Principal Cloud Infrastructure Engineer (GCP) at Cvshealth

We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time. GCP Platform Technical Lead     Position Summary   We are looking for a GCP Principal Engineer to lead our Cloud Engineering team, owning the Google Cloud Platform for the enterprise. This is a foundational platform role — you are the GCP technical authority, setting architectural /engineering   direction,   establishing   engineering standards, and ensuring the platform is secure, scalable, and built to last.   Your role will include driving designs of the platform , mentor ing   the engineers around you, and   aligning   quality and best practices. You bring deep GCP   expertise , a platform-owner mindset, and the leadership presence to align engineers and stakeholders around a shared technical vision.   T his role demands a  cloud-first thinker  who ensures cloud solutions meet business needs efficiently while prioritizing Infrastructure as Code ( IaC ) to create repeatable, automated deployments. You need to have a proven   track record   of  architecting cloud environments from scratch .   You'll   drive cloud transformation initiatives   all CSP’s focusing on the   GCP    platform   while ensuring every design decision considers security, reliability, and scalability.   This is not a hands-off leadership role — you write code, review designs, and stay close to the work.   Major Responsibilities   1.  GCP Platform Ownership   Own the enterprise GCP platform end-to-end: organization structure, resource hierarchy, networking architecture   while collaborating with several teams to ensure the platform is stable and compliant.    Define and   maintain   the GCP landing zone — Shared VPC, Org Policies ,   and project factory patterns — as the foundation all product teams build on.   Serve as the   one of the   final technical authorit ies   on GCP   engineering   decisions, reviewing designs for scalability, security, and operational excellence before they reach production.   Build self-service platform capabilities that enable product engineering teams to move fast without compromising standards.   2.  Technical Team Leadership   Lead the   GCP   cloud engineering team as the technical anchor — set direction, conduct design reviews, unblock engineers, and drive delivery on platform initiatives.   Establish and enforce engineering standards:   IaC   patterns, naming conventions, tagging strategy, branching models, and deployment practices.   Mentor engineers at all levels, building depth on the team and raising the bar on what “excellence” looks like in cloud engineering.   Partner with architecture, security, operations, and business stakeholders to translate enterprise requirements into platform capabilities.   3.  Infrastructure as Code & Automation   Drive Infrastructure as code as a core   principle    —   reusable modules, pipeline integration, state management, and policy guardrails.   Build and maintain CI/CD pipelines using Cloud Build, GitHub Actions, and Artifact Registry for both platform infrastructure and application teams.   Write production-quality automation to extend platform functionality, integrate GCP APIs, and   eliminate   operational toil.   Implement policy-as-code using OPA, Config Connector, and GCP Org Policies to enforce governance at scale without manual gatekeeping.   4.  Networking, Security & Compliance   Architect /Engineer   GCP networking: Shared VPC, VPC Service Controls, Private Service Connect,   NCC ,   Cloud   NAT ,   and hybrid connectivity via Cloud Interconnect and HA VPN.   Own the enterprise security posture on GCP — Workload Identity Federation, Binary Authorization, Secret Manager, IAM least-privilege design, and SIEM/CSPM integration (Security Command Center, Prisma Cloud, or Wiz).   Drive continuous automated compliance across applicable regulatory frameworks (HIPAA, PCI, SOC 2)   so   controls are enforced in real time, not discovered at audit.   Integrate observability — Cloud Operations Suite, Datadog, and SLO/SLI frameworks — as a first-class   platform   capability across all workloads.   5.  Platform Strategy & Continuous Improvement   Own the GCP platform roadmap, evaluating new GCP services and capabilities and making deliberate decisions about what the enterprise adopts and when.   Incorporate   FinOps practices across the platform: committed use discounts, rightsizing, budget alerting, and cost allocation as engineering disciplines, not afterthoughts.   Research and pilot emerging GCP capabilities   like   — Vertex AI, GKE Enterprise, Duet AI for DevOps — evaluating their fit for enterprise adoption.   Foster a culture   that drive collaboration across teams and towers to shape the future of   cutting-edge   cloud technology adoption      Required Qualifications   10+ years in cloud and infrastructure engineering with 5+ years of deep, hands-on GCP experience at enterprise scale.   Proven ownership of a GCP organization — Resource Hierarchy, Billing, Org Policy, IAM, and multi-project governance in production.   Demonstrated technical leadership: you have led a platform team or major enterprise cloud initiative, set technical direction, and grown engineers around you.     Deep GCP   expertise   required   across:   Compute & Containers: GKE (Autopilot + Standard), Cloud Run, Compute Engine, MIGs   Networking: Shared VPC, VPC Service Controls, Private Service Connect, Cloud Armor, Interconnect   Data & Messaging: BigQuery , Pub/Sub, Cloud Storage, Dataflow, Cloud Composer   Security: IAM, Workload Identity, SCC, Binary Authorization, Secret Manager, VPC-SC   IaC   & Automation: Terraform (modules, remote state, OPA), Cloud Build, Config Connector   Observability:   Cloud Operations Suite, Datadog, SLO/SLI design, PagerDuty integration   Languages: Python and Go (required); Bash   proficiency   expected     Preferred Qualifications   Google Cloud Professional Cloud Architect certification (strongly preferred)   Google Cloud Professional DevOps Engineer certification   HashiCorp   Terraform Associate or Professional certification   Experience in regulated industries applying HIPAA, PCI-DSS, or FedRAMP controls on GCP   Familiarity with Anthos, GKE Enterprise, and multi-cloud connectivity patterns   Experience with Vertex AI platform and   MLOps   patterns on GCP     Education   Bachelor’s degree in Computer Science , Engineering, or a related field — or equivalent demonstrated experience.   Pay Range The typical pay range for this role is: $144,200.00 - $288,400.00 This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls.  The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors.  This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above.  This position also includes an award target in the company’s equity award program.    Our people fuel our future. Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong. Great benefits for great people We take pride in offering a comprehensive and competitive mix of pay and benefits that reflects our commitment to our colleagues and their families. This full‑time position is eligible for a comprehensive benefits package designed to support the physical, emotional, and financial well‑being of colleagues and their families. The benefits for this position include medical, dental, and vision coverage, paid time off, retirement savings options, wellness programs, and other resources, based on eligibility. Additional details about available benefits are provided during the application process and on Benefits Moments . We anticipate the application window for this opening will close on: 10/30/2026 Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.