Summary
Design secure enterprise cloud platforms that support AI-enabled applications. Build automated infrastructure, enforce governance, and define scalable security patterns across cloud environments.
Highlights
Lead secure cloud platform architecture for AI-enabled workloads with strong emphasis on automation, governance, and technical leadership.
Description
Description
Position Summary
We are seeking a Platform Engineer III to lead the design, engineering, and security of enterprise-scale Google Cloud platforms, with a focus on enabling and protecting AI-enabled workloads.
This role is responsible for building the underlying GCP foundation that AI systems depend on—including landing zones, networking, identity, data protection, and controlled access to services such as Vertex AI and Gemini.
You will define how these services are securely consumed across the organization, ensuring strong governance, isolation, and compliance.
You will help architect and enforce secure connectivity patterns, private access to AI services, API and endpoint protection, data security controls, and policy-driven access models.
These standards will be embedded into Terraform-based infrastructure and CI/CD pipelines to ensure consistency and scalability.
The focus of this role is to make AI workloads production-ready, auditable, and secure at scale.
Summary Of Essential Job Functions
Cloud Platform Architecture
Design and evolve enterprise GCP platforms and landing zonesDefine standards for scalable, resilient, and secure cloud infrastructureOwn multi-project and multi-cloud architecture, organization hierarchy, and governance models
Secure AI & Cloud Workloads
Architect security controls protecting AI platforms and services (Gemini, Vertex AI)Implement safeguards for:Sensitive data exposure (PII, PCI)API and model endpoint securityIdentity and access boundariesEstablish secure patterns for AI consumption (not model development)Partner with security teams on AI risk management and compliance
Networking & Connectivity
Lead architecture for:Shared VPC and private service accessPrivate Service Connect and service isolationHybrid connectivity (VPN, Interconnect)Harden ingress/egress paths for AI and application endpointsEnforce network segmentation and zero-trust principles
Infrastructure Automation & CI/CD
Build and standardize Terraform-based infrastructureDrive CI/CD pipelines for infrastructure and platform servicesImplement GitOps workflows and automated policy enforcementEnable secure deployment of AI-integrated applications
Governance & Security Engineering
Implement enterprise security frameworks using:IAM, VPC Service Controls, KMS, DLPPolicy enforcement and compliance automationIntegrate with tools such as Wiz, SIEM, and vulnerability management platformsDefine best practices for secure external endpoints and API exposure
Leadership & Influence
Serve as a technical leader and advisor across Cloud, Security, and Engineering teamsDrive adoption of secure cloud and AI practicesMentor engineers on GCP architecture, security, and automation
Position Requirements
8+ years of experience in cloud engineering, platform engineering, or cloud architectureExpertise in Google Cloud Platform (GCP)Strong experience with:GCP networking (VPCs, Private Service Connect, hybrid connectivity)Landing zone design and governanceCloud security architecture and compliance frameworksHands-on expertise in:Terraform (Infrastructure as Code)CI/CD pipelines (GitLab or similar)Experience securing:APIs, external endpoints, and distributed systemsCloud-native and AI-integrated workloads
Preferred
Exposure to Vertex AI, Gemini, or AI-enabled platforms (from a platform/security perspective)Experience with AI security, model protection, and data governance frameworksFamiliarity with tools such as Wiz, DLP, SIEM, CSPMMulti-cloud experience (AWS preferred)GCP certifications (Professional Cloud Architect, Security Engineer)
Credit One Bank, N.A.
is a data-driven financial services company based in Las Vegas.
Founded in 1984, Credit One Bank offers a spectrum of credit card products for people in all stages of financial life.
Credit One Bank is an equal opportunity employer committed to diversity and inclusion and does not discriminate against any employee or applicant for employment because of age, race, religion, color, disability, sex, sexual orientation, or national origin.
Reasonable accommodations can be made for those who require them, including access to job applications and workplace accommodations.
Employment at Credit One Bank is based on mutual consent (also known as at-will).
This means that employees and the Bank may terminate the employment relationship at any time, with or without cause and with or without notice.
Please contact the recruiter for this position to learn more.
Credit One Bank does not accept unsolicited resumes from agencies and is not responsible for related fees.