GXO is a leading provider of cutting-edge supply chain solutions to the most successful companies in the world. We help our customers manage their goods most efficiently using our technology and services. Our greatest strength is our global team – energetic, innovative people of all experience levels and talents who make GXO a great place to work.
Principal Cloud AI Platform Architect
Location
United States
Posted
7 days ago
Salary
0
Seniority
Lead
Job Description
Principal Cloud AI Platform Architect
GXO Logistics
Role Description Are you ready to take your career to the next level with a rapidly growing global company? As the Principal Cloud AI Platform Architect, Google Cloud, you will serve as GXO's principal authority for Google Cloud architecture, platform engineering, and enterprise cloud design. This role provides hands-on technical leadership across Google Cloud Platform (GCP), establishing architectural standards, engineering best practices, and secure-by-default cloud foundations that enable enterprise-scale innovation. If you're looking for an opportunity to shape the future of cloud architecture and enterprise AI at a global scale, join us at GXO. What you'll do on a typical day - Provide principal-level architecture leadership for GXO's Google Cloud environment, including landing zones, organization policies, networking, identity, security, and platform design. - Design and evolve enterprise Google Cloud foundations including folder and project hierarchy, Shared VPC, Private Service Connect, Identity-Aware Proxy (IAP), Workload Identity Federation, Secret Manager, Cloud KMS/CMEK, and Cloud Logging and Monitoring. - Lead architecture for Google Kubernetes Engine (GKE), including networking, ingress/egress, autoscaling, security, observability, production operations, and deployment standards. - Establish enterprise platform engineering standards through Terraform modules, GitOps, CI/CD pipelines, DevSecOps controls, policy-as-code, and paved-road developer experiences. - Develop and maintain enterprise reference architectures, architectural decision records (ADRs), technical standards, and cloud design patterns. - Partner with Information Security to implement zero-trust architecture, identity federation, least privilege access, encryption, secrets management, audit logging, and secure-by-default cloud operations. - Define enterprise observability and FinOps standards including cost attribution, budgeting, service level objectives (SLOs), tracing, monitoring, and operational excellence. - Lead the Google Cloud architecture for GXO's Enterprise AI Platform, including Gemini Enterprise Agent Platform, LiteLLM, Agent Gateway, MCP, Agent Registry, ADK, and governed Snowflake integrations. - Partner with Data Engineering, Security, and Product Architecture to design secure, scalable, model-agnostic AI inference, agent runtimes, identity passthrough, tool execution, and end-to-end traceability. - Contribute to future AI platform capabilities including model tiering, open-source model serving on GKE, and evolving enterprise AI architecture. - Serve as the principal Google Cloud architect supporting additional enterprise workloads including analytics, application modernization, integration, and data platforms. - Evaluate emerging Google Cloud technologies and strategic partner offerings for enterprise adoption. - Conduct architecture reviews, design governance, technical mentorship, and executive-level technology recommendations. - Collaborate with enterprise, infrastructure, security, and data architects to establish consistent cloud architecture standards across GXO. - Provide hands-on technical leadership by writing Terraform, reviewing IAM policies, troubleshooting GKE networking, and partnering directly with engineering teams. Qualifications - Bachelor's degree in Computer Science, Information Technology, Engineering, or a related technical field, or equivalent work experience. - Google Cloud Professional Cloud Architect certification. - 12–15+ years of experience in cloud architecture, enterprise architecture, distributed systems, or platform engineering. - 7+ years of hands-on experience designing and operating enterprise-scale Google Cloud environments. - Deep expertise in Google Cloud architecture including landing zones, organization policies, IAM, Workload Identity Federation, networking, Shared VPC, Private Service Connect, VPC Service Controls, Cloud KMS/CMEK, IAP, logging, monitoring, and secure cloud operations. - Extensive experience designing and operating production Google Kubernetes Engine (GKE) platforms. - Strong experience implementing Infrastructure as Code using Terraform, GitOps, CI/CD pipelines, and policy-as-code frameworks. - Demonstrated expertise implementing zero-trust cloud security, identity federation, least privilege access, encryption, secrets management, audit logging, and governance. - Experience designing enterprise observability and FinOps capabilities including monitoring, tracing, cost management, budgeting, and operational maturity. - Experience designing enterprise AI or LLM platforms utilizing Vertex AI, Gemini Enterprise Agent Platform, LiteLLM, MCP, AI gateways, agent runtimes, or comparable technologies. - Excellent analytical skills with the ability to translate complex business requirements into scalable enterprise architectures. - Strong written communication skills with experience producing executive-ready architecture documentation, standards, design reviews, and technical recommendations. - Exceptional communication and collaboration skills with the ability to engage engineering teams, executive leadership, technology partners, and security organizations. - Proven ability to prioritize competing initiatives while balancing architecture strategy, hands-on engineering, and stakeholder engagement. - Ability to operate effectively with minimal supervision in a fast-paced, global enterprise environment. Requirements - It'd be great if you also have: - Google Cloud Professional Security Engineer certification. - Google Cloud Professional DevOps Engineer certification. - Google Cloud Professional Machine Learning Engineer certification. - Certified Kubernetes Administrator (CKA) or Certified Kubernetes Application Developer (CKAD). - HashiCorp Terraform Associate