Mateusz Wójcik Senior GCP Engineer
Warsaw, Poland • gcpeng@gmail.com • +48 22 555 0184
Profile Summary
- Senior GCP Engineer with 8 years of experience running GCP production environments at marketplace scale across online marketplaces, payments, and consumer commerce platforms, specializing in Well-Architected reviews, GKE Autopilot with Cloud Run, and Terraform-driven landing zones.
- Hands-on coverage across compute (GKE Autopilot with Cloud Run), IaC (Terraform with Config Connector), CI/CD (Cloud Build with Cloud Deploy), observability (Cloud Monitoring with Cloud Logging), and data (BigQuery with Pub/Sub and Dataflow), with networking grounded in Shared VPC with VPC Service Controls and Cloud Armor and certified on Professional Cloud Architect.
- Deep expertise in Well-Architected reviews across all five pillars, multi-project landing zones with org policies and folders, event-driven integration with Pub/Sub and Eventarc, and FinOps tagging and CUDs and Spot VMs optimization, applying methodologies such as GitOps-style Terraform modules with environment-scoped pipelines and least-privilege IAM with Workload Identity Federation to deliver secure, cost-aware GCP estates that hold up under ISO 27001 and customer load.
- Engaged collaborator working cross-functionally with Platform, Security, SRE, Data, and Finance teams in multi-project, review-heavy cloud platform teams, contributing to architecture review boards, on-call rotations, and cost-review forums with an ownership-first mindset and clean handoffs.
- Mentor who shares technical excellence and fosters a culture of secure, well-tagged GCP infrastructure and cost-aware, Well-Architected practice through PR reviews and module docs, while running the internal GCP guild and architecture review board and authoring widely used Terraform module and landing-zone templates.
Technical Skills
- Compute & Containers:
- GKE Autopilot with Cloud Run, Compute Engine, managed instance groups, Cloud Run, Cloud Functions 2nd gen, GKE Standard, App Engine, Cloud Batch, GPU and TPU nodes
- Networking & Edge:
- Shared VPC with VPC Service Controls and Cloud Armor, VPC networks, subnets, Cloud NAT, VPC Peering, Private Service Connect, Cloud Interconnect, Cloud VPN, Cloud Load Balancing, Cloud CDN, Cloud DNS, firewall rules
- Identity, Security & Compliance:
- Cloud IAM, service accounts, Workload Identity Federation, Organization Policies, Cloud KMS, Secret Manager, Security Command Center, VPC Service Controls, SOC 2, HIPAA, PCI DSS, ISO 27001, FedRAMP
- Storage & Database:
- Cloud Storage with lifecycle and storage classes, Persistent Disk, Filestore, Cloud SQL (Postgres, MySQL, SQL Server), AlloyDB, Spanner, Firestore, Bigtable, Memorystore for Redis, BigQuery, cross-region replication
- Infrastructure as Code:
- Terraform with Config Connector, Pulumi, Infrastructure Manager, Deployment Manager, Terraform modules, remote state on Cloud Storage, environment-scoped pipelines, plan previews
- CI/CD & Automation:
- Cloud Build with Cloud Deploy, Artifact Registry, GitHub Actions with Workload Identity Federation, GitLab CI, Jenkins, OS Config, Cloud Scheduler, Cloud Tasks, Workflows
- Data, ML & Integration:
- BigQuery with Pub/Sub and Dataflow, Pub/Sub, Eventarc, Cloud Tasks, Workflows, Dataflow (Apache Beam), Dataproc, Vertex AI, BigQuery ML, Gemini API, Document AI
- Observability, Cost & FinOps:
- Cloud Monitoring with Cloud Logging, Cloud Trace, Cloud Profiler, Error Reporting, Datadog, Grafana, OpenTelemetry, Cost Explorer, Budgets, Recommender, CUDs, Spot VMs
- Certifications & Frameworks:
- Professional Cloud Architect, Professional Cloud DevOps Engineer, Professional Data Engineer, Professional Cloud Security Engineer, Google Cloud Architecture Framework, multi-project landing zones, org policies, FinOps tagging
Education
Work Experience
- Owned GCP architecture and solution design end to end on the marketplace platform on Google Cloud serving 22M active buyers, shipping GKE workloads, Spanner fleets, and Pub/Sub mesh across 120 GCP projects reviewed against all five Well-Architected pillars.
