Associate Security ConsultantDesigning an overall network architecture. Considerations include: high availability, failover, and disaster recovery strategies; DNS strategy (e.g., on premises, Cloud DNS); security and data exfiltration requirements; load balancing; applying quotas per project and per VPC; hybrid connectivity (e.g., Google private access for hybrid connectivity); container networking; IAM roles; SaaS, PaaS, and IaaS services; microsegmentation for security purposes (e.g., using metadata, tags, service accounts).Designing Virtual Private Cloud (VPC) instances. Considerations include: IP address management and bring your own IP (BYOIP); standalone vs. shared VPC; multiple vs. single; regional vs.
multi regional; VPC Network Peering; firewalls (e.g., service account based, tag based); custom routes; using managed services (e.g., Cloud SQL, Memorystore); third party device insertion (NGFW) into VPC using multi NIC and internal load balancer as a next hop or equal cost multi path (ECMP) routes.Designing a hybrid and multi cloud network. Considerations include: dedicated interconnect vs. partner interconnect; multi cloud connectivity; direct peering; IPsec VPN; failover and disaster recovery strategy; regional vs. global VPC routing mode; accessing multiple VPCs from on premises locations (e.g., Shared VPC, multi VPC peering topologies); bandwidth and constraints provided by hybrid connectivity solutions; accessing Google Services/APIs privately from on premises locations; IP address management across on premises locations and cloud; DNS peering and forwarding.Designing an IP addressing plan for Google Kubernetes Engine. Considerations include: public and private cluster nodes; control plane public vs.
private endpoints; subnets and alias IPs; RFC 1918, non RFC 1918, and privately used public IP (PUPI) address options.Configuring VPCs. Considerations include: Google Cloud VPC resources (e.g., networks, subnets, firewall rules); VPC Network Peering; creating a shared VPC network and sharing subnets with other projects; configuring API access to Google services (e.g., Private Google Access, public interfaces); expanding VPC subnet ranges after creation.Configuring routing. Considerations include: static vs. dynamic routing; global vs. regional dynamic routing; routing policies using tags and priority; internal load balancer as a next hop; custom route import/export over VPC Network Peering.Configuring and maintaining Google Kubernetes Engine clusters.
Considerations include: VPC native clusters using alias IPs; clusters with Shared VPC; creating Kubernetes Network Policies; private clusters and private control plane endpoints; adding authorized networks for cluster control plane endpoints.Configuring and managing firewall rules. Considerations include: target network tags and service accounts; rule priority; network protocols; ingress and egress rules; firewall rule logging; firewall insights; hierarchical firewalls.Implementing VPC Service Controls. Considerations include: creating and configuring access levels and service perimeters; VPC accessible services; perimeter bridges; audit logging; dry run mode.Configuring load balancing. Considerations include: backend services and network endpoint groups (NEGs); firewall rules to allow traffic and health checks to backend services; health checks for backend services and target instance groups; configuring backends and backend services with balancing method (e.g., RPS, CPU, Custom), session affinity, and capacity scaling/scaler; TCP and SSL proxy load balancers.
Associate Security Consultant MAHIN-JOB-33097 in plano at Unknown Company
This position is listed as full time and hybrid.