GCP Cloud Platform Engineer - Hybrid
Description
Hybrid-Monday/Tuesday /Thursday Title: GCP Cloud Platform Engineer (Contract-to-Hire) Locations: Houston, TX; Mayfield Heights, OH; Milwaukee, WI Team: IT Platform Engineering, Infrastructure & Operations Role summary We are bringing Google Cloud Platform into our enterprise-supported cloud environment alongside our existing Azure platform. This contract-to-hire engineer will build and harden an enterprise-ready GCP landing zone and help evolve our current tenant from experimentation into a governed, production-grade platform. The role partners closely with identity, security, FinOps and AI Governance teams. Key Responsibilities Design and deploy an enterprise landing zone covering organization, folder, and project structure, IAM, connectivity, logging, and security integrations, aligned to landing zone best practices. Migrate unmanaged Google accounts to managed identities and implement Entra-to-Google identity sync with full SSO and MFA. Consolidate projects into a single billing account to enable FinOps invoicing and chargeback. Establish network guardrails including public IP blocking policies, centralized VPCs and hub architecture, and private access and endpoints. Centralize audit logging and monitoring and integrate enterprise security tooling such as Wiz and CrowdStrike. Implement platform components as code (Terraform) with reusable, secure, policy-enforced modules. Document standards and operational runbooks to support handoff to platform and cloud operations teams. Required Qualifications Hands-on GCP platform engineering experience, including Cloud Identity, IAM, org policy, VPC networking, and billing administration. Identity federation experience with Microsoft Entra ID, SSO, and MFA. Infrastructure as code proficiency with Terraform. Working knowledge of cloud security posture management and log and monitoring centralization. Experience taking a cloud environment from POC to enterprise-governed state. Preferred Experience operating a second cloud (Azure) at enterprise scale. FinOps and chargeback model experience. Familiarity with Wiz, CrowdStrike, and manufacturing or regulated enterprise environments.