1755 - Azure Network Engineer

Sigma Defense

Roma

In loco

EUR 95.000 - 132.000

Tempo pieno

8 giorni fa
Generatore di candidature

Non inviare un curriculum generico — genera un curriculum e una lettera di presentazione personalizzati per questo specifico impiego.

Supera i filtri ATS

Vantaggi offerti da questo lavoro

Dental and Vision Insurance
Medical Insurance with HSA/FSA/DFSA
Life and AD&D coverage
401(k) with company match
PTO

Descrizione del lavoro

Sigma Defense seeks an Azure Network Engineer to lead complex connectivity across Microsoft Azure environments, with a focus on secure design and policy enforcement. The role demands deep Azure networking expertise, firewall specialization, and DoD/compliant practices.

The candidate will design and manage VNets, subnets, NSGs, and UDRs, while configuring Azure Firewall, Private Link, and ExpressRoute to ensure secure, scalable connectivity across multiple Azure environments and external networks.

Competenze

  • 5+ years of relevant experience.
  • Professional experience designing, implementing, and supporting Microsoft Azure networking environments.
  • Strong understanding of TCP/IP, routing, subnetting, DNS, NAT, VPNs, firewalls, and network segmentation.
  • Hands-on experience configuring and troubleshooting Azure Firewall and Palo Alto Firewall.
  • Experience designing and managing Azure VNets, subnets, NSGs, route tables, and UDRs.
  • Experience implementing connectivity between multiple Azure VNets and environments.
  • Understanding of hub-and-spoke architectures and centralized network-security models.
  • Experience with Azure Private Link and Private Endpoints.
  • Understanding of hybrid cloud connectivity and integration between Azure and external networks.
  • Ability to analyze network traffic, logs, and flow information to diagnose connectivity and security issues.
  • Experience designing or supporting Azure Government environments.
  • Experience supporting cloud infrastructure within a DoD or other highly regulated environment.
  • Advanced experience with Azure Firewall Premium and Azure Firewall Policy.
  • Experience with Azure Network Watcher and Azure Monitor.
  • Experience automating Azure networking through IaC technologies.

Mansioni

  • Design, implement, configure, and maintain network infrastructure within Microsoft Azure.
  • Serve as a technical SME for Azure networking, routing, connectivity, and firewall technologies.
  • Design and manage Azure VNets, subnets, route tables, UDRs, NSGs, and ASGs.
  • Configure, maintain, and troubleshoot Azure Firewall, Palo Alto Firewall, and policy/rule sets.
  • Develop and maintain firewall rules governing traffic between applications, networks, environments, and security boundaries.
  • Design secure network segmentation strategies to control east-west and north-south traffic.
  • Engineer secure connectivity between multiple Azure environments, subscriptions, VNets, and external networks.
  • Configure and support VNet peering, hub-and-spoke, VPN connectivity, private endpoints, Private Link.
  • Support hybrid connectivity using ExpressRoute and site-to-site VPNs.
  • Design routing solutions involving firewalls, network appliances, shared services, and security boundaries.
  • Troubleshoot network connectivity, routing, DNS, firewall, latency, and application communication issues.
  • Analyze network flows and firewall logs to identify connectivity problems and security issues.
  • Implement network controls supporting Zero Trust architectures and micro-segmentation.
  • Support automation of Azure network infrastructure using IaC.
  • Collaborate with cloud architects, infrastructure developers, cybersecurity engineers, application teams, and system administrators.

Conoscenze

Azure networking
Network security
Zero Trust
RMF/NIST
DoD compliance
Terraform/IaC
Troubleshooting

Formazione

Bachelor's degree in Network Engineering

Strumenti

Palo Alto Firewall
Azure Firewall
Azure VNets
ExpressRoute
Private Link/Private Endpoints
Azure VPN Gateway
Terraform

Descrizione del lavoro

Sigma Defense is seeking an Azure Network Engineer with deep Microsoft Azure expertise, rather than a general cloud administrator who has occasionally configured networking.

This individual should be comfortable taking ownership of complex connectivity problems involving multiple networks, security boundaries, routing paths, firewalls, and cloud environments. The ideal candidate understands how traffic should move through an Azure architecture and can design secure solutions that provide required connectivity without unnecessarily expanding the network attack surface.

Equal Opportunity Employer/Veterans/Disabled: Sigma Defense Systems is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status and will not be discriminated against on the basis of disability.

