Figured it out:

I need to create this tunnel using the gcloud tool:

$ gcloud compute start-iap-tunnel <instance name> 22 --project=<project name> --zone=us-west1-b --verbosity=warning --local-host-port=localhost:3333
Testing if tunnel connection works.
Listening on port [3333].

Then in SecureCRT I connect to localhost:3333 with the right name and cert et voila... :-)
