Senior Software Engineer II

American Express

Bengaluru

Hybrid

INR 4,000,000 - 7,000,000

Full time

6 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Competitive base salaries
Bonus incentives
Flexible hybrid/onsite/remote work

Job summary

American Express in Bengaluru seeks a Senior Multi-Cloud Network Engineer to design, build, secure, automate, and operate enterprise-scale cloud network fabrics across AWS and GCP. You will architect multi-account/multi-project environments with hybrid connectivity and strong security controls.

You will lead design decisions, implement network segmentation, routing, DNS, and observability, and drive automation using IaC and modern tooling.

Qualifications

  • 10-12+ years in network engineering with public cloud experience.
  • Extensive hands-on AWS and GCP networking design experience.
  • Strong knowledge of TCP/IP, BGP, DNS, NAT, routing, VPN, firewalls, and segmentation.

Responsibilities

  • Design, build, and operate enterprise-scale cloud network fabrics across AWS and GCP.
  • Automate network infrastructure and implement observability.
  • Lead architecture reviews and provide guidance to cross-functional teams.

Skills

Cloud networking
AWS networking
GCP networking
BGP/DNS/NAT
IaC Terraform
Hybrid connectivity
Troubleshooting
Security by design
Observability
Technical leadership

Tools

Terraform
CloudFormation/CDK
Cloud Infra tooling

Job description

Job Description:

Enterprise Cloud under Global Infrastructure is seeking a highly experienced Senior Multi-Cloud Network Engineer to design, build, secure, automate, and operate enterprise-scale cloud network fabrics across Amazon Web Services (AWS) and Google Cloud Platform (GCP).

Responsibilities

The ideal candidate will have deep hands-on experience building complex cloud network architectures across both AWS and GCP, including multi-account/multi-project environments, hybrid connectivity, inter-cloud connectivity, network segmentation, routing, DNS, traffic inspection, and centralized security controls. This role requires strong foundational networking expertise combined with practical knowledge of how AWS and GCP implement networking differently.

The successful candidate will design cloud networks that are secure by design, highly available, scalable, observable, automated, and resilient, applying least privilege, Zero Trust, defense-in-depth, segmentation, and policy-driven infrastructure principles.

What Success Looks Like

  • Design and build enterprise-grade AWS and GCP network fabrics from the ground up.
  • Design networking based on sound engineering principles rather than simply connecting cloud resources.
  • Explain end-to-end packet flows across AWS, GCP, on-premises, and security infrastructure.
  • Design scalable routing and segmentation models across hundreds of cloud accounts/projects and VPCs.
  • Build highly resilient hybrid and multi-cloud connectivity architectures.
  • Implement secure network boundaries without unnecessary operational complexity.
  • Make informed decisions between native AWS, native GCP, and third-party networking capabilities.
  • Automate network infrastructure, build comprehensive observability, and diagnose complex problems at both the architecture and packet level.
  • Balance security, resiliency, scalability, performance, operability, and cost in architecture decisions.

Multi-Cloud Network Architecture & Engineering

  • Design, build, and operate enterprise-scale cloud network fabrics across AWS and GCP.
  • Develop architectures supporting multiple AWS accounts, GCP projects, business units, application environments, regions, and hybrid data centers.
  • Define standardized multi-cloud connectivity patterns covering cloud-to-cloud, cloud-to-data-center, application-to-application, internet ingress/egress, east-west traffic, shared services, private service connectivity, and centralized traffic inspection.
  • Design scalable routing, segmentation, IP addressing, DNS, and connectivity strategies across AWS and GCP.
  • Develop multi-region architectures with appropriate availability, redundancy, failover, route convergence, and disaster recovery characteristics.
  • Evaluate architecture trade-offs across cloud-native networking services based on security, scalability, performance, resiliency, operational complexity, and cost.

