Below glcoud command can help shows how to extract roles assigned to Service account:
gcloud projects get-iam-policy <project_id> \
--flatten="bindings[].members" \
--format='table(bindings.role)' \
--filter="bindings.members:<project_numder>@cloudbuild.gserviceaccount.com"