This is the stage where the screen's second round genuinely plays out, the final gate standing before an
interview reaches your inbox. A recruiter eases up here, and despite that, your present
role alone still steers about 95% of the result.
That holds up: nothing proves what you can ship to production right now better than the chair you occupy
today. To pull a "yes", the section has to land every entry on the
GCP Engineer role profile, one bullet for each domain you flagged in Domain
Expertise above. And each bullet has to come out of something you genuinely owned in production,
never a ticket that happened to drift into your queue.
1
Cloud Architecture & Landing Zones
The flagship work of the role. Show the landing zone you designed, the account topology under
it, and the workloads the architecture now carries. Name the design and what it enabled, not
"worked on cloud architecture".
Techniques
Multi-account topology
Hub-and-spoke
Architecture Framework reviews
Tenant isolation
Tools
Resource Manager, folders
Organization policies
Resource Manager, folders
Metrics
Accounts brought online
Teams onboarded
Time-to-account cut
2
Networking & Connectivity
The plumbing that ties the cloud estate together. Show the VPC topology you built, the
transit and edge layer (NCC, peering, Cloud DNS, Cloud CDN), and the connectivity model into
on-prem. Name the design and the workloads it carries, not "set up networking".
Techniques
VPC / subnet design
Transit & peering
DNS & CDN
Cloud Interconnect / VPN
Tools
Network Connectivity Center, Cloud DNS
CloudFront / Cloud CDN
Cloud Interconnect
Metrics
Network SLA
Latency cut
Egress cost down
3
Identity & Security
Who can do what, across the whole estate. Show the IAM model you authored, the SSO and
permission-set design, the secrets strategy, and the guardrails that block risky changes at
the org boundary. Name the policy you put in place, not "managed identity".
Techniques
SSO & SCIM
Permission sets / least privilege
SCPs / Org policies
Secrets & Cloud KMS
Tools
Cloud Identity, Okta
Cloud KMS, Secret Manager
Security Command Center
Metrics
Findings closed
Privileged access reduced
Audits passed
4
Compute & Cloud-Native Services
The services every product team consumes. Show the compute stack you stood up (GCE, GKE,
Cloud Run, Cloud Functions), the data plane (Cloud SQL, Spanner) and messaging (Pub/Sub,
Eventarc). Name the service and the workload it carries, not "deployed on GCP".
Techniques
Compute selection
Serverless patterns
Event-driven architecture
Reference patterns
Tools
GCE, GKE, Cloud Run
Cloud SQL, Spanner, Firestore
Pub/Sub, Eventarc
Metrics
Workloads onboarded
Service uptime
Latency held
5
Storage, Data & Databases
How the estate stores and protects data. Show the storage tiers you designed (GCS lifecycles,
Persistent Disk types), the database choices behind each workload, and the backup and replication
strategy. Name the dataset and the policy behind it, not "ran some databases".
Techniques
GCS lifecycle & tiering
Backup & PITR
Cross-region replication
Encryption at rest
Tools
GCS, Persistent Disk, Filestore
Cloud SQL, Spanner, BigQuery
Backup and DR
Metrics
RPO / RTO
Storage cost cut
Backups restored under test
6
Cost Optimization & FinOps
Where GCP Engineering meets the business. Show the FinOps program you set up, the
chargeback model, the rightsizing campaign, and the savings plans or RIs you tuned. Name the
spend you cut and how, not "optimized cloud costs".
Techniques
Tagging & chargeback
Rightsizing
Savings Plans / RIs
Anomaly detection
Tools
Billing export, BigQuery
Recommender, Active Assist
Budgets & alerts
Metrics
Annual spend cut
Tag coverage
Unit cost held
7
Reliability, DR & Compliance
The discipline that keeps the cloud estate trusted by the business. Show the DR posture you
designed (multi-AZ, multi-region), the compliance framework you ran the estate through (SOC
2, ISO, HIPAA, PCI), and the audits you closed. Name the incident or audit and what it shifted, not
"handled compliance".
Techniques
Multi-AZ / multi-region
DR playbooks
Audit evidence pipelines
Compliance frameworks
Tools
Org Policy, Cloud Audit Logs
Drata, Vanta
Security Command Center
Metrics
Audits passed
RPO / RTO held
Findings closed
8
Tooling & Workflow
The setup that lets one GCP Engineer carry a multi-project estate. Show the IaC modules
you authored, the review patterns that catch a bad VPC change at PR time, and the docs that
cut onboarding ramp. Name the workflow, not "a modern stack".
Techniques
Reusable IaC modules
Plan-based PR review
Policy as code
Self-serve docs
Tools
Terraform, Atlantis
Git, GitHub
OPA / Conftest, Checkov
Metrics
Modules maintained
PR cycle time
Onboarding ramp cut