- Ran core compute and containers on GKE Autopilot with horizontal pod autoscaling, Cloud Run for stateless edges, and Functions 2nd gen on burst paths, blue/green rollouts on App Engine for legacy add-ons, and Cloud Batch for fan-out across 210 production workloads, pulling Cloud Run cold-start from 1.8s down to 180ms on the checkout path.
- Owned GCP networking with Shared VPC with VPC Service Controls perimeters, Cloud Armor, and global HTTP(S) Load Balancing, tightened firewall rules on every spoke, layered Cloud CDN and Cloud DNS on the customer edge, and routed 42 VPCs through Private Service Connect and Cloud NAT, cutting egress cost by 61% in the first two quarters.
- Hardened identity, security, and compliance with Cloud IAM with Workload Identity Federation, Cloud KMS, Secret Manager, and Security Command Center Premium, service-account keys retired on every workload, Organization Policies bound to folders, and VPC Service Controls perimeters tuned to the platform, dropping critical findings by 78% and clearing ISO 27001 controls at a 100% pass rate across the last two audit windows.
- Designed storage and database services around Spanner multi-region with Cloud SQL for Postgres, BigQuery for analytics, and Cloud Storage with lifecycle tiering, Filestore for shared workspace state, Memorystore for Redis on hot paths, AlloyDB for high-throughput transactional reads, and Cloud Storage cross-region replication for DR across a 14PB estate, cutting Spanner p99 query latency on the checkout path by 62%.
- Drove infrastructure as code with Terraform modules in a monorepo, Config Connector for Kubernetes-native GCP, and plan previews on every PR, Pulumi for app constructs, Infrastructure Manager for managed rollouts, and policy gates with Checkov on every PR, authoring 58 modules and dropping new-project provisioning from 3 days to 35 minutes.
- Ran CI/CD, DevOps, and automation through Cloud Build with Cloud Deploy progressive rollouts, Artifact Registry for container and language packages, and GitHub Actions on app repos, drift detection on every Terraform plan, and chat-ops runbooks for break-glass scenarios, holding 420 deploys per week across the estate at a 1.4% change failure rate.
- Built serverless and event-driven pipelines with Pub/Sub topics with Cloud Run subscribers, Eventarc for change capture, and Dataflow for streaming ingest, Cloud Tasks for retries, Workflows for orchestration, and Cloud Scheduler for cron, lifting event throughput from 9k/s to 85k/s across a fleet of 320 Cloud Run services.
- Owned observability and cost management with Cloud Monitoring dashboards with Cloud Logging sinks, Cloud Trace on hot paths, and Recommender for rightsizing, Cloud Profiler on the heaviest services, anomaly alerts wired to PagerDuty, and Budgets with forecast-based alerting on every cycle, pulling incident MTTD from 22 min down to 3 min and cutting monthly GCP spend by 34% without slowing release pace.
- Built out the data and ML platform on BigQuery as the warehouse with Dataflow batch and streaming, Dataproc for Spark jobs, and Vertex AI for serving, BigQuery ML for in-warehouse models, Document AI for ingestion, and Gemini API for assistive features, putting 42 Vertex AI models into production and speeding up the top BigQuery dashboards by 3.6x.
- Stood up multi-project governance through Org policies with folders and project factories, Cloud Asset Inventory for drift, and FinOps tagging, chargeback dashboards for every product team, and landing-zone blueprints for new business units, onboarding 48 net-new GCP projects under a single audit-ready posture.