Work Type: Hybrid (3 days) Experience Level: 5-9 Years Top 3 Required Skills: 1. Cloud Network Engineer 2. Terraform Knowledge 3. CI/CD pipeline Job Description: Design, implement, secure, and operate cloud networking (VPC/VNet, hybrid connectivity, routing, firewalls, private access, load balancing) with a strong focus on Infrastructure as Code (IaC) using Terraform. Ensure high availability, compliance, observability, and cost efficiency across environments (Dev → Prod). ________________________________________ Core Responsibilities 1) Cloud Network Architecture & Design • Design VPC/VNet topologies: CIDR planning, subnets, route tables, NAT/IGW/ER/Direct Connect, DNS (public/private). • Define hybrid connectivity: Site to Site VPN, ExpressRoute/Direct Connect, Transit architectures, SD WAN integration. • Architect resilient and secure network paths (multi AZ/region, hub and spoke, segmentation/micro segmentation). • Produce HLD/LLD, network diagrams, decision logs, and reference patterns aligned to enterprise standards. 2) Implementation & Configuration (Azure / AWS) • Build and configure: o Azure: VNets, Subnets, NSGs, UDRs, Azure Firewall, Application Gateway/WAF, Private Endpoints, Route Server. o AWS: VPCs, Subnets, Route Tables, IGW/NAT, Security Groups/NACLs, ALB/NLB, Transit Gateway, PrivateLink. o (GCP as applicable: VPCs, firewall rules, Cloud Router, Cloud NAT, load balancing) • Implement DNS (Azure DNS/Route 53/Cloud DNS), IPAM hygiene, and name resolution across hybrid. 3) Security & Compliance by Design • Enforce least privilege and network segmentation, zero trust patterns, and WAF/DDoS protections. • Implement private access patterns (Private Link/Private Endpoints/Service Endpoints) to avoid public exposure. • Partner with security/GRC for threat modeling, control mapping, evidence collection, and remediation. 4) Operations, Monitoring & Troubleshooting • Enable observability: VPC Flow Logs / NSG Flow Logs, Network Watcher, CloudWatch/CloudTrail, Log Analytics; build dashboards and alerts. • Troubleshoot latency, packet loss, asymmetric routing, MTU/MSS, and TLS/WAF issues. • Participate in incident, problem, and change management with clear runbooks and post incident reviews. 5) Infrastructure as Code (Terraform First) • Author and maintain Terraform modules for reusable network patterns (VPC/VNet, TGW, firewalls, private endpoints). • Implement environment promotion via workspaces or pipelines; parameterize with tfvars. • Enforce state management (remote backend, state locking), versioning, code reviews, and policy as code (Sentinel/OPA). • Integrate Terraform in CI/CD pipelines (Azure DevOps/GitHub Actions/GitLab/Jenkins) with plan/apply gates and approvals. |