The person in this seat owns how the cloud foundation is built: landing zone and project structure, network topology and connectivity back to on-premises, and the security model that everything else inherits. They are also expected to lift the rest of the engineering team up rather than sit on what they know.
What we are looking for:
Infrastructure architecture, not application architecture This is the sharpest line the hiring manager drew, and it is the fastest way to screen someone out. He is not interested in how many applications a candidate has deployed into a public cloud, or how many product teams they have advised on application
design. He wants the person who designed the platform underneath: the network, the security boundaries, the account and project structure, the shared services.
If a resume reads as "helped teams migrate their apps," that is the wrong candidate. If it reads as "designed the landing zone those teams deployed into," that is the right one.
Landing zone and platform design (GCP)
- Designed a GCP landing zone from the ground up
- Made and defended decisions about organization and folder hierarchy, where
workloads belong, and why
- Defined what it actually takes to stand up a new project: quotas, IAM, billing,
networking, guardrails, policy
- The hiring managers team struggled with exactly this problem. A candidate who has solved it and can explain their reasoning will stand out immediately.
Networking
- Hybrid connectivity at real scale: Cloud Interconnect, Dedicated or Partner
Interconnect, Direct Connect, VPN tunnels
- On-premises to public cloud offload and migration, done hands-on
- Can speak credibly about what went wrong. Latency problems, workload placement decisions, bandwidth and routing constraints, what they would do differently. The hiring manager specifically wants the failure stories, not the happy path.
Security and the shared networking model
- Hands-on ownership of cloud security architecture, not a governance or paper role
- Deep familiarity with the shared VPC / shared networking model, including its
tradeoffs
- **Must be able to argue both sides.** The hiring manager knows exactly why his
team chose shared networking. He wants someone who can either defend that choice
on the merits or make the case for a different approach. A candidate who only recites
the model without opinions will not clear the bar.
- IAM design, org policy, network segmentation, encryption and key management, workload identity, Multicloud depth
- Strong GCP is the priority. GCP is the cliens hardest skill to source and the hiring manager is personally invested in that side.
- Strong AWS alongside it. The team's demand over the next year is expected to include a meaningful AWS component.
- Azure and on-premises-only backgrounds are deprioritized. Not disqualifying, but not what to hunt for. Mentoring and knowledge transfer
- Has taken something they built and successfully handed it off
- Has grown other engineers to their level, formally or informally
- The hiring managers own philosophy: offload the knowledge so you can go learn the next thing. He actively dislikes engineers who hoard knowledge as job security. Look for evidence of the opposite. Supporting skill stack
Terraform or equivalent infrastructure as code, Kubernetes (GKE and EKS), CI/CD pipelines, observability and SRE practice, Linux, scripting (Python, Go, or Bash).
Work Location: Remote