GCP Architect & Platform Engineering for San Francisco & the Bay Area based organizations

I’m Amit Malhotra, a Principal GCP Architect and founder of Buoyant Cloud. Bay Area startups move fast — and the GCP environment that got you from zero to MVP is rarely the architecture that survives your first enterprise customer, your SOC 2 audit, or your next 10x traffic spike. I work as a fractional cloud architect embedded in your engineering team, rebuilding that foundation while your team keeps shipping. Over 20 years of hands-on IT leadership. GCP only. No juniors. No hand-offs.

Scaling, compliance, and reliability start with the architecture underneath. Get the foundation right.

  • Ship SOC 2 readiness without re-architecting your entire GCP environment
  • Scale GKE and Cloud Run workloads from demo traffic to production load
  • Replace the infrastructure your first engineer built with a platform your whole team can operate.

You’re Here If…

  • Your GCP environment was built for speed, not durability — and now it’s showing. The architecture that shipped your MVP is buckling under production traffic, real security scrutiny, and a team that’s tripled in size since the first project was created.
  • You’re scaling past Cloud Run’s sweet spot — cold starts on critical API paths, concurrency limits during traffic spikes, and no clear framework for which workloads belong on Cloud Run versus GKE. The decision was made by whoever deployed first, not by an architect.
  • Your investor or board is asking about SOC 2 and your team is scrambling — not because the code is insecure, but because the GCP environment was never designed with audit controls, access boundaries, or evidence collection in mind.
  • GKE is your production runtime but it’s operationally fragile — node pool sizing is guesswork, autoscaling isn’t tuned, there’s no pod disruption budget, and the last scaling event took down a service because nobody understood the readiness probe configuration.
  • Your Terraform is a liability, not an asset — no module structure, no state locking strategy, no environment parity. Your engineers avoid touching infrastructure because the blast radius of a bad apply is unknown.
  • You’re building AI-native product features and need GCP platform expertise — Google ADK, Vertex AI Agent Engine, MCP server architecture — but your team’s strength is product engineering, not cloud infrastructure.

What I Do as a GCP Architect

Most GCP environments I audit weren’t architected — they were assembled. Someone spun up a project, created service accounts with Owner role, deployed to GKE from a laptop, and called it infrastructure. It worked at low traffic with a small team. Then the company grew, the enterprise deals started, and the security reviews exposed everything.

I work with Bay Area engineering teams on:

Cloud architecture and landing zone design. Organization hierarchy, folder structure, VPC networking with Private Google Access, IAM with least-privilege custom roles, and Terraform modules your team can maintain. Every foundation I build follows the SCALE Framework — Security by Design, Cloud-Native Architecture, Automation and IaC, Lifecycle Operations, and Elastic Scalability.

GKE platform engineering. Regional cluster topology, node pool design by workload profile, private cluster configuration, namespace isolation, RBAC, Network Policy enforcement, Istio service mesh, CI/CD with Cloud Build or ArgoCD, Binary Authorization, and observability with Cloud Monitoring and Cloud Trace. The full platform layer, implemented as code.

Cloud Run and serverless architecture. Concurrency tuning, min-instance configuration for cold start elimination, Pub/Sub and Eventarc integration, VPC connectors for private access, and the decision framework for when Cloud Run is the right call versus GKE — based on your actual workload patterns, not ideology.

DevSecOps and SOC 2 readiness. I implement my 6-Layer Security Model across your environment: identity and access, network security, data protection, application security, operations security, and compliance automation. VPC Service Controls, Security Command Center, secrets management with Secret Manager CSI Driver, and continuous compliance monitoring. I’ve taken GCP environments from zero security posture to SOC 2 audit-ready in 60–90 days.

Agentic AI and Google ADK. I design production-grade agentic AI systems on Google Cloud — multi-agent workflows using ADK’s sequential, parallel, and loop orchestration, custom MCP servers that expose your internal systems as structured tools, and deployment on Vertex AI Agent Engine or Cloud Run. The real IP in agentic AI isn’t the model — it’s the MCP servers that encode your domain logic and the orchestration patterns that make agents reliable in production.

Fractional or Full Engagement — Your Choice

Fractional GCP Architect. Part-time embedded architectural oversight — I own the GCP platform roadmap, review decisions, and unblock engineers without the cost or lead time of a full-time senior hire. A full-time principal cloud architect in San Francisco costs $280K–$400K. I deliver the same expertise at a fraction of that, with zero ramp-up.

Project engagement. Scoped deliverable — a landing zone build, GKE platform hardening, SOC 2 readiness, DevSecOps pipeline, or agentic AI architecture. Fixed scope, defined outcome, direct Principal Architect involvement throughout.

No sales layer, no junior engineers, no handoffs.

Why Bay Area Teams Work With Me

I work exclusively with North American clients and understand the compliance, security, and scaling requirements that Bay Area companies face — from seed-stage startups preparing for their first enterprise deal to mid-market companies under SOC 2, HIPAA, or PCI scrutiny.

Named clients include Tangerine Bank, Telus Health, Loblaws, RBC, and Ford.

I work with engineering teams in San Francisco, the Bay Area, and across North America — fintech, SaaS, healthtech, developer tools, and regulated workloads.

Book a Free GCP Architecture Review Explore GCP Architecture & Modernization Services

Book Your Architecture Review

If you’re a San Francisco CTO or engineering leader looking for a GCP architect who actually does the work—not one who sends juniors—let’s talk. Book a 30-minute architecture review and I’ll give you an honest assessment of where your GCP environment stands and what it needs.

Ready to Build a Platform That Scales Without the Tech Debt?

The SCALE framework gives your GCP platform a structured foundation — secure by design, automated by default, and built to grow with your business without accumulating technical debt.
Buoyant Cloud Inc
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.