Job Description
Role GCP Enterprise Architect (Platform Automation Architect, GCP)
\n
\n
Practice Trace3 — Cloud Solutions Group, Digital · Google Cloud Practice
\n
\n
Workstream Product Teams Support
\n
\n
Location Remote (U.S.)
\n
\n
Reports To Trace3 Google Cloud Practice / Engagement leadership
\n
43647
\n
Role Overview
\n
Serves as the dedicated enterprise architect for Gap's Google Cloud program, evaluating incoming use cases holistically and defining the most appropriate end-to-end solution design across security, networking, and infrastructure automation. This Trace3-led role translates business and technical requirements into scalable, secure, and supportable cloud automation patterns; produces documented, repeatable architecture artifacts; and coordinates required changes across dependent teams to completion. The architect strengthens the overall solution-design process, improves cross-functional alignment, and accelerates delivery of Gap's cloud initiatives.
\n
Key Responsibilities
\n
• Evaluate incoming use cases holistically and define end-to-end solution designs spanning security, networking, and infrastructure automation.
\n
• Translate business and technical requirements into scalable, secure, and supportable cloud automation patterns.
\n
• Produce documented, repeatable architecture artifacts and reference designs that delivery teams can operationalize.
\n
• Partner across Gap's InfoSec, Network, and Infrastructure Automation teams to ensure designs align across all foundational pillars and can be operationalized effectively.
\n
• Coordinate required changes across dependent teams and drive them to completion.
\n
• Provide architectural direction across the program's technical domains — network security architecture, foundational GCP organization and IAM, cloud security posture management, Terraform/IaC structure, and the Gemini Enterprise Agent (Vertex AI) platform.
\n
• Guide persona-based least-privilege IAM design, organization policy, VPC Service Controls, Private Service Connect, and CMEK/encryption standards.
\n
• Establish Terraform architecture standards — separation of global/shared policy from perimeter-specific implementation, shared-module strategy, drift detection, and CI/CD policy-as-code gating.
\n
• Provide architectural guidance to the NCC network transition and hybrid-connectivity direction (including Cross-Cloud Interconnect to Azure) where it intersects platform automation.
\n
• Support project governance — participate in design reviews, secure architecture sign-off, and maintain alignment to timelines and scope.
\n
Primary Deliverables
\n
• Architecture designs and supporting documentation for approved use cases.
\n
• Reusable reference solution patterns spanning security, networking, and infrastructure automation.
\n
• Persona-based IAM / least-privilege role design and foundation policy recommendations.
\n
• Terraform repository and structure design guidance (global vs. shared policy separation, module strategy, drift detection, IaC security scanning).
\n
• Design artifacts for the Gemini Enterprise Agent Platform (Agent Engine, RAG Engine, Vector Search), including governance and threat-model considerations.
\n
Required Qualifications
\n
• Extensive enterprise / cloud architecture experience with deep, hands-on Google Cloud Platform expertise.
\n
• Demonstrated ability to own end-to-end solution design across security, networking, and infrastructure automation.
\n
• Expert-level Terraform / Infrastructure-as-Code design and standards.
\n
• Strong command of GCP foundations: resource hierarchy and organization policy, IAM and least-privilege design, Shared VPC, VPC Service Controls, Private Service Connect, and CMEK.
\n
• Experience embedding security and compliance into cloud designs (e.g., PII/PCI-regulated workloads) and cloud security posture management.
\n
• Proven cross-functional leadership — aligning InfoSec, Network, and Infrastructure/Platform teams and driving change to completion.
\n
• Excellent documentation, communication, and stakeholder-management skills.
\n
Preferred Qualifications
\n
• Google Cloud Professional certifications (Cloud Architect, Cloud Security Engineer, and/or Cloud Network Engineer).
\n
• Vertex AI / generative-AI platform architecture — Agent Engine, RAG Engine, Vector Search, Model Armor, and Model Garden governance.
\n
• CI/CD policy-as-code tooling (OPA/Conftest, Checkov, tfsec) and layered Terraform pipelines.
\n
• Cloud security posture management with Prisma Cloud.
\n
• Network Connectivity Center (NCC), hub-and-spoke fabric, and hybrid connectivity including Cross-Cloud Interconnect to Azure.
\n
• Experience in large, regulated, enterprise-scale (e.g., retail) environments.
\n
Core Technology Environment
\n
Google Cloud Platform; Terraform / Infrastructure-as-Code; IAM, organization policy, Shared VPC, VPC Service Controls, Private Service Connect, and CMEK; Vertex AI / Gemini (Agent Engine, RAG Engine, Vector Search, Model Armor, Model Garden); Cloud Run; Prisma Cloud (CSPM); CI/CD policy-as-code (OPA/Conftest, Checkov, tfsec); and Network Connectivity Center with Cross-Cloud Interconnect to Azure.
\n
\n
Engagement Details & Working Arrangement
\n
• Delivery model: Dedicated Trace3 consulting resource embedded with Gap's GCP program, supporting the Product Teams Support workstream alongside the broader GCP Architecture Support and NCC Transition projects.
\n
• Location: Remote (U.S.). All work performed remotely via secure VPN/collaboration tooling.
\n
• Hours: Normal business hours (8:00 AM – 5:00 PM client local time); occasional off-hours work by mutual agreement to support change windows.
\n
• Security & compliance: Trace3-managed device, hard-drive encryption, two-factor authentication, and adherence to the client's remote-work protocols and information-security standards.
