Please note: Only candidates who meet all listed required qualifications will be considered for this position.
- GCP IAM, Terraform, Python, Security & Compliance, Network & Security Controls
- Technical Skills: Git/version control - experience with GitLab, GitHub, or
- BitbucketCI/CD pipelines - Jenkins, GitLab CI, Cloud Build, or similarAPI security - OAuth 2.0, OIDC, API keys, and token managementLogging and monitoring - Cloud
- Logging, Cloud Monitoring, integration with SIEM tools
- Container security - GKE workload identity, service mesh authentication (Istio/Anthos Service Mesh)
As an Identity Management Contractor, you will be responsible for implementing and maintaining identity management solutions to ensure secure and efficient access control. Configure and manage identity management systems to support user authentication and authorization. Implement identity and access management (IAM) policies and procedures in accordance with project requirements. Troubleshoot and resolve issues related to identity management systems and processes. Conduct regular audits and assessments to ensure compliance with security standards and best practices. Develop and maintain documentation for identity management processes and configurations.
Title: GCP IAM Engineer (Associate)
Primary Skill Required for the Role: GCP Python
Additional Skills Requested for Role:
Role summary:
Seeking an experienced IAM (Identity and Access Management) Specialist/Engineer to support the implementation of GCP Atlas 2.0 Control Plane and Vertex AI enablement for a large-scale financial services client. This role will be critical in establishing secure, governed access to Google Gemini AI model endpoints while maintaining strict compliance with enterprise security standards.
Key responsibilities:
- Provision and manage IAM (roles, bindings, service accounts) across projects using Terraform and Git-based workflows.
- Implement least-privilege patterns for application onboarding (runtime identity, human access, break-glass).
- Support identity integrations and group/role mappings as defined by enterprise standards.
- Produce onboarding evidence (access approvals, deployment records, audit log pointers) and maintain documentation/runbooks.
- Troubleshoot access issues and partner with platform/network/security teams to resolve blockers.
Required qualifications
- Hands-on GCP IAM experience (roles, service accounts, policy inheritance concepts).
- Terraform fundamentals (modules, state basics) and Git/PR workflow discipline.
- Scripting ability (Python) for automation/validation tasks.
- Familiarity with change/release processes and working in controlled environments.
Technical Skills Needed:
GCP IAM Expertise
- Deep experience with Google Cloud IAM
- GCP Vertex AI IAM
- Resource hierarchy
Infrastructure as Code
- Terraform - Advanced proficiency:
- GCP provider expertise (google, google-beta)
- IAM module development
- State management and remote backends
- Workspace and environment management
- Python - Strong scripting skills for automation:
- Google Cloud Client Libraries
- IAM policy manipulation and validation
- API integration and orchestration
Security & Compliance
- Strong understanding of zero-trust architecture principles
- Experience with data classification and sensitivity-based access controls
- Knowledge of financial services compliance requirements (ideally experience with JPMC or similar enterprises)
- Familiarity with SOC 2, ISO 27001, PCI-DSS or similar frameworks
- Understanding of encryption, key management (Cloud KMS), and secrets management (Secret Manager)
Networking & Security Controls
- Understanding of VPC networking and its intersection with IAM (private Google access, shared VPC)
- Experience with VPC Service Controls and security perimeters
- Knowledge of firewall rules, Cloud Armor, and Cloud Load Balancing as they relate to access control
- Familiarity with PrivateLink/Private Service Connect patterns
Supporting Technical Skills
- Git/version control - experience with GitLab, GitHub, or Bitbucket
- CI/CD pipelines - Jenkins, GitLab CI, Cloud Build, or similar
- API security - OAuth 2.0, OIDC, API keys, and token management
- Logging and monitoring - Cloud Logging, Cloud Monitoring, integration with SIEM tools
- Container security - GKE workload identity, service mesh authentication (Istio/Anthos Service Mesh)
Success measures:
- Onboarded apps meet access-control standards with minimal rework; IAM incidents reduced; evidence is audit-ready
Ready to take the next step? Click "Interested" to kickstart your journey toward a rewarding career!
#IND2
Job Types: Full-time, Contract
Pay: $90.00 - $100.00 per hour
Benefits:
- Dental insurance
- Health insurance
- Referral program
- Vision insurance
Application Question(s):
- Are you comfortable working on W2? If not, please hold off on completing the application for now. We’ll be posting another opportunity in the future for 1099/C2C candidates.
- Are you willing to work on a contract basis? If not, please hold off on completing the application for now. We’ll be posting another opportunity in the future for full time roles.
- Do you have a minimum of 5 years hands-on experience with GCP IAM? If you do not have, please hold off on completing the application for now. We’ll be posting another opportunity in the future for candidates without the required experience.
- Do you have a minimum of 5 years hands-on experience with Terraform? If you do not have, please hold off on completing the application for now. We’ll be posting another opportunity in the future for candidates without the required experience.
- Do you have a minimum of 4 years hands-on experience with Python? If you do not have, please hold off on completing the application for now. We’ll be posting another opportunity in the future for candidates without the required experience.
- Do you have a minimum of 5 years experience with Cloud Security , networking, architecture and migration? If you do not have, please hold off on completing the application for now. We’ll be posting another opportunity in the future for candidates without the required experience.
- Are you legally authorized to work in the United States, US Citizen? If not, please hold off on completing the application for now. We’ll be posting another opportunity in the future for visa candidates.
Ability to Commute:
- Plano, TX 75023 (Required)
Work Location: In person