Posted on: 21/07/2026



About the role :
We are seeking a Lead/Principal GCP Cloud Solution Architect to own Google Cloud governance for Cognizant's Enterprise Cloud Management Platform including the Organisation hierarchy, Project Factory, Shared VPC design, Org Policies, and GCP-native security controls.
GCP is the fastest-growing cloud in Cognizant's estate, with significant adoption in AI/ML workloads (Vertex AI, BigQuery) and engineering Cognizant internal BUs.
This role is critical to bringing the GCP estate into the same governance framework as Azure and AWS delivering parity in security posture, lifecycle management, and cost attribution, and ensuring AI/ML projects are provisioned with proper guardrails.
In this role, you will :
- Design and manage the GCP Organisation hierarchy Cognizant internal BU-aligned Folder structure, Project Factory for automated provisioning, and resource policy inheritance.
- Implement GCP Org Policies at Organisation and Folder level restricting external IP access, enforcing data residency, restricting public Cloud Storage access, and requiring Workload Identity Federation.
- Design and implement the GCP Landing Zone Shared VPC Host/Service Project model, Cloud NAT, Cloud Interconnect, Private Google Access, and Cloud DNS.
- Implement GCP IAM governance principle of least privilege, Workload Identity Federation (no long-lived service account keys), and Groups-based IAM.
- Manage the GCP project lifecycle end-to-end from Project Factory request through CSPM auto-enrolment, labelling enforcement, and decommission.
- Deploy and manage Google Security Command Centre (SCC) Premium across the Organisation Security Health Analytics, Event Threat Detection, and Container Threat Detection.
- Implement GCP Cloud Armor as the enterprise WAF/DDoS baseline and design VPC security architecture hierarchical firewall policies and Private Service Connect for managed services.
- Design security and governance controls for AI/ML workloads on GCP (Vertex AI, Gemini API, BigQuery ML) private endpoints, IAM-only access, and VPC Service Controls perimeters.
- Own GCP cost governance mandatory labelling via Org Policy, Cloud Billing integration with Apptio Cloudability, and Committed Use Discount management.
- Maintain working awareness of one secondary cloud (AWS or Azure) sufficient for cross-cloud platform discussions.
- Guide Cognizant internal BU GCP engineering teams on secure-by-default solution design (GKE, Cloud Run, Cloud Functions, BigQuery, Pub/Sub) and review Terraform templates before provisioning.
- Participate in cross-cloud architecture decisions with the AWS and Azure Solution Architects to keep the CMP governance model consistent across all three clouds.
What you must have to be considered :
- 4-6 years of GCP architecture/engineering experience with hands-on Org Policy, Shared VPC, and Security Command Centre experience in a real enterprise organisation not just single-project deployments.
- Deep expertise in GCP resource hierarchy, VPC networking (Shared VPC, Private Service Connect), IAM (Workload Identity Federation), and Cloud Armor.
- Hands-on experience with GCP Security Command Centre findings management, custom modules, and SCC Premium threat detection features.
- Expert-level Terraform on GCP (google / google-beta providers) writing modules from scratch, plus CI/CD for IaC (GitHub Actions, Cloud Build).
- Working awareness of one secondary cloud AWS (Organizations, SCPs, IAM Identity Center) or Azure (Management Groups, Azure Policy, Entra ID).
- Ability to interpret CSPM/SCC findings, distinguish critical risk from informational noise, and design/implement the corrective fix.
- Ability to investigate a cloud security incident, trace root cause, and guide Cognizant internal BU teams through remediation.
- Ability to embed security controls into Terraform templates so compliance is provisioned automatically rather than reviewed after the fact.
- Strong stakeholder communication skills able to produce architecture documentation independently and contribute to enterprise architecture discussions.
These will help you succeed :
- Hands-on GKE cluster security experience (Workload Identity, Binary Authorization, network policies) and Vertex AI / BigQuery security (VPC Service Controls, CMEK, Private Service Connect).
- Familiarity with GCP Chronicle SIEM (log ingestion, detection rules) or Zscaler ZPA connector deployment on GCP (App Connector on GCE).
- Experience with Cloud Armor Adaptive Protection, GCP Assured Workloads (data sovereignty), or Apptio Cloudability GCP billing integration.
- Awareness of CIEM, Privileged Access Management, and Data Security Posture Management (DSPM) concepts.
- Experience with Firebase or App Engine governance for Cognizant internal BU-managed projects outside the standard VPC governance model.
Preferred certifications :
- GCP Professional Cloud Architect, GCP Professional Cloud Security Engineer, Terraform Associate.
Good to have :
- GCP Professional DevOps Engineer, GCP Professional Cloud Network Engineer, AWS Solutions Architect Associate or Azure Administrator Associate (secondary cloud).
Work model :
We believe hybrid work is the way forward as we strive to provide flexibility wherever possible. Based on this role's business requirements, this is a hybrid position requiring 2-3 days a week in a client or Cognizant office in Pune/Hyderabad/Kolkata/Bangalore/Coimbatore. Regardless of your working arrangement, we are here to support a healthy work-life balance though our various wellbeing programs.
The working arrangements for this role are accurate as of the date of posting. This may change based on the project you're engaged in, as well as business and client requirements. Rest assured; we will always be clear about role expectations.
We're excited to meet people who share our mission and can make an impact in a variety of ways. Don't hesitate to apply, even if you only meet the minimum requirements listed. Think about your transferable experiences and unique skills that make you stand out as someone who can bring new and exciting things to this role.
Did you find something suspicious?
Posted by
Posted in
DevOps / SRE
Functional Area
Technical / Solution Architect
Job Code
1656064