All remote jobs

Cloud Governance Engineer

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

Remote from
Portugal
Salary
Undisclosed
Department
Cybersecurity
Employment
Full Time
Experience
Open level
Published
Apply before
5 Nov 2026
Listing views
31
Application actions
3
Application toolkit

Make your next move.

Prepare your resume, explore your fit, and draft a cover letter for this opportunity.

AI Summary

The role, at a glance.

Five9 seeks a Cloud Governance Engineer to define and enforce multi-cloud governance standards, with GCP representing the majority of the environment. The role focuses on policy-as-code, preventative guardrails, exception management, IAM and network-control governance, cloud cost accountability, and governance reporting rather than operating infrastructure. The engineer will partner closely with Security, Finance, IT, DevOps, Cloud Architects, and Product Engineering to translate technical risk into business decisions. Strong hands-on GCP experience, Terraform, Python automation, and demonstrated stakeholder communication are central requirements.

Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

Job Complexity

4/5
EasyHard

Pace & Pressure

4/5
RelaxedFast-paced

Autonomy Level

5/5
GuidedFull ownership

Communication Load

5/5
IndependentCollaborative
AI insightThis is a senior-leaning governance role requiring practical GCP guardrail implementation alongside knowledge of AWS and Azure control frameworks. Success depends on independently influencing technical and non-technical stakeholders, resolving policy fallout, and balancing security, operational, and cost trade-offs.

Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianMarket rate
$155,000
US market range$130k–$185k
AI insightNo actual salary is disclosed, so these are estimated US-market annual base-salary figures in USD for a Cloud Governance Engineer with 4+ years of public-cloud experience, strong GCP expertise, policy-as-code capability, and significant cross-functional responsibility. Actual compensation may differ materially based on location, level, bonus, and equity.

Core skills

Skills and capabilities most closely associated with this opportunity.

Sample interview questions
Describe a cloud policy or guardrail you rolled out that caused unexpected disruption. How did you address it?

I would explain the policy objective, affected services, and the pre-deployment testing performed. I would describe quickly identifying impacted teams, introducing a time-bound exception or phased enforcement path, remediating incompatible configurations, and documenting lessons to improve future rollout testing and stakeholder communication.

How would you implement and govern a GCP organization policy across a large multi-team environment?

I would start by defining the control objective and scope, mapping it to folders, projects, and service owners. I would test the constraint in a non-production hierarchy, assess exceptions and operational impact, deploy it progressively through infrastructure-as-code, and monitor violations, exceptions, and remediation time with dashboards.

How do you decide whether a requested waiver to a cloud control should be approved?

I would require a clear business justification, identify the specific risk introduced, assess compensating controls, define an accountable owner, and set a short expiry date. Approved waivers should be recorded centrally, reviewed periodically, and closed through remediation or a formally renewed decision.

How would you explain an overly permissive IAM finding to a non-technical product leader?

I would frame the issue in terms of business impact: excessive access increases the chance that an account error or compromise can expose customer data, disrupt service, or create compliance risk. I would present a practical least-privilege remediation plan, ownership, timeline, and any delivery trade-offs rather than focusing only on technical permissions.

What metrics would you use to measure the effectiveness of cloud governance?

I would track policy compliance rate, number and age of control violations, mean time to remediate, exception volume and expiry adherence, privileged-access coverage, key and credential rotation status, configuration drift, tagging completeness, cloud-cost anomalies, and commitment utilization. Metrics should be segmented by team and environment so owners can act on them.

This analysis is generated from the job description. Salary estimates, role characteristics and sample answers are guidance, not employer-provided facts.
Opportunity details

About this role.

Join us in bringing joy to customer experience. Five9 is a leading provider of cloud contact center software, bringing the power of cloud innovation to customers worldwide.

Living our values everyday results in our team-first culture and enables us to innovate, grow, and thrive while enjoying the journey together. We celebrate diversity and foster an inclusive environment, empowering our employees to be their authentic selves.

This is a governance role, not a build-and-operate role. You will spend your time defining the rules our cloud estate runs by, making those rules enforceable in code, and proving they are working. You will write standards that other engineering teams have to follow, and you will be the person who explains to Finance, Security, and Product leadership why a given risk matters and what it will cost to fix or ignore.

If what you want is to build and run infrastructure, this is not the right seat. If you want to own how a multi-cloud estate is governed, it is.

