We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time.
Who Are You
You are a cloud-first, hands-on Staff Cloud Engineer who serves as a key technical contributor for the enterprise Google Cloud Platform (GCP) environment. You bring strong engineering expertise, sound architectural judgment, and a platform-focused mindset to help design, build, and operate secure, scalable, and production-grade GCP landing zones in highly regulated environments.
You are comfortable translating architecture into implementation, writing production-quality code, documenting technical decisions through Architecture Decision Records (ADRs), and collaborating with cross-functional teams to deliver reliable cloud platform capabilities. You influence peers and stakeholders through technical expertise, practical solutions, and operational excellence.
You believe Infrastructure as Code, security-by-design, automation, and observability are foundational principles for modern cloud platforms. You are motivated by building scalable, self-service solutions that enable teams to innovate quickly while maintaining reliability, compliance, and governance standards.
Role Responsibilities
Development & Enforcement
- Support the enterprise GCP platform, including organization structure, resource hierarchy, billing, networking architecture, IAM tiering, CMEK, VPC Service Controls, and centralized logging.
- Design, implement, and maintain enterprise GCP Landing Zone capabilities, including Shared VPC, project factory patterns, Org Policies, and governance guardrails.
- Contribute to GCP architecture and engineering decisions, ensuring solutions are scalable, secure, reliable, and operationally ready.
- Implement and maintain engineering standards across Infrastructure as Code, GitOps workflows, naming conventions, tagging strategies, branching models, and deployment practices using Terraform and Kubernetes Config Connector (KCC).
Collaboration & Expertise
- Serve as a senior technical contributor within the GCP Cloud Engineering and Platform teams.
- Partner with enterprise architecture, security, networking, operations, and application teams to translate business and regulatory requirements into scalable cloud solutions.
- Collaborate across technology and platform teams, including AI and provisioning platforms, to enable secure and efficient cloud adoption.
- Contribute to cloud strategy initiatives and support GCP adoption as a strategic enterprise platform.
Analysis & Configuration
- Design and implement enterprise-grade GCP networking solutions, including Shared VPC, NCC hub-and-spoke architectures, VPC Service Controls, Private Service Connect, Cloud NAT, and hybrid connectivity using Cloud Interconnect and HA VPN.
- Deploy and support secure private GKE clusters using Workload Identity, Binary Authorization, Shielded Nodes, Config Sync, and least-privilege IAM practices.
- Implement identity and access management solutions leveraging IAM, group-based access controls, PAM entitlements, Workload Identity Federation, and Entra ID integration.
- Assess platform designs for performance, reliability, scalability, cost optimization, and operational sustainability.
Operational Support
- Build and maintain self-service platform capabilities that enable product teams to deploy workloads safely and independently.
- Implement observability solutions using Cloud Monitoring, Cloud Logging, Datadog, SLIs/SLOs, alerting policies, and PagerDuty.
- Support CI/CD and automation infrastructure, including self-hosted GitHub Actions runners on GKE using Actions Runner Controller (ARC).
- Manage secrets and encryption lifecycle processes utilizing Secret Manager, CMEK, External Secrets Operator, and automated key rotation practices.
- Participate in on-call rotations and provide advanced support for platform and infrastructure incidents.
- Assist in automating compliance controls aligned with frameworks such as HIPAA, PCI-DSS, SOC 2, and FedRAMP.
Mentorship & Training
- Mentor and support engineers by sharing cloud engineering best practices, security principles, and operational standards.
- Participate in architecture, design, code, and security reviews to ensure platform quality and consistency.
- Promote adoption of GCP best practices and cloud-native design patterns.
- Contribute to developing technical knowledge and cloud engineering capabilities across the organization.
Innovation and Research
- Evaluate and pilot emerging GCP and cloud-native technologies, including GKE Enterprise, Vertex AI, and AI-assisted DevOps capabilities.
