Design or audit GCP identity, access, and security posture — Cloud IAM (allow + deny policies, conditions), Workload Identity Federation for non-GCP CI, Workload Identity for GKE, Secret Manager, Cloud KMS (CMEK + EKM), Security Command Center, BeyondCorp Enterprise, Binary Authorization, Org Policies. Use when writing IAM bindings, configuring Workload Identity, rotating secrets, scoping service accounts, or hardening an organization.