Design and implement GCP network solutions, lead NCC transition, and execute production network cutovers.
Key Highlights
Key Responsibilities
Technical Skills Required
Benefits & Perks
Nice to Have
Job Description
Network Engineer (Google Cloud Platform Network Delivery)
6 to 12 month contract- Fully Remote
Potential to renew
Sought Skills & Experience:
• Extensive network engineering experience with deep, hands-on GCP networking delivery.
• Expert Terraform / Infrastructure-as-Code for network automation — modules, scaffolding, and production hardening.
• Strong hands-on skills across NCC, Shared VPC, VPC Peering, Cloud Router, BGP, route tables, and IPAM.
• Experience with hybrid connectivity (Cloud Interconnect / Cross-Cloud Interconnect to Azure) and DMZ / egress inspection (e.g., Palo Alto).
• Strong documentation (MOP / runbooks, READMEs, as-builts) and disciplined code review.
Role Overview
Serves as the senior network engineer executing s NCC transition. Leads the design and implementation of GCP network solutions tailored to needs, ensuring risk mitigation and compliance across systems. Builds the Terraform Infrastructure-as-Code that stands up the NCC hub, spokes, route tables, hybrid attachments, and DMZ insertion; authors the migration runbook; and executes wave-based production cutovers of Shared VPCs, Hub VPCs, and DMZ — followed by decommission of the legacy peering mesh.
Key Responsibilities
• Design Terraform module structure and repository scaffolding aligned to existing IaC.
• Develop Terraform for the NCC hub, spokes, route tables, hybrid attachments, and DMZ insertion.
Interested in remote work opportunities in IT & Network Engineering? Discover IT & Network Engineering Remote Jobs featuring exclusive positions from top companies that offer flexible work arrangements.
• Build and iteratively test in a mock lab; produce code documentation and READMEs; run code-review cycles and rework with.
• Author the migration Method of Procedure (MOP) — a step-by-step runbook — plus test/validation plans (routing and application connectivity per step) and rollback procedures.
• Surface pilot-workload dependencies (one non-production workload), plan change windows, and provide pilot execution guidance and advisory during the change window.
• Productionize Terraform (harden, parameterize, environment promotion) and run pre-cutover dry-runs / staging rehearsals per wave.
• Execute BU Shared VPC production cutovers (up to eight production VPCs) in off-hours change windows, supplier-led alongside.
• Support high-risk central events — Hub VPC + CCI/Azure cutover and DMZ / Palo Alto egress cutover — with post-cutover validation and traffic verification.
• Provide hypercare / stabilization and rollback / war-room standby following each wave.
• Execute legacy VPC Peering decommission and cleanup; deliver as-built documentation and production runbook updates.
Primary Deliverables
• NCC Terraform modules (hub, spokes, route tables, hybrid attachments, DMZ) and mock-lab validation results.
• Migration MOP (step-by-step runbook), test / validation plans, and rollback procedures.
• Pilot execution support and post-pilot lessons-learned report; self-service framework handoff.
• Productionized Terraform and executed cutovers for in-scope BU Shared VPCs, Hub VPCs (CCI/Azure), and DMZ.
• Post-cutover validation and hypercare; legacy VPC Peering decommission; as-built documentation and production runbooks.
Required Qualifications
• Extensive network engineering experience with deep, hands-on GCP networking delivery.
Browse our curated collection of remote jobs across all categories and industries, featuring positions from top companies worldwide.
• Expert Terraform / Infrastructure-as-Code for network automation — modules, scaffolding, and production hardening.
• Strong hands-on skills across NCC, Shared VPC, VPC Peering, Cloud Router, BGP, route tables, and IPAM.
• Experience with hybrid connectivity (Cloud Interconnect / Cross-Cloud Interconnect to Azure) and DMZ / egress inspection (e.g., Palo Alto).
• Proven execution of production network cutovers in off-hours change windows, including validation, rollback, and hypercare.
• Strong documentation (MOP / runbooks, READMEs, as-builts) and disciplined code review.
Preferred Qualifications
• Google Cloud Professional Cloud Network Engineer certification.
• Direct NCC implementation experience (hub / spokes / route tables / hybrid attachments / DMZ insertion).
• Mock-lab / staging-rehearsal and wave-based migration experience.
• Multi-cloud (GCP ↔ Azure) routing and BGP troubleshooting.
• Experience in large, regulated, enterprise-scale (e.g., retail) environments.
Core Technology Environment
Google Cloud networking — Network Connectivity Center (NCC), Shared VPC, VPC Peering, Cloud Router, BGP, route tables, IPAM, and Cloud DNS; Cloud Interconnect / Cross-Cloud Interconnect to Azure; DMZ / Palo Alto egress inspection; and Terraform / Infrastructure-as-Code for network automation, including mock-lab validation and wave-based production cutovers.
Engagement Details & Working Arrangement
• Delivery model: Dedicated consulting resource supporting NCC Transition workstream — the migration of GCP network from a VPC Peering hub-and-spoke topology to a Network Connectivity Center (NCC) fabric.
Similar Jobs
Explore other opportunities that match your interests