- Research modern Kubernetes, networking, and platform engineering approaches to improve scalability, security, and developer experience.
- Explore AI-driven infrastructure automation and operational improvement opportunities.
- Support a culture of innovation through disciplined experimentation and measurable outcomes.
Strategic Planning
- Contribute to the GCP platform roadmap aligned with enterprise priorities and regulatory requirements.
- Author and maintain Architecture Decision Records (ADRs) for key platform initiatives and technical decisions.
- Support FinOps initiatives, including cost allocation, budget monitoring, committed-use discounts, and rightsizing recommendations.
- Help ensure platform scalability and cloud transformation efforts support long-term business growth and compliance objectives.
Required Qualifications
7+ years of experience in infrastructure or cloud engineering, including 5+ years of deep, hands-on experience with Google Cloud Platform (GCP) at enterprise scale.
5+ years of experience with proven ownership of a GCP organization, including resource hierarchy, billing, organizational policies, IAM, and multi-project governance.
5+ years of demonstrated technical leadership as a Principal Engineer or Platform Owner for a major enterprise cloud initiative.
3+ years of experience implementing cloud best practices and Well-Architected Framework principles.
6+ years of deep expertise across GCP cloud services, including:
Compute & Containers
- GKE (Private, Autopilot, and Standard)
- Cloud Run
- Compute Engine
- Managed Instance Groups (MIGs)
Networking
- Shared VPC
- Network Connectivity Center (NCC)
- VPC Service Controls
- Private Service Connect
- Cloud Armor
- Interconnect
- High Availability VPN (HA VPN)
Security & Identity
- IAM
- Workload Identity
- Workload Identity Federation (WIF)
- Privileged Access Manager (PAM)
- Binary Authorization
- Security Command Center
- Secret Manager
- Customer-Managed Encryption Keys (CMEK)
Data & Messaging
- BigQuery
- Pub/Sub
- Cloud Storage
- Dataflow
- Cloud Composer
Infrastructure as Code (IaC) & Automation
- Terraform (modules, remote state, and policy as code)
- Config Connector (KCC)
- Cloud Build
- GitOps
Observability
- Cloud Operations Suite
- Datadog
- SLIs/SLOs
- PagerDuty
1+ year of experience implementing Agentic AI solutions and building AI agents.
Preferred Qualifications
- Strong programming and scripting experience in Python and Go; Bash required. PowerShell experience is a plus.
- Experience operating and supporting production platforms in regulated environments.
- Google Cloud Professional Cloud Architect and/or Professional DevOps Engineer certification.
- HashiCorp Terraform Associate or Professional certification.
- Experience with Palo Alto VM-Series NGFW and F5 BIG-IP VE on GCP.
- Familiarity with Anthos, GKE Enterprise, and multi-cloud connectivity patterns.
- Experience with Vertex AI, large language models (LLMs), and enterprise MLOps practices.
- Healthcare or other highly regulated industry experience, including HIPAA, SOC 2, PCI-DSS, or FedRAMP environments.
- Experience with advanced CI/CD runner infrastructure and multi-OS build environments.
Education
Bachelor’s degree in Computer Science, Engineering, or a related field, or equivalent experience (High School diploma + 4 years of relevant experience)
Pay Range
The typical pay range for this role is:
$130,295.00 - $260,590.00
This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls. The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors. This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above. This position also includes an award target in the company’s equity award program.
Our people fuel our future. Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong.
Great benefits for great people
We take pride in offering a comprehensive and competitive mix of pay and benefits that reflects our commitment to our colleagues and their families.
This full‑time position is eligible for a comprehensive benefits package designed to support the physical, emotional, and financial well‑being of colleagues and their families. The benefits for this position include medical, dental, and vision coverage, paid time off, retirement savings options, wellness programs, and other resources, based on eligibility.
Additional details about available benefits are provided during the application process and on Benefits Moments.
We anticipate the application window for this opening will close on: 09/22/2026
Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.