Senior Principal Engineer, Infrastructure Lead
Bridge Analytics is seeking a senior, security-minded infrastructure leader to own the cloud foundation of the Bridge Analytics Environment (BAE) — a Trusted Research Environment on Google Cloud Platform that gives the world’s leading neuroscientists secure, fully-audited access to harmonized, multi-modal data with native compute. In this role, you will own the infrastructure, reliability, and security perimeter that let BAE scale to 500+ external researchers at public launch and across a growing multi-study portfolio advancing science and therapeutics for Parkinson’s disease, autism, and bipolar disorder.
This is a senior individual-contributor role. You set the technical direction and build hands-on, backed by contractor and consultant resources for implementation, operations, and help desk — so you multiply your impact without building or managing a large team. You will operate in a fast-scaling, security-first environment where the perimeter is non-negotiable and everything must be reproducible and auditable. We are looking for a true owner who can codify a live platform into infrastructure-as-code and set the reliability and security bar for the whole environment.
Key Responsibilities
- SDLC & Delivery Backbone: Establish parity dev, test, and production environments with CI/CD (Cloud Build, GitHub Actions) on our infrastructure-as-code (CDKTF/Terraform for Python), deploying reliably across GCP projects for both internal data operations and external researchers.
- Reliability & Operations: Define SLOs/SLIs and build the observability, alerting, incident response, and runbooks for live researcher workloads — with a light on-call rotation supported by contractor resources — and retire single points of failure so the platform is dependable at 500+ users.
- Security & Perimeter Ownership: Own and harden the security perimeter — VPC Service Controls, Assured Workloads, organization policy, and least-privilege IAM — along with the exfiltration posture (full and controlled exfiltration prevention, geo-blocking) and forensic audit logging that keep a regulated TRE demonstrably safe.
- Identity & Access: Automate the access and permissions lifecycle — group-based RBAC and provisioning via Cloud Identity and OIDC federation — to replace manual work and scale researcher onboarding through beta and launch.
- Scaling the Portfolio: Templatize per-project GCP provisioning so every new study in a growing multi-study portfolio lands in an isolated, properly-configured project instead of bespoke setup each time.
- Direct Contractor & Consultant Support: Set direction for the contractor and consultant resources that help with implementation, operations, and help desk — reviewing for quality and security and ensuring every change lands in our repos and runbooks — and partner with IT and Compliance on HIPAA/GDPR-aligned controls.
Who You Are
- You have deep, hands-on experience building and operating production cloud at scale, and the seniority to set the technical bar for an entire platform — not just a single service.
- You thrive as a hands-on individual contributor — you would rather set direction and build than manage a large team, and you know how to get leverage from contractor and consultant resources.
- You treat security as non-negotiable and can own a regulated perimeter end-to-end, from VPC Service Controls and IAM to DLP and complete audit logging.
- You are a force multiplier: you turn tribal knowledge into infrastructure-as-code and runbooks, and you direct contractor and consultant resources rather than carrying every ticket yourself.
- You don’t wait to be told what to do; you proactively anticipate failure modes and retire single points of failure before they become incidents.
- You are eager to adopt and integrate modern AI tools into your daily workflow to multiply your impact — this is an AI-native team.
- You care about the mission and want your work in researchers’ hands in weeks, not years.
Qualifications
Minimum Qualifications:
- Experience: 10+ years in infrastructure, platform, or Site Reliability Engineering roles, operating production cloud at scale.
- Google Cloud Platform: Deep, hands-on GCP expertise — IAM, networking, organization policy, GKE, Cloud Run, and Composer in production.
- Infrastructure-as-Code: Expert with Terraform in production (CDKTF and strong Python a major plus); fluent with CI/CD and containers.
- Cloud Security: Proven ownership of a security perimeter at scale — identity and least-privilege (IAM, VPC Service Controls, org policy), DLP/exfiltration control, and audit logging.
- Regulated Environments: Experience operating regulated or security-sensitive environments (HIPAA, HITRUST, GxP, or equivalent).
- Leadership Through Influence: Track record of directing contractor or consultant resources and raising operational resilience without a large direct team.
Preferred Qualifications:
- Data & Compute: Cloud Composer/Airflow, Dataplex, and BigQuery security; Cloud Batch/GKE for scientific compute; FinOps.
- Regulated Research Platforms: Trusted Research Environments or HIPAA/GDPR-regulated data platforms; policy-as-code (OPA/Rego); the GA4GH ecosystem; confidential computing.
- Tech Adaptability: Enthusiasm for integrating AI tools into daily engineering workflows to optimize efficiency.
Senior Principal Engineer, Infrastructure Lead in south san francisco at Unknown Company
This position is listed as contract and onsite.