Salesforce QA Automation Engineer
June 9, 2026Fabric Enterprise Azure Data Architect
June 9, 2026
Experience : 6+ Years
Budget : 1L- 1.5L
JD:
Position Overview
We are seeking a highly skilled and experienced Google Cloud Platform (GCP) Subject Matter Expert (SME) to spearhead the design, security, and delivery of enterprise Google Cloud environments. This critical role involves establishing secure landing zones, optimizing network connectivity, managing identity, and implementing robust detective controls for clients migrating or extending their workloads onto GCP.
The ideal candidate will possess deep, hands-on expertise across GCP architecture, networking, security and hardening, identity federation, and DevSecOps. A strong understanding of mapping controls between Microsoft Azure and GCP is essential to ensure that new Google Cloud estates align seamlessly with an organization’s existing security posture. This role uniquely blends solution architecture, hands-on engineering, and advisory support for internal delivery teams and client Cloud Centres of Excellence.
Key Responsibilities
•Design secure GCP landing zones and develop reference architectures, meticulously mapping each control to the client’s existing Azure security posture.
•Architect advanced VPC networking solutions, including Shared VPC, hub-and-spoke topologies, efficient subnetting, and hierarchical firewall policies.
•Design and implement hybrid and multi-cloud connectivity strategies utilizing HA VPN and Dedicated/Partner Interconnect between GCP, Azure, and on-premises environments.
•Implement workforce identity federation between Microsoft Entra ID and GCP IAM (OIDC / SAML), encompassing group-to-role mapping and Context-Aware / Conditional Access.
•Harden GCP environments to comply with CIS benchmarks through the application of Organisation Policy Service custom constraints and Security Command Centre.
•Integrate comprehensive detective controls and Security Information and Event Management (SIEM) systems, including streaming Cloud Logging and Security Command Centre findings to Splunk (via Dataflow Pub/Sub-to-Splunk), and extending Palo Alto (VM-Series / Cloud NGFW, Panorama) capabilities into GCP.
•Design and implement privileged access solutions using Privileged Access Manager, IAM Conditions, VPC Service Controls, and integration with CyberArk.
•Develop infrastructure-as-code and DevSecOps pipelines with Infrastructure Manager / Terraform, policy-as-code, and Binary Authorisation.
•Provide expert advice to client Cloud Centres of Excellence and internal teams, translating complex architectural concepts into clear, understandable language for non-technical and executive stakeholders.
•Produce high-quality, client-ready architecture diagrams, control mappings, and detailed design documentation.
•Support cost management (FinOps), logging, and monitoring (Cloud Monitoring, New Relic) for GCP workloads.
Required Skills and Experience
Technical Skills
•GCP Certifications: Professional Cloud Architect and/or Professional Cloud Security Engineer (Professional Cloud Network Engineer and Professional Cloud DevOps Engineer strongly preferred).
•Core GCP Services: Deep hands-on expertise across: VPC / Shared VPC, Cloud Interconnect, HA VPN, Cloud DNS, Cloud IAM, Organization Policy Service, Security Command Center, Cloud KMS, Secret Manager, Cloud Logging / Monitoring, Pub/Sub, Cloud Functions, Cloud Run, Firestore, Dataflow.
•Network Design: Strong experience in hub-and-spoke topologies, firewall policies, Private Service Connect, and VPC Service Controls.
•Identity and Access: Proficiency in Workforce and Workload Identity Federation, OIDC / SAML, IAM Conditions, Context-Aware Access (Access Context Manager), and Privileged Access Manager.
•Security Tooling: Experience with Palo Alto VM-Series / Cloud NGFW and Panorama; CyberArk; Splunk integration (Varonis a plus).
•Infrastructure-as-Code & DevSecOps: Expertise in Terraform / Infrastructure Manager, policy-as-code (Org Policy custom constraints / gcloud terraform vet), CI/CD, and Binary Authorization.
•Multi-cloud Fluency: Demonstrated ability to map controls between Microsoft Azure (Entra ID, Azure Policy, Defender for Cloud, ExpressRoute, Azure Firewall) and their GCP equivalents.
•CIAM Platforms: Familiarity with CIAM platforms such as Google Identity Platform / Firebase, SAP CDC / Gigya is a plus.
•API Knowledge: Strong understanding of REST APIs, OAuth 2.0 / OpenID Connect, and secure service-to-service integration (e.g., Cloud Functions to API Management).
Soft Skills
•Exceptional ability to articulate complex cloud architecture concepts in plain language to both non-technical and executive audiences.
•Strong analytical, problem-solving, and troubleshooting capabilities.
•Effective communication and collaboration skills, enabling seamless interaction with cross-functional and client teams (Cyber, Network, DevOps, Cloud COE).
•Comfortable leading workshops and producing high-quality, client-ready documentation.