- Salary
- $90 – $100/hr
- Location
- Chicago, IL, US
- Workplace
- Remote
- Type
- Contract
- Department
- Engineering
- Seniority
- Senior
- Source
- Breezy HR
Description
OVERVIEW
OnTrac is seeking a highly skilled and experienced Senior GCP Cloud Infrastructure Engineer to join a contractor program supporting a critical customer engagement. This role is ideal for an experienced cloud engineer capable of architecting, building, and securing a FedRAMP High-compliant Google Cloud Platform landing zone for a multi-department enterprise migration, while consolidating fragmented legacy systems into a unified, IaC-managed environment. You will work closely with the client technical lead and customer stakeholders to ensure project success from initial definition through final delivery.
ENGAGEMENT
• Expected start date: 5 October 2026
• Duration: 6 months, with possible extension
• Location: United States only, fully remote
REQUIRED CREDENTIALS
• Google Cloud Professional Cloud Architect (PCA)
• Relevant federal compliance certification or demonstrated experience (FedRAMP, NIST 800-53, CJIS, or IL4 environments)
REQUIRED QUALIFICATIONS
• 8+ years designing and deploying production-grade Google Cloud Platform architectures at enterprise scale
• Proven experience building GCP landing zones, including folder/project hierarchy, org policies, and labeling standards
• Deep hands-on expertise implementing least-privilege IAM models integrated with an external Identity Provider for SSO
• Experience provisioning Assured Workloads folders to meet regulated compliance boundaries (FedRAMP, CJIS, HIPAA, or IL4)
• Strong background in Infrastructure-as-Code using Git-based repositories and automated CI/CD deployment pipelines
• Demonstrated skill configuring VPCs, VPNs, Interconnects, firewall rules, Cloud Armor, and VPC Service Controls
• Experience with Cloud Operations Suite, including log sink configuration exporting to external SIEM/SecOps platforms
• Hands-on experience implementing API Gateway or Apigee, including OAuth/JWT validation, rate limiting, and WAF policies
USEFUL QUALIFICATIONS
• Google Cloud Professional Cloud Security Engineer
• Google Cloud Professional Cloud Network Engineer
• Experience migrating large-scale legacy data volumes (multi-terabyte) into cloud storage with validated integrity checks
• Prior work supporting state or federal government IT modernization projects
• Familiarity with managing multi-environment pipelines (Sandbox, Dev, UAT, Prod) for regulated workloads
• Experience integrating third-party financial, identity, or federal database APIs and SFTP connections
• Background in security incident response coordination alongside a centralized SOC/SIEM team
SCOPE AND DELIVERY EXPECTATIONS
The following covers the scope of work we anticipate the contractor supporting throughout the project timeline.
• Deliver a fully documented, FedRAMP High-aligned GCP landing zone spanning organization, resource hierarchy, and policy structure
• Establish repeatable, automated IaC pipelines eliminating manual configuration across all four environments
• Ensure end-to-end network security posture, including border protection and service perimeter controls, before production go-live
• Stand up a centralized API Gateway layer capable of securely brokering 40+ external integrations
• Provide audit-ready logging and monitoring integration verified against the client's SIEM/SecOps ingestion requirements