We are deploying a managed GenAI SaaS platform into regulated client environments using a hybrid "carve-out" model:
- Control plane (application logic, AI inference, orchestration, management) runs provider-side in Azure — this is already built and operational.
- Data / client plane (databases, object storage, cache, telemetry) resides inside the client's own cloud tenant — which may be GCP, Azure, or (on the roadmap) AWS.
The immediate work is client-side (GCP first): standing up the data-plane environments, landing zones, and policy guardrails in client tenants, and connecting them to the existing Azure control plane.
You will not be designing or rebuilding the Azure control plane — but you must understand it well enough to integrate the client data plane cleanly and reason about the multi-cloud, cross-tenant management model end to end. Deep GCP is the priority; solid working Azure knowledge is required to make the two sides interoperate.
You will work alongside a solution architect who owns the overall design and will provide direction, architectural guidance, and support throughout — so you're delivering against a clear technical vision, not building it in isolation.
What You'll Do
- Stand up client-plane data environments in GCP (and Azure/AWS as clients require) and connect them to the existing Azure control plane.
- Design and deploy secure-by-default landing zones and tenant onboarding patterns in client tenants.
- Author and enforce organization policies / guardrails enabling specific management actions (e.g. create/configure resources) while strictly prohibiting access to client data.
- Own Infrastructure-as-Code (Terraform) and GitOps (Flux) delivery for client-plane resources.
- Implement the cross-cloud, cross-tenant management pattern — integrating with the existing Azure Lighthouse setup and building the GCP resource-hierarchy / IAM equivalents.
- Implement cross-cloud telemetry (Grafana / Telegraf) with metadata-only logging that avoids client-data exfiltration.
- Define client prerequisites — networking, security policies, landing-zone configuration — for engagement kickoff.
- Support incident response, upgrades, versioning across client environments.
Must-Have (Non-Negotiable)
- Deep, hands-on GCP — resource hierarchy (Org → Folders → Projects), Organization Policy Service, IAM, VPC Service Controls, GKE.
- Proven multi-tenant / multi-client deployment experience — same platform operated across many isolated client environments.
- Multi-cloud / hybrid architecture knowledge — able to reason about control-plane / data-plane separation across clouds and connect a GCP data plane to an Azure control plane.
- Deep policy / guardrail expertise — granular access separating control-plane management from data-plane access.
- Strong IaC — Terraform (modules, state, multi-environment) in production.
- GitOps / CI-CD — Flux (or ArgoCD) and pipeline-driven deployments.
- Working Azure knowledge — management groups, Azure Policy, and an understanding of Azure Lighthouse delegated management (enough to integrate with the existing control plane — not to design it from scratch).
- Understanding of data residency / sovereignty requirements for regulated clients.
Nice-to-Have
- AWS — Organizations, Control Tower, SCPs (roadmap client cloud).
- Observability — Grafana, Telegraf, Prometheus, cross-cloud telemetry standardization.
- Customer-managed keys / encryption — Cloud KMS, Key Vault, CMEK/CMK governance.
- Experience deploying GenAI / RAG workloads (vector stores, managed inference endpoints).
- Financial services / regulated-industry delivery background.
- Relevant certs: GCP Professional Cloud Architect / DevOps Engineer (Azure certs a plus).
Team & Support
You'll be part of the Cloud Transformation team and work directly with the engagement's solution architect, who owns the target architecture and will provide hands-on guidance, design direction, and ongoing support. This is a delivery-focused engineering role with strong architectural backing — ideal for someone who is deeply hands-on and wants to execute against a well-defined vision with an experienced architect in their corner.
What Success Looks Like
- A repeatable, policy-enforced GCP tenant onboarding pattern for client data planes.
- First client landing zone (GCP) and prerequisites defined and deployed.
- GCP data plane cleanly integrated with the existing Azure control plane, with control-plane/data-plane separation demonstrable to a client CISO.
- CI/CD-driven deployment + schema migration working end-to-end into the client tenant.
.png)

