We are looking for a Senior Network Engineer to join our engagement on the delivery of a Unified Automation Platform — an Internal Developer Platform (IDP) that standardizes new-project delivery, centralizes access to development resources, and enables software creation through templates and golden paths.
Within this role, you will contribute to the Network/Firewalls automation stream, developing modules on a modern toolchain (Terraform/OpenTofu for IaC and Ansible for CaC) with AI-assisted development through GitHub Copilot as a standard practice.
Responsibilities
- Develop and maintain firewall automation modules across PaloAlto, F5, and Cloudflare (security rules, address/service objects, NAT, VIP/pool configuration, WAF policy, certificate binding), following designs defined by the Network Architect
- Create and support DNS and NetBox IPAM automation (zone/record management, prefix/role/tenant data entry, reconciliation jobs)
- Provide Azure core connectivity modules (VNets/subnets, Application Gateway, WAF, Azure Firewall, NSGs) via Terraform/OpenTofu
- Assist VMware NSX-T segment and distributed firewall (DFW) rule implementation in coordination with the VMware team
- Perform commit/lock handling procedures for concurrent firewall pipeline changes (PaloAlto/Panorama candidate-config workflows)
- Resolve and remediate production network/firewall issues during Implementation and Adoption, operating within change-control processes given the high blast-radius of network changes
Requirements
- 3+ years of hands-on experience in network engineering with a focus on automation
- Background in automating firewall platforms through Infrastructure as Code, including PaloAlto, F5, and Cloudflare
- Expertise in deploying Azure networking constructs (VNets, Application Gateway, WAF) and security components (Azure Firewall, NSGs) via Terraform/OpenTofu
- Knowledge of DNS and IPAM (NetBox) data models and automation
- Familiarity with VMware NSX-T network segmentation and distributed firewall concepts
- Proficiency in Ansible for network/firewall configuration tasks, combined with Terraform/OpenTofu-based provisioning
- Capability to work within change-control processes for high-blast-radius network/security modifications
- Flexibility to use AI-assisted development with GitHub Copilot (provided project-wide)
- Excellent command of written and spoken English (B2+ level)
Nice to have
- Competency in certificate distribution (Venafi) linked to network/load-balancer endpoints
- Understanding of global traffic management and multi-region failover patterns
We offer
- CONTINUOUS UPSKILLING, LEARNING & DEVELOPMENT
- Diversity of tasks and projects
- Assessment center for objective review of competency level
- Personal development plan
- Mentoring programs and leadership development
- Certification and professional development support
- Access to learning platforms including more than 2,500 internal courses
- English courses taught by certified teachers
- CORPORATE BENEFITS
- Extra leave days
- Referral bonuses
- COMPENSATION PACKAGE
- Competitive compensation paid in USD
- Regular salary and performance reviews
- MEDICAL & HEALTHCARE
- Private health insurance
- Well-being events
- WORKING ENVIRONMENT
- Recreation areas and kitchens
- Tea, coffee and snacks
- Sports equipment and game consoles
- IT Equipment
- Microsoft’s Software Assurance Home Use Program (HUP)
EPAM is global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and ambitious startups. With over thirty years of expertise in custom software, product and platform engineering, we empower our clients to become AI-Native enterprises, driving measurable value from innovation and digital investments.