Jobs and Careers
CV

Principal Cloud Engineer- GCP Platform Technical Lead

CVS Health
New York-161 Ave of the Americas, United States, United Statesfull_timeVerifiedPosted 16 Jul 2026
💰 $288,400/yr($144,200/yr$288,400/yr)

About the role

We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time.

Principal Cloud Engineer/ GCP Platform Technical Lead

Who are you

You are a cloud-first, hands-on Principal Engineer and the authoritative technical voice for the enterprise Google Cloud Platform (GCP) environment. You bring deep engineering expertise, strong architectural judgment, and a platform-owner mindset to design, build, and operate a secure, scalable, and production-grade GCP landing zone in highly regulated environments.

You are equally comfortable setting technical vision, writing production-grade code, documenting complex decisions through Architecture Decision Records (ADRs), and guiding teams through disciplined execution. You influence engineers and stakeholders through clarity of thought, strong design rationale, and operational rigor.

You believe Infrastructure as Code, security-by-design, automation, and observability are foundational—not optional. You are motivated by building durable, self-service platforms that empower teams to move quickly while maintaining reliability, compliance, and enterprise governance.

Role Responsibilities

Development & Enforcement

  • Own the enterprise GCP platform end-to-end, including organization structure, resource hierarchy, billing, networking architecture, IAM tiering, CMEK, VPC Service Controls, and centralized logging.
  • Define, build, and maintain the enterprise GCP Landing Zone, including Shared VPC, project factory patterns, Org Policies, and governance guardrails.
  • Serve as the final technical authority on GCP architecture and engineering decisions, ensuring scalability, security, reliability, and production readiness.
  • Establish and enforce engineering standards across Infrastructure as Code, GitOps workflows, naming conventions, tagging strategies, branching models, and deployment practices using Terraform and Kubernetes Config Connector (KCC).

Collaboration & Expertise

  • Act as the technical anchor and senior-most individual contributor for the GCP Cloud Engineering and Platform teams.
  • Partner closely with enterprise architecture, security, networking, operations, and application teams to translate business and regulatory requirements into scalable platform capabilities.
  • Collaborate across technology towers and platform teams (including AI and provisioning platforms) to enable consistent, secure, and efficient cloud adoption.
  • Influence cloud strategy across CSPs while driving GCP as the primary enterprise platform of choice.

Analysis & Configuration

  • Design and engineer enterprise-grade GCP networking, including Shared VPC, NCC hub-and-spoke architectures, VPC Service Controls, Private Service Connect, Cloud NAT, and hybrid connectivity using Cloud Interconnect and HA VPN.
  • Architect and operate secure private GKE clusters using Workload Identity, Binary Authorization, Shielded Nodes, Config Sync, and least-privilege IAM patterns.
  • Define identity and access strategies leveraging IAM, group-based access, PAM entitlements, Workload Identity Federation, and Entra ID integration.
  • Evaluate platform designs for cost efficiency, performance, resilience, and long-term sustainability.

Operational Support

  • Build and maintain self-service platform capabilities enabling product teams to deploy safely and independently.
  • Integrate observability as a first-class platform feature using Cloud Monitoring, Cloud Logging, Datadog, SLIs/SLOs, alerting policies, and PagerDuty.
  • Design and operate CI/CD and automation infrastructure, including self-hosted GitHub Actions runners on GKE using ARC.
  • Manage secrets and encryption lifecycle using Secret Manager, CMEK, External Secrets Operator, and automated key rotation.
  • Participate in on-call rotation and provide L3 escalation support for platform and infrastructure incidents.
  • Drive continuous, automated compliance for regulatory frameworks such as HIPAA, PCI-DSS, SOC 2, and FedRAMP.

Mentorship & Training

  • Mentor engineers at all levels, raising the bar for cloud engineering excellence, security, and operational maturity.
  • Lead and participate in architecture, design, code, and security reviews for all platform changes.
  • Coach engineers on GCP best practices, cloud-native design patte

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

CVS Health

View company profile →