AWS Network Fabric

  • Design and engineer AWS networking using Amazon VPC, Transit Gateway, Cloud WAN, Direct Connect, Site-to-Site VPN, Transit Gateway Connect, VPC Peering, PrivateLink/VPC Endpoints, Network Firewall, Firewall Manager, Route 53/Resolver, DNS Firewall, Elastic Load Balancing, Global Accelerator, VPC IPAM, and flow logs.
  • Design network architectures for complex multi-account and multi-region AWS environments, including centralized and distributed connectivity and security models.

GCP Network Fabric

  • Design and engineer GCP networking using Google Cloud VPC, Shared VPC, VPC Network Peering, Network Connectivity Center (NCC), Cloud Router, Cloud Interconnect, Partner Interconnect, HA VPN, Private Service Connect, Private Google Access, Cloud NAT, Cloud DNS, Cloud Load Balancing, Cloud Armor, Firewall Policies, Network Intelligence Center, and VPC Flow Logs.
  • Design network architectures supporting multi-project, multi-region, and Shared VPC environments, with appropriate separation between host projects, service projects, shared services, security controls, and application workloads.

Hybrid & Inter-Cloud Connectivity

  • Design highly available connectivity between AWS, GCP, enterprise data centers, colocation facilities, and third-party environments.
  • Design and operate architectures utilizing AWS Direct Connect and Google Cloud Interconnect.
  • Engineer resilient BGP-based routing across cloud and on-premises environments and VPN-based connectivity for primary, secondary, and contingency use cases.
  • Develop secure connectivity patterns between AWS and GCP while avoiding unnecessary internet exposure.
  • Understand and mitigate asymmetric routing, overlapping IP space, route propagation, route preference, MTU, NAT, DNS, and stateful security-device challenges.
  • Develop routing strategies that prevent unintended transit paths and connectivity between security zones, with clear failure domains and predictable failover behavior.

Cloud Network Security

  • Design cloud network architectures using security-by-design and Zero Trust principles.
  • Implement segmentation based on application, environment, business function, data classification, and trust boundaries.
  • Design centralized and distributed firewall architectures and secure ingress, egress, east-west, and inter-cloud traffic patterns.
  • Implement appropriate traffic inspection and security enforcement points; apply least-privilege connectivity and minimize unnecessary network reachability.
  • Design private access patterns using AWS PrivateLink/VPC Endpoints, GCP Private Service Connect, and Private Google Access.
  • Implement controls using AWS Security Groups, NACLs, Network Firewall; GCP VPC Firewall Rules/Policies, Cloud Armor; DNS security controls; and third-party NGFW technologies where appropriate.
  • Partner with cybersecurity teams to translate security standards into enforceable cloud network controls.
  • Identify excessive connectivity, unintended routing paths, insecure internet exposure, and weaknesses in segmentation or firewall policies.
  • Incorporate logging, monitoring, detection, and auditability into network architecture from the outset.

Routing, DNS & IP Address Management

  • Demonstrate expert-level understanding of TCP/IP, IPv4/IPv6, BGP, DNS, NAT, CIDR/subnetting, route summarization, route propagation, route preference, ECMP, and stateful/stateless filtering.
  • Develop enterprise-scale IP Address Management (IPAM) strategies spanning AWS, GCP, and on-premises environments.
  • Prevent and remediate overlapping address-space issues across cloud environments.
  • Design hybrid DNS architectures spanning AWS Route 53, GCP Cloud DNS, and enterprise DNS infrastructure.
  • Understand provider-specific routing behavior and diagnose complex routing issues across cloud boundaries.

Infrastructure as Code & Automation

  • Build and manage cloud networking using Infrastructure as Code (IaC) rather than manual configuration.
  • Develop reusable networking modules and patterns using Terraform, AWS CloudFormation/CDK, Google Cloud Infrastructure Manager or equivalent tooling, Python, and Ansible.
  • Integrate network infrastructure deployments into CI/CD pipelines and implement automated validation, testing, compliance, and policy enforcement.
  • Develop guardrails to prevent insecure or non-standard network configurations.
  • Promote repeatable, version-controlled, auditable deployments and automate routine network operations, configuration validation, route analysis, and compliance checks.