About our estate: roughly 70% Google Cloud, with AWS and Azure in scope as secondary platforms. GCP is where the majority of the work sits, so hands-on GCP experience is a hard requirement rather than a preference.

Key Responsibilities

  • Define, document, and maintain cloud governance policies and standards across GCP, AWS, and Azure, and turn them into enforceable technical controls using GCP Organization Policy, AWS SCPs and Config, and Azure Policy
  • Own the exception and waiver process end to end: intake, risk assessment, time-bound approval, expiry, and follow-up
  • Partner with Security to enforce Identity and Access Management and network security standards across the organization, and review access models for least privilege
  • Build and maintain dashboards that track governance metrics: security posture, key and credential rotation, policy violations, configuration drift, and time to remediation
  • Own resource labeling and tagging standards and enforce them, so that cost, ownership, and environment can be attributed reliably
  • Drive cost governance: spend visibility and showback, anomaly detection, commitment and discount coverage reviews, and surfacing waste to the teams that own it
  • Collaborate with IT, Finance, Security, DevOps, Cloud Architects, and Product Engineering to keep governance controls consistent across all environments, and translate technical risk into language those stakeholders can act on
  • Work with stakeholders to define service level objectives, key performance indicators, and metrics for operational efficiency
  • Support the review of new third-party cloud services before they enter the estate

Requirements

  • 4+ years working in public cloud environments, including at least 2 years hands-on with GCP
  • Hands-on experience implementing preventative guardrails in at least one hyperscaler (GCP Organization Policy, AWS SCPs or Config, Azure Policy). You should be able to walk us through a policy you rolled out, what it broke, and how you handled the fallout
  • Experience authoring a cloud policy or standard that other teams were required to follow, not only implementing one written elsewhere
  • Experience running or contributing to an exception or waiver process for cloud controls
  • Working knowledge of cloud IAM, network security, encryption, and key and secret management
  • Infrastructure-as-Code with Terraform, and comfort extending it to policy-as-code
  • Python for automation, enforcement, and reporting
  • Demonstrated ability to explain a technical risk to a non-technical audience and drive a decision. This is a core part of the job and we will test it during the interview process

Preferred Qualifications

  • Google Cloud Professional Cloud Security Engineer or Professional Cloud Architect certification
  • Policy-as-code tooling: OPA, Conftest, Sentinel
  • Cloud cost tooling: GCP billing exports and BigQuery, AWS Cost Explorer, or a third-party platform such as Cloudability or Apptio
  • Familiarity with the control frameworks our platform is audited against (SOC 2, HIPAA, GDPR). You will not own audits in this role, but context helps you prioritize
  • Kubernetes governance and policy enforcement
  • Okta integration, Microsoft Active Directory Federation Services
  • Bachelor’s degree in Computer Science, Engineering, or another relevant technical field
  • Result oriented, self-starter

Workplace location: This role is fully remote for candidates who reside outside Porto, Maia, Matosinhos, Gondomar, Valongo e Vila Nova de Gaia. Candidates who reside within those municipalities would be required to work in-office 3 days a week.

Benefits:

  • Five9 Equity Programs
  • Bonus Scheme
  • 10% Flex Benefit
  • Meal Allowance
  • Medical Insurance
  • Life Insurance
  • 25 day Annual Leave + Public Holidays

Five9 embraces diversity and is committed to building a team that represents a variety of backgrounds, perspectives, and skills.  The more inclusive we are, the better we are.  Five9 is an equal opportunity employer.

Five9 is committed to providing reasonable accommodations for qualified individuals with disabilities throughout the application and interview process. If you need assistance or an accommodation due to a disability, please contact us at accommodations@five9.com to request an accommodation. Requests will be handled confidentially and in accordance with applicable law.


View our privacy policy, including our privacy notice to California residents here: https://www.five9.com/pt-pt/legal.

Note: Five9 will never request that an applicant send money as a prerequisite for commencing employment with Five9.

Apply now >

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Did you apply?Let us know, and we’ll help you track your application.

Continue on the employer website

Protect your personal information and never pay to secure an interview or job offer. .

Log in to save
One quick step before you apply

Sign in to continue.

Sign in or create a free account to continue to the employer's application.

Applying is free. After signing in, return to this job and select Apply Now.
Add alert
Jobs Talent AI Tools Salaries
Menu