Data Engineer
Job Description
Hollstadt Consulting is staffing a remote Data Engineer contract to embed with the Enterprise Interfaces team and finish operationalizing the Globus Managed File Transfer platform in the GCP Cloud Data DMZ. The engagement runs for 6 to 12 months, with extension possible, and focuses on configuration, onboarding, operations, documentation, and alignment with security and compliance expectations.
This role supports a Globus platform that is installed in a GCP Data DMZ and nearing completion of initial implementation. Enterprise Interfaces will serve as the operational home for Globus alongside existing MFT solutions (Signiant and Cleo), with you acting as the primary technical resource for building long-term institutional knowledge.
What you will do
- Complete final configuration and hardening of the Globus Connect Server (GCS) v5 deployment on GCP Compute Engine VMs within the Data DMZ
- Configure and validate Globus Storage Gateways and Globus Storage Connectors (ingress and egress) for GCP bucket access
- Configure Globus collections (Managed and Guest) according to client data access policies and identity provider restrictions
- Validate end-to-end transfer workflows spanning ingress, egress, and staging collection transfers across the Service Connector (SC) boundary into the MCC VPC
- Set up DNS, authentication flows (OAuth/OpenID Connect via Entra ID), and endpoint registration in Globus.org
- Onboard initial research user groups with hands-on support for first transfers
- Develop and document standardized onboarding procedures, including Sailpoint provisioning workflows and Globus Web App access
- Provide Tier 1/2 operational support for Globus users, including troubleshooting transfer failures, stalled transfers, permission issues, connectivity problems, and performance optimization
- Coordinate with Globus vendor support (University of Chicago) for escalated issues using the established Globus support process
- Monitor and maintain GCS VM health, GCS services, and GCP bucket lifecycle policies
- Manage Globus endpoint configurations including storage gateways, identity provider settings, path restrictions, and access policies
- Perform ongoing performance tuning, optimizing GridFTP concurrency, parallelism, data channel settings, and transfer parameters for high-throughput workloads
- Monitor transfer activity, usage patterns, and audit logs for operational and compliance reporting
- Manage GCS software updates, patches, and version upgrades
- Support disaster recovery planning and testing for the Globus platform
- Implement and enforce security controls aligned with ISA, BAA, and NIST frameworks
- Manage identity provider configurations and RBAC within the Globus platform
- Ensure data governance policies are enforced, including collection permissions, path restrictions, and transfer audit logging
- Support TPRM and Risk/OIS requirements related to Globus operations
- Create comprehensive documentation, including runbooks, SOPs, architecture diagrams, troubleshooting guides, and operational playbooks
- Attend the Globus Orientation Session led by Pete Eby from the Architecture team and translate session content into operational procedures
- Transfer knowledge to Enterprise Interfaces staff to enable long-term self-sufficiency and document lessons learned from onboarding and support activities
- Navigate internal governance, change management, and approval processes for platform changes
- Collaborate with the Architecture team, Storage/Infrastructure team, and Research stakeholders
- Coordinate with ADO repo owners for configuration and state management
- Provide input into long-term MFT operations planning and AI-operations integration
Required experience
- 3+ years hands-on experience with the Globus platform, including Globus Connect Server v5 deployment, configuration, and administration
- Deep understanding of the Globus ecosystem: endpoints, collections (managed and guest), storage gateways, storage connectors (S3, POSIX), and the Globus Web App
- GridFTP protocol experience, including concurrency, parallelism, data channel tuning, and performance optimization for large-scale transfers
- Experience with Globus Auth: OAuth 2.0 / OpenID Connect integration, federated identity management, and identity provider configuration
- Experience with Globus Flows for workflow automation and scheduled/recurring transfer operations
- Experience with Globus CLI and the Globus Python SDK for scripting and automation
- Familiarity with Globus vendor support engagement processes
- Hands-on experience with GCP Compute Engine (VM provisioning, management, and maintenance)
- Experience with GCP Cloud Storage (S3-compatible buckets, lifecycle policies, IAM, service accounts)
- Understanding of GCP networking: VPCs, firewall rules, DNS, ingress/egress controls, and DMZ architecture
- Experience with GCP IAM, service accounts, and RBAC
- Strong Linux administration skills for Linux-based GCS operations
- Proficiency with shell scripting (Bash), system monitoring, log analysis, and troubleshooting
- Experience with package management, service configuration, and security hardening on Linux
- Understanding of network protocols: TCP/IP, HTTPS, GridFTP, DNS
- Experience configuring firewall rules for high-port-range protocols (TCP 50000–51000)
- Familiarity with Zero-Trust security principles and DMZ architecture patterns
- Understanding of HIPAA compliance as it applies to data transfer and PHI handling in healthcare environments
- Broad understanding of Managed File Transfer principles, including secure transfer protocols, audit logging, compliance, and data governance
- Experience supporting large-scale data transfers (terabyte- to petabyte-scale) in research, academic, or healthcare environments
- Bachelor’s degree in Computer Science or Engineering from an accredited University or College
- OR Associate’s degree in Computer Science or Engineering from an accredited University or College with two (2) years of experience
- Self-directed problem solving and strong communication skills for technical and research audiences
- Experience enabling others through runbooks and training materials
- Customer-oriented approach with comfort troubleshooting with research users
- Governance awareness for change management, approvals, and security review requirements
- Proactive approach to anticipating operational needs and proposing improvements
Technologies you will work with
- Globus, Globus Connect Server (GCS) v5, Globus Storage Gateways, Globus Storage Connectors (S3, POSIX), Globus Web App
- GridFTP
- OAuth 2.0, OpenID Connect
- Globus Flows, Globus CLI, Globus Python SDK
- Google Cloud Platform (GCP), GCP Compute Engine, Google Cloud Storage (S3-compatible buckets), S3
- GCP IAM, RBAC, VPC, DNS
- Entra ID, Sailpoint
- Azure DevOps (ADO), Terraform
- Linux, Bash, TCP/IP, HTTPS
Location, type, and pay
- Location: Minnesota (remote)
- Job type: Contract
- Duration: 6-12 months (extension possible)
- Rate: $52.51/hour W2
- Salary range listed: USD 52 - 52 per hourly
Benefits
- Comprehensive Benefit Plan (medical, dental, vision, life insurance, short-term disability, long-term disability, paid sick leave, retirement benefits)
- 401(k) + matching on the first 4% of contributions
- Bonus Opportunities (Longevity Award bonus; $1,000 referral bonus for placed referrals)
- Professional Development (on-demand training through consultant portal; AI upskilling hub)
- Ongoing Support & Networking (Consultant Coach program)
- Remarketing Process