BRS Consultant
Yangyang Wang
Tech Services
NEW
Job number: JN -082026-208727
Posted: 2026-08-19
GCP IAM Specialist
Lead GCP IAM governance and cloud security.
10 - 16 million yen
Tokyo
Information Technology
Cloud Engineer
Job details
- Company overview
- We are a global IT consulting and technology services firm that helps clients with their digital transformation. We provide services from strategy development to implementation and create innovative solutions for a wide range of industries. We help our clients gain a competitive edge by leveraging our expertise in areas such as data analytics, cloud technology, and cybersecurity. With a focus on sustainability and digital innovation, we provide solutions for business environments around the world.
- Responsibilities
-
A global IT consulting and technology services firm is seeking a highly skilled GCP IAM Specialist with strong cloud-native development expertise to design, implement, and govern identity and access management frameworks across our Google Cloud Platform estate.
This role is pivotal in ensuring secure, compliant, and scalable access controls while driving cloud-native application delivery.
■RESPONSIBILITIES- Design and enforce IAM policies, roles, and permission boundaries across GCP projects, folders, and organizations
- Develop and maintain custom IAM roles aligned to least-privilege principles across multi-project GCP environments
- Build and maintain cloud-native applications and automation tooling using GCP-native services (Cloud Run, Cloud Functions, Pub/Sub, GCS)
- Implement Workload Identity Federation and service account management best practices
- Integrate IAM controls with CI/CD pipelines and enforce policy-as-code using Terraform
- Conduct IAM access reviews, audit log analysis via Cloud Audit Logs and Security Command Center
- Collaborate with development and platform teams to embed security controls into cloud-native delivery
- Define and maintain organization-level IAM guardrails using VPC Service Controls and Access Context Manager
- Drive IAM automation using Ansible playbooks for configuration management and drift detection
- Provide technical guidance and IAM governance frameworks to delivery teams
━━━━━━━━━━━━━━━#spotlightjob3 - Requirements
-
■Required Qualifications- 5+ years of hands-on experience with GCP IAM, including custom roles and policy management
- Strong experience with GCP-native services such as Cloud Run, Cloud Functions, App Engine, and Pub/Sub
- Experience using Terraform for IAM policy provisioning and infrastructure-as-code
- Experience with Workload Identity, service accounts, and federated identity management
- Proficiency in Python or Go
- Experience with GCP Security Command Center, Cloud Audit Logs, and cloud compliance requirements
- Experience implementing VPC Service Controls and Organization Policies
- Knowledge of OAuth 2.0, OIDC, and SAML integration on GCP
■Preferred Qualifications- Google Professional Cloud Security Engineer certification
- Experience with Ansible for IAM configuration management
- Experience in regulated industries such as financial services or healthcare
- Experience with GKE Workload Identity and namespace-scoped IAM configurations
- Experience with SIEM integrations and security event automation pipelines
- Salary
- 10 - 16 million yen
- Location
- Tokyo