Senior Cloud Network Engineer (Automation / IaC)

SUNSCRAPERS Spółka z ograniczoną odpowiedzialnością

Warszawa

On-site

PLN 391,000 - 608,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Remote-first culture
Premium AI tooling access
Direct exposure to leadership and top‑

Job summary

SUNSCRAPERS Spółka z ograniczoną odpowiedzialnością is seeking a Senior Cloud Network Engineer to own cloud networking at scale, across 300+ accounts and thousands of VPCs. The role blends Platform Engineering with Networking, translating network needs into infrastructure code and driving migration programs.

You’ll work in an AWS-first environment with Terraform IaC, Cloud WAN, and centralized firewall initiatives while collaborating with DevOps and network teams to deliver repeatable patterns

Qualifications

  • Strong Terraform / IaC at scale.
  • Deep AWS networking knowledge across multi-account environments.
  • Experience with VPC design, Transit Gateway and IPAM.
  • Fluent English for client discussions.

Responsibilities

  • Drive the Transit Gateway → AWS Cloud WAN migration.
  • Lead the centralized firewall programme.
  • Operate and evolve the hybrid firewall architecture.
  • Build and maintain a Terraform module library.
  • Own IP address management via AWS IPAM.
  • Support DNS (Route 53) and Direct Connect connections.
  • Bridge Platform Engineering and Networking with IaC for both sides to operate and trust.

Skills

AWS networking
Terraform IaC
VPC design
Network security
GitHub / IaC automation
English communication

Tools

Terraform
GitHub
Route 53
AWS Cloud WAN

Job description

Senior Cloud Network Engineer (Automation / IaC)

Full-time B2B | Remote EU / Poland | Financial Services Context

We are an AI-native data and technology partner for private capital and healthcare. Founded in 2010 and headquartered in Warsaw, we work with leading PE firms, VC funds, and healthcare organizations to build proprietary data infrastructure, deploy AI solutions, and drive AI-native transformation.

Our clients manage a cumulative $1.2T+ in assets. Our average engagement runs five years. Our NPS sits above 80. We don't need to claim credibility – we can show it.

We've also done to ourselves what we now do for clients. We've restructured our own company around AI – tools, policies, roles, delivery models. This isn't a pitch. It's a playbook we've already run, and we're hiring the engineers who will run it for others.

The Opportunity

A leading global alternative asset management firm is looking for a Senior Cloud Network Engineer to own cloud networking at scale – across ~300 AWS accounts and thousands of VPCs, spanning multiple regions. This is a hands-on role at the boundary between Platform Engineering and Networking: the person who translates network requirements into infrastructure code, drives active migration programmes, and builds the reusable patterns every engineering team provisions their networks against.

The team already has strong network engineers and strong DevOps engineers. What's missing is the person who bridges the two – deep enough in AWS networking to hold their own with the Head of Networking, and fluent enough in Terraform and IaC to make that knowledge repeatable.

The environment is AWS-first with no on-premises data centres. You'll work with AWS Cloud WAN (an active TGW → Cloud WAN migration is in flight), AWS Network Firewall, and a centralized firewall programme replacing the legacy NACL model. You won't be designing networks in Visio – you'll be writing Terraform and deriving firewall rules from VPC Flow Log analysis.

What You'll Own
  • Drive the active Transit Gateway → AWS Cloud WAN migration – ~10 segments, tag-based segmentation, phased TGW decommission; already in flight and needs an engineer who can own it to completion
  • Lead the centralized firewall programme replacing the NACL model – policing cross-account traffic, analysing VPC Flow Logs in S3 to derive firewall rules, and managing change control at scale
  • Operate and evolve the hybrid firewall architecture: AWS Network Firewall for east-west traffic alongside NGFWs via Gateway Load Balancers; understand and maintain the boundary between them
  • Build and maintain a Terraform module library for network provisioning (VPC layouts, routing, firewall policies, Cloud WAN policies) consumed across the org via GitHub / GitHub Enterprise
  • Own IP address management via AWS IPAM at 400+ account scale, supporting account-vending workflows
  • Support DNS (Route 53 + inbound resolvers to Active Directory) and Direct Connect (NY primary, Virginia POP failover, four-nines target)
  • Act as the primary technical bridge between Platform Engineering and Networking – turning routing requirements, security standards, and network architecture into IaC both sides can operate and trust
  • Deep, hands-on AWS networking at multi-account scale: VPC design, routing, security groups, Transit Gateway, PrivateLink, IPAM
  • Conceptual understanding of AWS Cloud WAN – core network policy documents, segments, tag-based routing, multi-region/multi-account topologies; hands-on production or migration experience a plus
  • Centralized firewall & traffic inspection – stateful/stateless rule groups, east-west inspection, centralized policy management; AWS Network Firewall, Palo Alto NGFW (via GWLB), or comparable vendors all count equally
  • Strong Terraform / IaC at scale – module design, state management, plan/apply, versioning, remote backends (real depth, not just consuming modules) – via GitHub / GitHub Enterprise
  • Data-driven network automation – ability to query VPC Flow Logs in S3 (Athena, Python/pandas, or equivalent) and translate traffic patterns into firewall rule changes; this is where purely traditional network engineers fall short
  • Cross-domain fluency – comfortable with pull-request reviews and BGP/routing discussions in the same week; familiarity with CI/CD for infrastructure and policy-as-code (OPA, Sentinel, or AWS Config); change-management discipline for high-blast-radius changes
  • Solid spoken English for peer-level technical discussion with the client

