Multi-cloud CIS-Compliant Enterprise Landing Zone

Job ID: 40465245

Budget: ₹400 – ₹750 INR

Enterprise Landing Zones & Cloud Governance
CIS-Compliant Architecture: Architected and deployed multi-account enterprise Landing Zones across AWS, GCP, and OCI, ensuring strict alignment with CIS Foundations Benchmarks and organizational compliance guardrails.

Multi-Tenant Isolation: Established robust tenant-isolation strategies utilizing hierarchical folder structures, automated IAM boundaries, and centralized Organization Policies to enforce least-privilege access at scale.

Centralized Security & Logging: Engineered unified security baselines integrating distributed audit trails, centralized SIEM data streams, and automated guardrails using AWS Control Tower and GCP Security Command Center.

Network Landing Zones: Implemented complex hub-and-spoke networking topologies featuring secure shared VPCs, automated DNS peering, and dedicated interconnect/VPN links for seamless hybrid-cloud connectivity.

Advanced Google Cloud Platform (GCP) Engineering
Enterprise GCP Migrations: Spearheaded large-scale data center-to-GCP migrations, leveraging automated discovery tools and executing zero-downtime database and VM cutovers.

FinOps & Resource Optimization: Instituted granular billing export pipelines and automated lifecycle management policies, slashing infrastructure overhead through data-driven resource sizing and Committed Use Discounts (CUDs).

Global Networking Management: Engineered globally distributed infrastructure using GCP Cloud Load Balancing, Cloud Armor DDoS mitigation, and cross-region VPC network peering.

Data & AI Infrastructure: Managed resilient backends for data pipelines utilizing Cloud Spanner, BigQuery, and Vertex AI infrastructure, ensuring low-latency data access for analytical applications.

Enterprise Kubernetes (GKE / EKS) Orchestration
Production-Grade Cluster Operations: Designed and managed multi-region Google Kubernetes Engine (GKE) and Amazon EKS clusters, executing seamless, zero-downtime canary upgrades of production control planes.

Advanced Networking & Mesh: Implemented enterprise service meshes (Istio/Cilium) to enforce mutual TLS (mTLS), micro-segmentation, and advanced traffic-routing patterns across distributed clusters.

GitOps Continuous Delivery: Standardized application delivery pipelines by implementing GitOps models via ArgoCD and Flux, ensuring cluster states remain drift-free from declarative Git repositories.

Node Pool Optimization: Designed cost-efficient cluster topologies using dynamic node pools, combining spot instances with custom taint/toleration and node-affinity rules for non-critical batch workloads.

Control Plane Automation with Crossplane
Universal Control Planes: Replaced legacy infrastructure orchestration by building internal cloud platforms using Crossplane, exposing declarative Kubernetes-native APIs to development teams.

Custom Compositions: Authored highly reusable, enterprise-approved Crossplane Compositions (CompositeResourceDefinitions) to package complex multi-cloud resources (e.g., a secured Cloud SQL database paired with its IAM bindings and KMS keys) into a single claim.

Infrastructure State Synchronization: Leveraged Crossplane providers to continuously reconcile state between the live cloud infrastructure and Git, eliminating configuration drift across multi-cloud environments.

Provider Management: Experienced in configuring, upgrading, and managing the lifecycle of Crossplane providers (AWS, GCP, Azure) inside high-volume clusters.

Event-Driven Autoscaling with KEDA
Dynamic, Metric-Driven Scaling: Integrated KEDA (Kubernetes Event-driven Autoscaling) to scale microservices from zero to thousands of pods based on real-time event metrics rather than traditional CPU/Memory thresholds.

Multi-Scalar Integration: Authored production-grade scaling policies utilizing diverse KEDA scalers, tracking external metrics from Apache Kafka lag, RabbitMQ queues, Prometheus queries, and GCP Pub/Sub message counts.

Scale-To-Zero Cost Optimization: Engineered scale-to-zero configurations for asynchronous workers and AI ingestion agents, completely eliminating compute costs during idle periods.

HPA Coexistence: Masterfully managed the interplay between native Horizontal Pod Autoscalers (HPA) and KEDA, mitigating resource contention and tuning stabilization windows to prevent scaling oscillation.