Network Observability & Troubleshooting

  • Establish comprehensive network observability across AWS and GCP using VPC/TGW Flow Logs, CloudWatch, Reachability Analyzer, Network Manager, GCP VPC Flow Logs, Cloud Logging/Monitoring, Network Intelligence Center, and Connectivity Tests.
  • Diagnose complex connectivity problems across cloud, hybrid, and inter-cloud environments.
  • Perform end-to-end packet-flow analysis through routing, NAT, firewalls, load balancers, private endpoints, VPNs, and hybrid connectivity.
  • Troubleshoot BGP advertisements, route propagation, asymmetric routing, DNS resolution, MTU issues, firewall policies, and application connectivity.
  • Lead root-cause analysis for major cloud networking incidents and implement permanent corrective actions.

Technical Leadership

  • Serve as a senior technical authority for cloud networking across AWS and GCP.
  • Develop cloud network reference architectures, engineering standards, design patterns, and guardrails.
  • Conduct architecture and design reviews for new cloud connectivity requirements.
  • Provide technical guidance to application, platform, SRE, infrastructure, and cybersecurity teams.
  • Challenge architecture proposals where network complexity, security exposure, scalability, or operational risk is unnecessary.
  • Mentor engineers and translate complex networking concepts into clear architectural decisions for technical and non-technical stakeholders.
Qualifications

Required Qualifications

  • Significant professional experience (10-12+ YOE) in network engineering, including substantial hands-on experience with public cloud networking.
  • Demonstrated experience designing and implementing enterprise-scale AWS and GCP network architectures.
  • Deep practical knowledge (7-8+ YOE) of TCP/IP, BGP, DNS, NAT, routing, VPN, firewalls, load balancing, and network segmentation.
  • Strong hands-on AWS experience (4-5+ YOE) with VPC, Transit Gateway, Direct Connect, PrivateLink, Route 53, VPN, and AWS Network Firewall.
  • Strong hands-on GCP experience (4-5+ YOE) with VPC, Shared VPC, Network Connectivity Center, Cloud Router, Cloud Interconnect, HA VPN, Private Service Connect, Cloud DNS, and Firewall Policies.
  • Experience designing hybrid connectivity between public cloud environments and enterprise data centers, and secure connectivity between cloud providers.
  • Strong understanding of cloud network security architecture, segmentation, firewalling, traffic inspection, private connectivity, and secure ingress/egress patterns.
  • Strong Infrastructure as Code experience (3-4+ YOE), preferably using Terraform, with CI/CD and automated deployment practices.
  • Advanced troubleshooting skills with the ability to trace application traffic across multiple network and security layers.
  • Ability to communicate complex cloud network architecture to engineers, architects, cybersecurity teams, and senior technology stakeholders.

Preferred Qualifications

  • Experience building large-scale AWS multi-account environments and GCP multi-project/Shared VPC environments.
  • Experience with AWS Transit Gateway, AWS Cloud WAN, and GCP Network Connectivity Center at enterprise scale.
  • Experience integrating AWS Direct Connect and Google Cloud Interconnect with enterprise WAN environments.
  • Experience designing multi-cloud connectivity using SD-WAN or cloud networking platforms.
  • Experience with Palo Alto Networks, Fortinet, Cisco, Check Point, Aviatrix, or equivalent technologies.
  • Experience with enterprise IPAM/DNS platforms and regulated, security-sensitive, or compliance-driven cloud environments.
  • Familiarity with Zero Trust, NIST, CIS Benchmarks, AWS Well-Architected Framework, and Google Cloud Architecture Framework.
  • Relevant certifications such as AWS Certified Advanced Networking - Specialty, AWS Solutions Architect - Professional, Google Cloud Professional Cloud Network Engineer, Google Cloud Professional Cloud Architect, AWS Security - Specialty, CCNP/CCIE, or CISSP are advantageous.

