Role Overview
Serves as the lead network architect for transition from a VPC Peering hub-and-spoke topology to a Google Cloud Network Connectivity Center (NCC) fabric.
Oversees the planning, execution, and delivery of the network-focused NCC program, ensuring alignment with business goals, timelines, and budget.
Owns the NCC target-state design across hub/spoke fabric, hybrid connectivity (including Cross-Cloud Interconnect to Azure), IPAM, routing, and DMZ insertion delivering a scalable, self-service connectivity model that removes VPC Peering scaling limits while preserving existing security inspection and egress controls.
Key Responsibilities
- Lead discovery workshops and requirements gathering with network and application stakeholders.
- Own current-state analysis VPC Peering limits, Cross-Cloud Interconnect VLANs, DMZ / Palo Alto egress, IPAM, and routing exceptions.
- Assess cross-cloud interconnects to Azure, Azure coordination requirements, and BGP routing validation; evaluate the DNS roadmap and integration.
- Assess compatibility of the current-state environment with NCC prerequisites, dependencies, and readiness criteria.
- Design the target NCC architecture: hub/spoke fabric, hybrid connectivity, IPAM, routing, DMZ insertion, and extensibility.
- Prepare and deliver NCC education workshop(s) for teams.
- Author the Technical Design Document (HLD/LLD) and drive design reviews, iteration, and architecture sign-off with.
- Engage Google product/engineering on platform limits and roadmap.
- Provide architectural direction into Terraform IaC module structure, the migration Method of Procedure (MOP), pilot, and production cutover wave sequencing.
- Guide high-risk central events Hub VPC + CCI/Azure cutover and DMZ / Palo Alto egress cutover and the legacy VPC Peering decommission.
- Ensure the delivered model is self-service, preserves existing security inspection and egress controls, and stays aligned to scope, timeline, and budget.
Primary Deliverables
- Current-state analysis findings.
- Target NCC architecture design (hub/spoke fabric, hybrid connectivity, IPAM, routing, DMZ insertion).
- Technical Design Document (HLD/LLD).
- NCC education workshop materials.
- Cutover program / wave plan and per-BU readiness (jointly with the engineering team).
Required Qualifications
- Extensive network architecture experience with deep, hands-on Google Cloud networking.
- Proven design of large-scale Google Cloud Platform network topologies Shared VPC, VPC Peering, and hub-and-spoke fabrics and migration toward Network Connectivity Center (NCC).
- Strong command of hybrid connectivity: Cloud Interconnect / Cross-Cloud Interconnect (to Azure), Cloud Router, and BGP routing.
- Expertise in IPAM, routing design, DNS, and DMZ / egress-inspection architectures (e.g., Palo Alto).
- Ability to author HLD/LLD design documentation and lead design reviews through to architecture sign-off.
- Experience planning wave-based production cutovers and rollback strategies for high-risk network changes.
- Excellent stakeholder-management, workshop-facilitation, and communication skills.
Preferred Qualifications
- Google Cloud Professional Cloud Network Engineer and/or Professional Cloud Architect certification.
- Direct experience implementing NCC (hub, spokes, route tables, hybrid attachments).
- Terraform / Infrastructure-as-Code fluency for network automation.
- Multi-cloud networking (Google Cloud Platform Azure) and enterprise egress / security-inspection design.
- Experience in large, regulated, enterprise-scale (e.g., retail) environments.
Core Technology Environment
Google Cloud networking Network Connectivity Center (NCC), Shared VPC, VPC Peering, Cloud Router, Cloud Interconnect / Cross-Cloud Interconnect to Azure, BGP, IPAM, and Cloud DNS; DMZ / Palo Alto egress inspection; hub-and-spoke and hybrid-connectivity fabrics; and Terraform / Infrastructure-as-Code for network automation.