certification. - Experience integrating Google Cloud workloads with Snowflake using OAuth, RBAC, masking policies, row-level security, and governed data access. - Experience designing secure multi-tenant enterprise platforms on Google Cloud. - Experience evaluating emerging AI, cloud, and platform technologies for enterprise adoption. - Demonstrated success collaborating within enterprise architecture organizations while contributing to shared standards and technical governance. - Experience mentoring architects and engineers while elevating enterprise architecture practices across large organizations. Benefits - We are eager to attract the best, so we offer competitive compensation and a generous benefits package, including: - Full health insurance (medical, dental and vision) - 401(k) - Life insurance - Disability - And more. Company Description GXO is a leading provider of cutting-edge supply chain solutions to the most successful companies in the world. We help our customers manage their goods most efficiently using our technology and services. Our greatest strength is our global team – energetic, innovative people of all experience levels and talents who make GXO a great place to work. We are proud to be an Equal Opportunity employer including Disabled/Veterans. GXO adheres to CDC, OSHA and state and local requirements regarding COVID safety. All employees and visitors are expected to comply with GXO policies which are in place to safeguard our employees and customers. All applicants who receive a conditional offer of employment may be required to take and pass a pre-employment drug test. The above statements are intended to describe the general nature and level of work being performed by people assigned to this classification. They are not intended to be construed as an exhaustive list of all responsibilities, duties and skills required of personnel so classified. All employees may be required to perform duties outside of their normal responsibilities from time to time, as needed.
Related Guides
Related Categories
Related Job Pages
More Cloud Engineer Jobs
• Lead cloud architecture and design • Define and implement scalable, secure Azure solutions • Own end-to-end delivery and translate business requirements into technical solutions • Design and maintain IaC modules using Terraform • Implement CI/CD pipelines and promote automation culture • Ensure compliance with security and governance frameworks • Architect for performance, reliability, and cost optimization • Mentor junior and mid-level engineers and drive technical direction
API/Microservices/AWS Software Engineer
AAAProud to serve our 62+ million members, help travelers see the world and drive real change to improve road safety.
• The API/Microservices/AWS Software Engineer designs and builds scalable, cloud-based microservices on AWS, using Java and modern DevOps practices. • You’ll partner with architects and teams to deliver reliable, high-performing APIs and services in a fast-paced, Agile environment. • Be involved in designing and building services in a continuous delivery model on a cloud platform. • Partner with leads and architects to help establish a technical vision and deliver innovative services which are consistent, maintainable, and highly scalable for various commerce experiences. • Work within microservices architecture, domain driven design, and RESTful APIs using Java. • Work in a distributed/cloud-based environment, including Amazon Web Services & Kubernetes with high transaction volumes. • Use data structures, algorithms, and architecture patterns. • Define solutions, provide estimates on effort and risk, and evaluate technical feasibility. • Use modern build strategies, continuous integration, unit testing, static analysis, and automated integration tests. • Practice full DevOps to ensure a culture of testing and releasing software on Amazon Web Services continuously using automation and monitoring. • Leverage NoSQL using Amazon Web Services to ensure data storage is designed for security, reliability, availability, maintainability, and performance. • Deliver software in a Scrum development process. • Perform technical code reviews and pair programming. • Partner with other teams to ensure the service ecosystem is loosely coupled and scalable.
• Own CrowdStrike Falcon configuration, ensuring policies are appropriately scoped, tuned, and generating actionable alerts. • Partner with MDR to define alert routing, triage thresholds, and escalation logic. • Monitor cloud environments (primarily AWS) for security posture drift. • Secure Kubernetes clusters and containerized workloads. • Develop and enforce cloud security policies and standards for AWS infrastructure. • Evaluate and lead the implementation of additional detection tooling. • Manage infrastructure as code (IaC) security using Terraform or OpenTofu. • Automate security posture checks and detection workflows using Python and shell scripting. • Stay current with the evolving cloud threat landscape.
• Own CrowdStrike Falcon configuration, ensuring policies are appropriately scoped, tuned, and generating actionable alerts. • Partner with MDR to define alert routing, triage thresholds, and escalation logic, ensuring the right signals reach the right team. • Monitor cloud environments (primarily AWS) for security posture drift: misconfigured IAM roles, overly permissive security groups, exposed storage, and non-compliant resource configurations. • Secure Kubernetes clusters and containerized workloads: manage Network Policies, RBAC, Admission Controllers, and runtime detection for anomalous container behavior. • Develop and enforce cloud security policies and standards for AWS infrastructure, ensuring secure and scalable deployments align with organizational risk posture. • Evaluate and lead the implementation of additional detection tooling, including cloud SIEM platforms, designing detection rules and alerting pipelines. • Manage infrastructure as code (IaC) security using Terraform or OpenTofu — ensuring IaC definitions meet security standards before deployment. • Automate security posture checks and detection workflows using Python and shell scripting. • Stay current with the evolving cloud threat landscape and translate emerging threats into detection coverage or posture improvements.