At American Express, our culture is built on a 175-year history of innovation, shared valuesand Leadership Behaviors, and an unwavering commitment to back our customers, communities, and colleagues. From delivering differentiated products to providing world-class customer service, we operate with a strong risk mindset, ensuring we continue to uphold our brand promise of trust, security, and service.

As part of Team Amex, you’ll experience our powerful backing with comprehensive support for your holistic well-being and many opportunities to learn new skills, develop as a leader, and grow your career. Here, your voice and ideas matter, your work makes an impact, and together, you will help us define the future of American Express.

We back you with benefits that support your holistic well-being so you can be and deliver your best. This means caring for you and your loved ones physical, financial, and mental health, as well as providing the flexibility you need to thrive personally and professionally:

  • Competitive base salaries
  • Bonus incentives
  • Support for financial-well-being and retirement
  • Comprehensive medical, dental, vision, life insurance, and disability benefits (depending on location)
  • Flexible working model with hybrid, onsite or virtual arrangements depending on role and business need
  • Generous paid parental leave policies (depending on your location)
  • Free access to global on-site wellness centers staffed with nurses and doctors (depending on location)Free and confidential counseling support through our Healthy Minds program
  • Career development and training opportunities

American Express is an equal opportunity employer and makes employment decisions without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran status, disability status, age, or any other status protected by law.

Offer of employment with American Express is conditioned upon the successful completion of a background verification check, subject to applicable laws and regulations.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Software Engineer II
Senior Software Engineer II

American Express • Gurgaon

Hybrid
INR 3,500,000 - 6,500,000
Competitive base salaries
Bonus incentives
Medical, dental, vision, life & 24
+2
Senior Software Engineer II
Senior Software Engineer II

American Express • Gurugram District

On-site
INR 4,000,000 - 7,000,000
Competitive base salaries
Bonus incentives
Flexible working model
Engineer I- Openshift Engineer
Engineer I- Openshift Engineer

American Express Services Europe Limited • Bengaluru Urban

Hybrid
INR 1,200,000 - 1,600,000
Flexible working model
Generous paid parental leave
Comprehensive medical and dental benefits
+1
Staff Engineer
Staff Engineer

American Express Services Europe Limited • Bengaluru Urban

Hybrid
INR 1,600,000 - 2,000,000
Comprehensive medical and dental benefits
Flexible working model
Career development opportunities
Engineer I
Engineer I

American Express • Chennai

Hybrid
INR 600,000 - 1,200,000
Competitive base salaries
Bonus incentives
Comprehensive medical, dental, vision, life insurance
+5
Software Engineer II
Software Engineer II

American Express • Bengaluru

Hybrid
INR 1,500,000 - 2,500,000
Competitive base salaries
Bonus incentives
Flexible hybrid/onsite/virtual work
Site Reliability Engineer II
Site Reliability Engineer II

American Express • Chennai District

On-site
INR 1,800,000 - 3,200,000
Competitive base salary
Bonus incentives
Health and wellness benefits
+2
Senior Software Engineer II - Full Stack Web Application
Senior Software Engineer II - Full Stack Web Application

American Express • Chennai District

On-site
INR 3,500,000 - 7,000,000
Competitive salary
Bonus incentives
Healthcare benefits
+5
Engineer - Java Full Stack Developer
Engineer - Java Full Stack Developer

American Express Services Europe Limited • Gurugram District

Hybrid
INR 1,000,000 - 1,500,000
Comprehensive medical, dental, vision insurance
Flexible working model
Career development opportunities
+1
American Express – Director – Control Management – Regulatory Reporting
American Express – Director – Control Management – Regulatory Reporting

American Express • Gurugram District

Hybrid
INR 2,000,000 - 3,000,000
Competitive base salaries
Bonus incentives
Comprehensive medical, dental, vision benefits
+2