  • 5+ Years of relevant experience.
  • Professional experience designing, implementing, and supporting Microsoft Azure networking environments.
  • Strong understanding of TCP/IP, routing, subnetting, DNS, NAT, VPNs, firewalls, and network segmentation.
  • Hands‑on experience configuring and troubleshooting Azure Firewall and Palo Alto Firewall.
  • Experience designing and managing Azure VNets, subnets, NSGs, route tables, and User Defined Routes.
  • Experience implementing connectivity between multiple Azure VNets and environments.
  • Experience troubleshooting complex network‑routing and firewall issues.
  • Understanding of hub‑and‑spoke network architectures and centralized network‑security models.
  • Experience with Azure Private Link and Private Endpoints.
  • Understanding of hybrid cloud connectivity and integration between Azure and external networks.
  • Ability to analyze network traffic, logs, and flow information to diagnose connectivity and security issues.
  • Experience designing or supporting Azure Government environments.
  • Experience supporting cloud infrastructure within a Department of Defense (DoD) or other highly regulated environment.
  • Advanced experience with Azure Firewall Premium and Azure Firewall Policy.
  • Experience with Azure Virtual WAN (vWAN), ExpressRoute, and Azure VPN Gateway.
  • Experience with third‑party Network Virtual Appliances and next‑generation firewall technologies within Azure.
  • Experience with Palo Alto Networks, Fortinet, Cisco, or similar enterprise firewall platforms.
  • Experience implementing Zero Trust network architectures and micro‑segmentation.
  • Experience with Azure Network Watcher, Azure Monitor, Log Analytics, Azure DNS, and Private DNS Zones.
  • Experience automating Azure networking through Terraform, Bicep, PowerShell, Azure CLI, or other IaC technologies.
  • Familiarity with DoD cybersecurity requirements, RMF, NIST SP 800‑53, and STIGs.
  • Must be a U.S. citizen.
Mandatory Certifications:
  • CompTIA Security+
  • Microsoft AZ104
Computer Programs/Software:
  • Palo Alto Firewall
  • Azure Firewall
  • Microsoft Azure Cloud Infrastructure
Personnel Clearance Level:
  • Candidate must possess or have the ability to obtain an active TS/SCI security clearance.
  • Clearance may be sponsored for the right candidate.
Education Requirements:
  • Bachelor's degree from an accredited college or university in a Network Engineering or related field of study.
Essential Job Duties (not all-inclusive):
  • Design, implement, configure, and maintain network infrastructure within Microsoft Azure.
  • Serve as a technical subject‑matter resource for Azure networking, routing, connectivity, and firewall technologies.
  • Design and manage Azure Virtual Networks (VNets), subnets, route tables, User Defined Routes (UDRs), Network Security Groups (NSGs), and Application Security Groups (ASGs).
  • Configure, maintain, and troubleshoot Azure Firewall, Palo Alto Firewall, and associated firewall policies and rule collections.
  • Develop and maintain firewall rules governing traffic between applications, networks, environments, and security boundaries.
  • Design secure network segmentation strategies to control east‑west and north‑south traffic.
  • Engineer secure connectivity between multiple Azure environments, subscriptions, VNets, and external networks.
  • Configure and support VNet peering, hub‑and‑spoke architectures, VPN connectivity, private endpoints, Private Link, and other Azure connectivity technologies.
  • Support hybrid connectivity using ExpressRoute and site‑to‑site VPNs.
  • Design routing solutions involving firewalls, network virtual appliances, shared services, and multiple security boundaries.
  • Troubleshoot network connectivity, routing, DNS, firewall, latency, and application communication issues.
  • Analyze network flows and firewall logs to identify connectivity problems and potential security issues.
  • Implement network controls supporting Zero Trust architectures and micro‑segmentation.
  • Support automation of Azure network infrastructure using Infrastructure as Code technologies.
  • Collaborate with cloud architects, infrastructure developers, cybersecurity engineers, application teams, and system administrators.
Salary Range: $110,000 - $153,000 annually.
  • Dental and Vision Insurance
  • Medical Insurance to Include HSA, FSA, and DFSA Plans
  • Life and AD&D coverage
  • Employee Assistance Program (EAP)
  • 401(k) Plan with Company Matching Contributions
  • 160 Hours of Paid Time Off (PTO)
  • 12 (Floating) Holidays
  • Educational Assistance
  • Highly Competitive Salary
Ottieni la revisione del curriculum gratis e riservata.
o trascina qui il file.
Similar jobs

Offerte di lavoro simili che vale la pena confrontare

Azure Networking Architect: DoD-Ready Security
Azure Networking Architect: DoD-Ready Security

Sigma Defense • Roma

In loco
EUR 95.000 - 132.000
Dental and Vision Insurance
Medical Insurance with HSA/FSA/DFSA
Life and AD&D coverage
+2
1750 - Virtual Desktop Infrastructure Engineer
1750 - Virtual Desktop Infrastructure Engineer

Sigma Defense • Roma

In loco
EUR 82.000 - 117.000
Dental and Vision Insurance
Medical Insurance to Include HSA, FSA,
Life and AD&D coverage
+5
1756 - Cybersecurity Engineer
1756 - Cybersecurity Engineer

Sigma Defense • Roma

In loco
EUR 102.000 - 119.000
Dental and Vision Insurance
Medical Insurance (HSA/FSA/DFSA)
Life and AD&D coverage
+5
Network Specialist
Network Specialist

Quantum Sky • Aviano

In loco
EUR 73.000 - 82.000
Health/Dental/Vision
401(k) match
Paid Time Off
+1
Senior Azure Architect
Senior Azure Architect

SoftwareOne • Turbigo

Ibrido
EUR 60.000 - 80.000
Structured onboarding and mentoring
Lifelong learning and professional development
President’s Club for outstanding contributions
Network Administrator
Network Administrator

Connect Group • Milano

In loco
EUR 30.000 - 50.000
Domain Consultant Network Security
Domain Consultant Network Security

Palo Alto Networks • Milano

In loco
EUR 70.000 - 110.000
Azure Cloud Infrastructure Specialist
Azure Cloud Infrastructure Specialist

Proge-Software • Roma

In loco
EUR 50.000 - 70.000
Flexible working hours
Bonuses based on performance
Health and wellness benefits
Network Security Engineer
Network Security Engineer

Smart4 Cloud • Milano

Ibrido
EUR 50.000 - 70.000
Hybrid work arrangement
Senior Azure Architect (gn)
Senior Azure Architect (gn)

SoftwareOne • Milano

Ibrido
EUR 75.000 - 110.000
Onboarding & mentoring
President's Club
Lifelong learning
+1