Permissions
The GCP CIS v2.0.0 - Section 1 - Identity and Access Management policy pack requires 6 permissions:
apikeys.keys.delete
cloudkms.cryptoKeys.setIamPolicy
dataproc.clusters.delete
iam.serviceAccountKeys.delete
iam.serviceAccounts.delete
resourcemanager.projects.setIamPolicy