GCP IAM Engineers implement secure identity and access management for Google Cloud Platform applications in regulated environments. This onsite contract role focuses on provisioning controls, automation, and compliance through Terraform and scripting.
Key Responsibilities:
- Provision and manage IAM roles, bindings, and service accounts across projects using Terraform and Git workflows.
- Implement least-privilege access patterns for application onboarding, including runtime identity, human access, and break-glass procedures.
- Support identity integrations and group/role mappings per enterprise standards.
- Produce onboarding evidence such as access approvals, deployment records, and audit log references.
- Maintain documentation and runbooks for processes.
- Troubleshoot access issues and collaborate with platform, network, and security teams.
Required Technical Skills:
- Hands-on experience with GCP IAM including roles, service accounts, and policy inheritance.
- Terraform fundamentals covering modules and state management.
- Git and pull request workflow discipline.
- Python scripting for automation and validation tasks.
- Familiarity with change/release processes in controlled environments.
Basic Qualifications:
- Proven ability to onboard applications meeting access-control standards with minimal rework.
- Experience reducing IAM incidents and producing audit-ready evidence.