Senior Cloud & Network Security Engineer

arcadian data

Doha

On-site

QAR 180,000 - 300,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

arcadian data is seeking a Senior Cloud and Network Security Engineer to design, implement, and maintain secure network infrastructures across Microsoft Azure and on‑prem environments. You will lead architecture decisions for DNS, VPN, Private Endpoints, proxies, and on‑premise firewalls, coordinating with multiple teams and vendors.

The role requires 10+ years of hands‑on experience in Azure networking and security, with a strong focus on Zero Trust, IaC, and secure connectivity across hybrid

Qualifications

  • Ten or more years of experience in network engineering or related security roles.
  • Hands-on experience designing and implementing Microsoft Azure networking and security in enterprise environments.
  • Proven delivery of hybrid architectures connecting Azure with on‑premises networks.

Responsibilities

  • Design end-to-end network security architectures for Azure and hybrid environments.
  • Develop network designs, diagrams, IP plans, traffic flow mappings, and firewall rule matrices.
  • Define segmentation, routing, and secure connectivity between apps, cloud services, and on‑premises systems.

Skills

Azure networking
DNS
VPN
Zero Trust
IaC (Terraform)
Azure Bicep
Terraform
Firewall design
Azure Private Endpoints
Azure CLI

Education

Bachelor's degree in computer science, information technology, engineering, or related discipline
AZ-700 Microsoft Certified: Azure Network Engineer Associate
Additional Microsoft azure security/architecture certifications

Tools

Terraform
Azure CLI
PowerShell
Azure Bicep
ExpressRoute

Job description

Senior Cloud and Network Security Engineer (Azure)

Position Summary

We are seeking a Senior Cloud and Network Security Engineer with at least 10 years of relevant experience to design, implement, and maintain secure network infrastructure across Microsoft Azure and on-premises environments. This role combines network security architecture with hands‑on engineering, with particular responsibility for DNS, VPN connectivity, Azure Private Endpoints, proxies, and on‑premises firewalls. The successful candidate will support multiple projects, translating business and technical requirements into secure, reliable, and scalable network designs.

