Data Engineer
Job Description
This remote Data Engineer role with Hollstadt Consulting supports the Enterprise Interfaces team as they operationalize the Globus Managed File Transfer platform in the GCP Cloud Data DMZ. The engagement focuses on final platform configuration, initial user onboarding, ongoing operational support, documentation, and compliance alignment, with an expected duration of 6 to 12 months (extension possible).
Role Summary
You will embed with the Enterprise Interfaces team as the primary technical resource for completing Globus operationalization. Work includes configuring the Globus Connect Server (GCS) environment on GCP Compute Engine VMs, setting up endpoints and storage connectivity for ingress and egress workflows, enabling authentication and access controls through Entra ID, and establishing repeatable operational processes for long-term team self-sufficiency.
The Globus platform is nearing completion of initial implementation and is being installed in the GCP Cloud Data DMZ. The Enterprise Interfaces team will serve as the operational home for Globus alongside existing MFT solutions (Signiant and Cleo).
Key Responsibilities
- Complete final configuration and hardening of the Globus Connect Server (GCS v5) deployment on GCP Compute Engine VMs within the Data DMZ
- Configure and validate Globus Storage Gateways and S3 Storage Connectors for GCP bucket ingress and egress
- Configure Managed and Guest Globus collections in alignment with the client’s data access policies and identity provider restrictions
- Validate end-to-end transfer workflows, including ingress, egress, and staging collection transfers across the Service Connector (SC) boundary into the MCC VPC
- Set up DNS, authentication flows using OAuth/OpenID Connect via Entra ID, and endpoint registration within Globus.org
- Onboard initial research user groups and provide hands-on support for first transfers
- Develop and document standardized onboarding procedures, including Sailpoint provisioning workflows and Globus Web App access
- Provide Tier 1/2 operational support for Globus users, including troubleshooting transfer failures, stalled transfers, permission issues, connectivity problems, and performance optimization
- Coordinate with Globus vendor support (University of Chicago) for escalated issues using the established Globus support process
- Monitor and maintain Globus Connect Server VM health, GCS services, and GCP bucket lifecycle policies
- Manage Globus endpoint configurations, including storage gateways, identity provider settings, path restrictions, and access policies
- Perform ongoing performance tuning, optimizing GridFTP concurrency, parallelism, data channel configuration, and transfer parameters for high-throughput workloads
- Monitor transfer activity, usage patterns, and audit logs for operational and compliance reporting
- Manage GCS software updates, patches, and version upgrades
- Support disaster recovery planning and testing for the Globus platform
- Implement and enforce security controls aligned with ISA, BAA, and NIST frameworks
- Manage identity provider configurations and access controls (RBAC) within the Globus platform
- Ensure data governance policies are enforced, including collection-level permissions, path restrictions, and transfer audit logging
- Support TPRM and Risk/OIS requirements as they relate to Globus operations
- Create comprehensive technical documentation, including runbooks, SOPs, architecture diagrams, troubleshooting guides, and operational playbooks
- Participate in the Globus Orientation Session led by Pete Eby from the Architecture team and translate session content into operational procedures
- Transfer knowledge to internal Enterprise Interfaces staff to enable long-term self-sufficiency
- Document lessons learned from initial onboarding and operational support activities
- Navigate internal governance, change management, and approval processes for platform changes
- Collaborate with the Architecture team, Storage/Infrastructure team, and Research stakeholders
- Coordinate with ADO repo owners for configuration and state management
- Provide input into long-term MFT operations planning and AI-operations integration
Required Qualifications
- 3+ years hands-on experience with the Globus platform, including Globus Connect Server v5 deployment, configuration, and administration
- Deep understanding of the Globus ecosystem, including endpoints, collections (managed and guest), storage gateways, storage connectors (S3, POSIX), and the Globus Web App
- Experience with GridFTP protocol tuning, including concurrency, parallelism, data channel configuration, and performance optimization for large-scale transfers
- Familiarity with Globus Auth, including OAuth 2.0 / OpenID Connect integration, federated identity management, and identity provider configuration
- Experience with Globus Flows for workflow automation and scheduled or recurring transfer operations
- Experience with Globus CLI and Globus Python SDK for scripting and automation
- Familiarity with Globus vendor support engagement processes
- Hands-on experience with GCP Compute Engine (VM provisioning, management, and maintenance)
- Experience with GCP Cloud Storage (S3-compatible buckets, lifecycle policies, IAM, service accounts)
- Understanding of GCP networking, including VPCs, firewall rules, DNS, ingress/egress controls, and DMZ architecture
- Experience with GCP IAM, service accounts, and RBAC
- Strong Linux administration skills (Globus Connect Server runs on Linux VMs)
- Proficiency with Bash for shell scripting, system monitoring, log analysis, and troubleshooting
- Experience with package management, service configuration, and security hardening on Linux
- Understanding of network protocols: TCP/IP, HTTPS, GridFTP, and DNS
- Experience configuring firewall rules for high-port-range protocols (TCP 50000–51000)
- Familiarity with Zero-Trust security principles and DMZ architecture patterns
- Understanding of HIPAA compliance as it applies to data transfer and PHI handling in healthcare environments
- Broad understanding of Managed File Transfer principles, including secure transfer protocols, audit logging, compliance, and data governance
- Experience supporting large-scale data transfers (terabyte- to petabyte-scale) in research, academic, or healthcare environments
- Bachelor’s degree in Computer Science or Engineering from an accredited University or College, or an Associate’s degree with two (2) years of experience
- Self-directed problem solver, strong communicator, and ability to enable internal team ownership through operational runbooks and training materials
- Customer-oriented approach to troubleshooting with research users, plus governance-aware navigation of change management and security review requirements
Technologies
- Globus
- Globus Connect Server (GCS) v5
- Globus Storage Gateways
- Globus Storage Connectors (S3, POSIX)
- Globus Web App
- GridFTP
- OAuth 2.0, OpenID Connect
- Globus Flows
- Globus CLI, Globus Python SDK
- Google Cloud Platform (GCP), GCP Compute Engine, Google Cloud Storage (S3-compatible buckets)
- GCP IAM, RBAC, VPC, DNS
- Entra ID, Sailpoint, Azure DevOps (ADO), Terraform
- Linux, Bash, TCP/IP, HTTPS
Compensation and Engagement Details
- Job type: Contract
- Location: Minnesota (remote)
- Duration: 6 to 12 months (extension possible)
- Pay rate: USD 52.51/hour W2
Benefits
- Comprehensive Benefit Plan (medical, dental, vision, life insurance, short-term disability, long-term disability, paid sick leave, retirement benefits)
- 401(k) matching on the first 4% of contributions
- Bonus opportunities, including Longevity Award bonus and a $1,000 referral bonus for placed referrals
- Professional development via on-demand training through the consultant portal and an AI upskilling hub
- Ongoing support and networking through a Consultant Coach program