Remote job
Cloud Governance Engineer
Job details
About this role
Role overview This position focuses on governing a multi-cloud estate rather than building or operating it directly. The work centers on defining the rules the cloud environment must follow, encoding those rules into enforceable controls, and proving they are working in production. A meaningful part of the role is communicating technical risk to Finance, Security, and Product leadership so they can make informed decisions about cost, exposure, and trade-offs.
Responsibilities - Author and maintain governance policies and standards spanning GCP, AWS, and Azure, then implement them as technical guardrails using native policy services. - Operate the exception and waiver workflow from intake and risk assessment through time-bound approval, expiry, and follow-up. - Partner with Security teams to enforce least-privilege IAM, network, encryption, and key-management standards across the organization. - Build and maintain dashboards tracking security posture, credential rotation, policy violations, configuration drift, and remediation times. - Own tagging and labeling standards so cost, ownership, and environment can be attributed reliably across the estate. - Drive cost governance through spend visibility, showback, anomaly detection, commitment and discount coverage reviews, and surfacing waste to owning teams.
Requirements - Four or more years working in public cloud, with at least two years hands-on in GCP. - Demonstrated experience rolling out preventative guardrails in at least one hyperscaler, including an example of what broke and how it was resolved. - History of authoring a cloud policy or standard that other teams were required to follow. - Practical experience running or contributing to an exception and waiver process for cloud controls. - Working knowledge of cloud IAM, network security, encryption, and secrets management. - Terraform for infrastructure-as-code, comfort extending to policy-as-code, plus Python for automation and reporting. - Track record of explaining technical risk to non-technical audiences and driving decisions to closure.
Nice to have - GCP Professional Cloud Security Engineer or Professional Cloud Architect certification. - Policy-as-code tooling such as OPA, Conftest, or Sentinel, and Kubernetes governance experience. - Cloud cost tooling including GCP billing exports with BigQuery, AWS Cost Explorer, or platforms like Cloudability or Apptio. - Familiarity with SOC 2, HIPAA, or GDPR control frameworks.
Benefits and work setup - Equity participation, bonus scheme, ten percent flex benefit, meal allowance, medical and life insurance, plus twenty-five days of annual leave plus public holidays. - Fully remote for candidates outside the Greater Porto municipalities; hybrid three-days-in-office a target for those within them.