Key Responsibilities
Network Architecture and Project Delivery
  • Design end-to-end network security architectures for Azure and hybrid environments, ensuring alignment with enterprise security standards and project requirements.
  • Develop high-level and low-level designs, network diagrams, IP addressing plans, traffic flow mappings, and firewall rule matrices.
  • Define network segmentation, routing, ingress and egress controls, and secure connectivity between applications, cloud services, and on-premises systems.
  • Review proposed solutions, identify network security risks and dependencies, and recommend appropriate controls.
  • Work with solution architects, cybersecurity teams, infrastructure engineers, application teams, and vendors throughout project delivery.
Azure Networking and Security
  • Configure and manage Azure Virtual Networks, subnets, peering, route tables, Network Security Groups, and Application Security Groups.
  • Implement Azure Private Endpoints and Private Link, including associated DNS configuration and access controls.
  • Configure and troubleshoot Azure DNS, Private DNS Zones, Azure DNS Private Resolver, and hybrid DNS resolution.
  • Implement and maintain site-to-site and point-to-site VPNs, Azure VPN Gateway, and ExpressRoute connectivity where required.
  • Configure Azure Firewall, network virtual appliances, NAT Gateway, and application protection services such as Web Application Firewall.
  • Design and maintain hub-and-spoke or Azure Virtual WAN architectures, including centralized inspection and controlled outbound access.
On‑Premises Firewalls, Proxies, and Hybrid Connectivity
  • Configure, maintain, and troubleshoot on‑premises firewalls, including security policies, NAT rules, routing, VPN tunnels, and logging.
  • Manage enterprise proxies and secure web gateways, including authentication, URL filtering, allowlists, and TLS inspection requirements.
  • Establish secure connectivity between Azure workloads, corporate networks, third‑party services, and remote users.
  • Investigate connectivity issues involving DNS, routing, asymmetric traffic flows, firewall policies, proxies, certificates, and VPN tunnels.
  • Review firewall and proxy rules regularly to remove unnecessary access and enforce least‑privilege connectivity.
Operations, Governance, and Documentation
  • Monitor network availability, performance, and security using Azure and enterprise monitoring tools.
  • Support incident investigation and root cause analysis for network and security‑related issues.
  • Implement changes through established change management processes, including impact assessments, testing, and rollback plans.
  • Automate repeatable configurations using Terraform, Bicep, PowerShell, or Azure CLI.
  • Maintain configuration documentation, operational runbooks, architecture standards, and support handover materials.
  • Validate resilience and failover arrangements for critical network connectivity and security components.
Required Experience and Technical Skills
  • Minimum 10 years of experience in network engineering, network security, infrastructure security, or closely related roles.
  • Substantial hands‑on experience designing and implementing Microsoft Azure networking and security solutions in enterprise environments.
  • Proven delivery of hybrid architectures connecting Azure with on‑premises networks.
  • Strong practical expertise in DNS, TCP/IP, subnetting, routing, BGP, NAT, IPsec VPNs, and TLS.
  • Demonstrated experience configuring Azure Private Endpoints and resolving hybrid private DNS issues.
  • Hands‑on experience with enterprise firewalls from vendors such as Palo Alto Networks, Fortinet, Check Point, or Cisco.
  • Experience managing enterprise proxies or secure web gateways and troubleshooting application connectivity through these services.
  • Strong understanding of network segmentation, Zero Trust principles, least‑privilege access, and defense in depth.
  • Infrastructure as Code (IaC): Hands‑on experience using Terraform or Azure Bicep to provision and manage Azure networking and security infrastructure, including virtual networks, subnets, route tables, security groups, firewalls, VPN gateways, Private Endpoints, and DNS configurations.
  • Experience developing reusable IaC modules, managing configurations in version control, and deploying changes through CI/CD pipelines.
  • Ability to produce clear architecture documentation and take ownership of technical delivery across multiple projects.
  • Strong troubleshooting, communication, and stakeholder management skills.
Qualifications and Certifications
  • Bachelor's degree in computer science, information technology, engineering, or a related discipline, or equivalent professional experience.
  • Required: Microsoft Certified: Azure Network Engineer Associate (AZ-700).
  • Preferred: Additional relevant Microsoft certifications in Azure architecture or cloud security.
  • Advantageous: Professional‑level networking or security certifications, such as CCNP, CCIE, CISSP, or relevant firewall vendor certifications.
Soft Skills and Professional Competencies
  • Influencing and stakeholder engagement: Ability to influence technical teams, project managers, and business stakeholders to adopt secure architecture decisions and implement recommended controls.
  • Driving best practices: Ability to establish, promote, and embed cloud infrastructure and network security best practices into project delivery and day‑to‑day operations.
  • Communication: Clearly explain technical risks, architectural decisions, and recommendations to both technical and non‑technical audiences.
  • Collaboration: Work effectively across cybersecurity, infrastructure, application, and vendor teams to resolve dependencies and deliver solutions.
  • Ownership and accountability: Take responsibility for solutions from design through implementation and operational handover, proactively addressing risks and issues.
  • Problem‑solving and judgment: Apply structured troubleshooting and sound judgment to balance security, reliability, cost, and business requirements.
  • Constructive challenge: Confidently challenge insecure or unsustainable approaches and propose practical alternatives.
  • Mentoring and knowledge sharing: Support colleagues through technical guidance, design reviews, documentation, and knowledge‑sharing sessions.
Desirable Experience
  • Supporting secure connectivity for enterprise applications, data platforms, and AI services.
  • Working in regulated industries or large organizations with formal security governance.
  • Integrating network and firewall logs with centralized monitoring and SIEM platforms.
  • Designing highly available connectivity and supporting disaster recovery exercises.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Azure Cloud & Network Security Architect
Azure Cloud & Network Security Architect

arcadian data • Doha

On-site
QAR 180,000 - 300,000
Senior Cloud Network Security Engineer
Senior Cloud Network Security Engineer

Codvo Private Limited • Doha

On-site
QAR 109,000 - 164,000
Senior Cloud Engineer
Senior Cloud Engineer

T4I TECHNOLOGIES PRIVATE LIMITED • Qatar

On-site
QAR 180,000 - 300,000
Cloud Systems Engineer
Cloud Systems Engineer

Talent Leaders Inc. • Doha

On-site
QAR 223,200 - 334,800
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Employment • Doha

On-site
QAR 360,000 - 600,000
Network Security Engineer
Network Security Engineer

Talent Leaders Inc. • Doha

On-site
QAR 167,400 - 223,200
Security Analyst - IT Ops
Security Analyst - IT Ops

Mekdam Technical Services • Doha

On-site
QAR 334,800 - 502,200
Cloud Security Consultant
Cloud Security Consultant

malomatia • Doha

On-site
QAR 240,000 - 360,000
Global Network Engineer: Cisco, Cloud & Security
Global Network Engineer: Cisco, Cloud & Security

Employment • Doha

On-site
QAR 167,000 - 257,000
Senior Network Administrator – Technical Pre-Sales
Senior Network Administrator – Technical Pre-Sales

Regency Technology - Qatar • Doha

On-site
QAR 180,000 - 320,000