a public cloud, or how many product teams they have advised on application design. He wants the person who designed the platform underneath: the network, the security boundaries, the account and project structure, the shared services. If a resume reads as "helped teams migrate their apps," that is the wrong candidate. If it reads as "designed the landing zone those teams deployed into," that is the right one. Landing zone and platform design (GCP) - Designed a GCP landing zone from the ground up - Made and defended decisions about organization and folder hierarchy, where workloads belong, and why - Defined what it actually takes to stand up a new project: quotas, IAM, billing, networking, guardrails, policy - The hiring managers team struggled with exactly this problem. A candidate who has solved it and can explain their reasoning will stand out immediately. Networking - Hybrid connectivity at real scale: Cloud Interconnect, Dedicated or Partner Interconnect, Direct Connect, VPN tunnels - On-premises to public cloud offload and migration, done hands-on - Can speak credibly about what went wrong. Latency problems, workload placement decisions, bandwidth and routing constraints, what they would do differently. The hiring manager specifically wants the failure stories, not the happy path. Security and the shared networking model - Hands-on ownership of cloud security architecture, not a governance or paper role - Deep familiarity with the shared VPC / shared networking model, including its tradeoffs - **Must be able to argue both sides.** The hiring manager knows exactly why his team chose shared networking. He wants someone who can either defend that choice on the merits or make the case for a different approach. A candidate who only recites the model without opinions will not clear the bar. - IAM design, org policy, network segmentation, encryption and key management, workload identity, Multicloud depth - Strong GCP is the priority. GCP is the cliens hardest skill to source and the hiring manager is personally invested in that side. - Strong AWS alongside it. The team's demand over the next year is expected to include a meaningful AWS component. - Azure and on-premises-only backgrounds are deprioritized. Not disqualifying, but not what to hunt for. Mentoring and knowledge transfer - Has taken something they built and successfully handed it off - Has grown other engineers to their level, formally or informally - The hiring managers own philosophy: offload the knowledge so you can go learn the next thing. He actively dislikes engineers who hoard knowledge as job security. Look for evidence of the opposite. Supporting skill stack Terraform or equivalent infrastructure as code, Kubernetes (GKE and EKS), CI/CD pipelines, observability and SRE practice, Linux, scripting (Python, Go, or Bash). Work Location: Remote
This job posting was last updated on 8/21/2026