Nice to Have

  • SD-WAN experience – Palo Alto Prisma SD-WAN is a plus; equivalent platforms (Cisco Viptela/Meraki, VeloCloud, Aviatrix) are equally welcome3
  • Direct Connect / BGP, Route 53 hybrid DNS, PrivateLink at scale, ZScaler client-access integration
  • AWS certifications: Advanced Networking Specialty or Solutions Architect Professional
  • AWS Control Tower or Landing Zone Accelerator for network account vending
  • GitOps workflows for infrastructure (Atlantis, ArgoCD, or equivalent)
  • Exposure to VPC Lattice / application networking (the client has evaluated it and may revisit)
  • Background in financial services or regulated industries where segmentation, audit trails, and change control are compliance requirements, not preferences
  • Unrestricted AI Stack & Premium Gear: Fully paid licenses for Cursor, Claude Pro, etc.
  • Total Autonomy (Remote-First): No filler meetings, no Jira bloat, no micromanagement. You own the workflow. We care about shipped systems in production, not logged hours.
  • Direct Impact: You’ll work face-to-face with our CEO, CTO & VPs and VC/PE General Partners.
  • Frontier Engineering Culture: Build alongside elite engineers who are shipping systems that drive real investment decisions. Backed by continuous growth and a strong knowledge-sharing culture (check our YouTube).
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Solutions Architect / Pre-Sales Lead: Enterprise Networking
Principal Solutions Architect / Pre-Sales Lead: Enterprise Networking

Codilime • Warszawa

Hybrid
PLN 150,000 - 200,000
Flexible working hours
Professional growth support
Solid onboarding process
+1
Senior Cloud & Platform Engineer (AWS/Kubernetes)
Senior Cloud & Platform Engineer (AWS/Kubernetes)

Salve.Lab • Warszawa

On-site
PLN 524,000 - 711,000
Fully remote position
Full-time collaboration
International engineering environment
Senior AWS Platform Engineer
Senior AWS Platform Engineer

FreeBalance Inc. • Kraków

On-site
PLN 180,000 - 240,000
Cloud Specialist - Terraform Engineer
Cloud Specialist - Terraform Engineer

ARK Solution • Poland

Hybrid
PLN 254,000 - 340,000
Staff Engineer I, DevOps Engineering
Staff Engineer I, DevOps Engineering

Bain & Company • Warszawa

On-site
PLN 300,000 - 460,000
Staff Engineer I, DevOps Engineering at Bain & Company
Staff Engineer I, DevOps Engineering at Bain & Company

Bain & Company • Warszawa

On-site
PLN 240,000 - 300,000
Application Security Engineer
Application Security Engineer

LionHires Recruitment • Poland

On-site
PLN 180,000 - 240,000
Senior Cloud Platform Engineer (Azure) – Landing Zone
Senior Cloud Platform Engineer (Azure) – Landing Zone

NordHR • Województwo pomorskie

Hybrid
PLN 180,000 - 280,000
Hybrid working model
Salary and benefits package
Private healthcare and life insurance
+2
AWS .NET Engineer
AWS .NET Engineer

Semantive • Warszawa

Remote
PLN 70,000 - 100,000
Fully remote working model
Knowledge-sharing sessions
Employee referral program
Senior Network Engineer
Senior Network Engineer

ISS Tech Team • Warszawa

Hybrid
PLN 180,000 - 300,000