Google Cloud Managed Instance Groups on Assured Workloads

Remote, USA Full-time
Title: Google Cloud Engineer – Windows Server MIG with Per-User VM Access (IAP + MFA) Description: We need help designing and implementing a secure, scalable Windows Server environment in Google Cloud Platform using Managed Instance Groups (MIGs). The goal: Each user gets their own Windows VM (1 user = 1 VM), accessed securely through Google Identity-Aware Proxy (IAP) with MFA. No Active Directory or Okta. Requirements: Build a golden Windows Server image with apps preinstalled (Adobe Reader, Office, browser). Configure a Managed Instance Group (MIG) to spin up VMs from this image. Implement a broker layer (Cloud Function/Run + Firestore or equivalent) that: Checks if a user already has a VM assigned. If not, provisions one, labels it with the user’s email, and grants them IAP access to that VM only. Ensure IAP is the only way to RDP into these VMs. On VM startup, a script should create a local Windows account matching the assigned user and generate a secure password (stored in Google Secret Manager). Optional: Implement cleanup logic to reclaim idle VMs. Provide documentation and handoff so we can manage and scale the system after delivery. Skills Needed: Google Cloud Platform (Compute Engine, MIGs, IAM, IAP, Cloud Functions/Run, Firestore, Secret Manager) Windows Server image building (sysprep, startup scripts, hardening) PowerShell scripting for automated account creation Security best practices (MFA, least privilege, CIS Level 1 baseline a plus) Deliverables: Working environment where each user automatically gets their own VM. IAP enforced with MFA for all access. Automated local account creation and credential management. Written runbook or video walkthrough for ongoing ops. ✅ Screening Questions You can paste these in the job posting to filter applicants: Have you built or managed a Managed Instance Group (MIG) in GCP before? How would you control per-instance IAM permissions so that only one user can access a VM through IAP? What approach would you use to automate Windows local account creation on boot? Do you have experience with Firestore or other lightweight state stores for tracking resources? What security baselines (CIS, Microsoft baselines) have you applied to Windows Server images? Can you provide an example of GCP automation you’ve built (Terraform, scripts, Cloud Functions)? Apply tot his job
Apply Now

Similar Jobs

Google Cloud Trainer Conversational AI & CCAI Specialist

Remote, USA Full-time

Google Cloud Solution Architect

Remote, USA Full-time

Strategic Architect, Google Cloud

Remote, USA Full-time

Google Cloud Platform DevOps Engineer

Remote, USA Full-time

Senior Google Cloud Engineer O&M Lead

Remote, USA Full-time

Google Cloud data engineer - Contract to Hire

Remote, USA Full-time

Fully Remote Medical Coder- Must Have CCS Cert

Remote, USA Full-time

Google Cloud Engineer -SME | Req#3966

Remote, USA Full-time

Workspace Sales Specialist Manager III, Google Cloud

Remote, USA Full-time

AI Phone Survey System – Hungarian Language (Google Gemini + Google Cloud) - Contract to Hire

Remote, USA Full-time

Experienced Remote Data Entry Specialist for Teens – Flexible Work from Home Opportunity with arenaflex

Remote, USA Full-time

Cyber security engineer - Contract to Hire

Remote, USA Full-time

[Remote] Senior Business Analyst / Business Architect, INOW

Remote, USA Full-time

Experienced Full Stack Sales Agent – Shipping Container Sales & Customer Engagement on Facebook Marketplace

Remote, USA Full-time

Senior Director, Business Development

Remote, USA Full-time

**Experienced Data Entry Clerk (Remote) – High-Speed Data Processing and Confidential Information Management**

Remote, USA Full-time

Senior Software Engineer, Payments/Fintech

Remote, USA Full-time

**Experienced Remote Customer Service Specialist – Delivering Exceptional Experiences at blithequark**

Remote, USA Full-time

Google Jobs In Austin, Texas $25/Hour

Remote, USA Full-time

Pharmacy Technician - Remote, FL (Federal Employees Program)

Remote, USA Full-time
Back to Home