1755 - Azure Network Engineer

Sigma Defense

City of Rome (NY)

On-site

USD 110,000 - 153,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Dental Insurance
Vision Insurance
Medical Insurance (HSA/FSA/DFSA)
Life and AD&D
EAP
401(k) Matching
PTO 160 Hours
Floating Holidays
Educational Assistance
Competitive Salary

Job summary

Sigma Defense seeks an Azure Network Engineer to own complex connectivity across multiple networks, secure routing paths, firewalls, and cloud environments. The role focuses on designing secure Azure networking solutions that balance connectivity with minimized attack surface.

The candidate will work on VNets, ExpressRoute, private endpoints, and hub-and-spoke architectures, with hands-on firewall expertise and DoD-regulated environment experience.

Qualifications

  • 5+ years of relevant experience in Azure networking.
  • Professional experience designing, implementing, and supporting Microsoft Azure networking environments.
  • Strong understanding of TCP/IP, routing, DNS, NAT, VPNs, firewalls, and network segmentation.
  • Hands-on experience configuring and troubleshooting Azure Firewall and Palo Alto Firewall.
  • Experience designing and managing Azure VNets, subnets, NSGs, route tables, and UDRs.
  • Experience implementing connectivity between multiple Azure VNets and environments.
  • Experience troubleshooting complex network-routing and firewall issues.
  • Understanding of hub-and-spoke architectures and centralized security models.
  • Experience with Azure Private Link and Private Endpoints.
  • Understanding of hybrid cloud connectivity with Azure ExpressRoute and VPNs.
  • Ability to analyze network traffic, logs, and flow information to diagnose issues.
  • Experience with DoD or highly regulated environments and RMF/NIST STIGs.
  • Must be a U.S. citizen.

Responsibilities

  • Design, implement, configure, and maintain network infrastructure within Microsoft Azure.
  • Serve as a technical resource for Azure networking, routing, connectivity, and firewall technologies.
  • Design and manage VNets, subnets, NSGs, UDRs, and ASGs.
  • Configure and troubleshoot Azure Firewall and Palo Alto Firewall policies and rule sets.
  • Develop firewall rules governing traffic between applications and networks.
  • Design secure network segmentation for east-west and north-south traffic.
  • Engineer secure connectivity between Azure environments, subscriptions, and external networks.
  • Configure VNet peering, hub-and-spoke, ExpressRoute, private endpoints, and Private Link.
  • Support hybrid connectivity using ExpressRoute and site-to-site VPNs.
  • Design routing solutions involving firewalls and network appliances.
  • Troubleshoot network connectivity, DNS, firewall, and latency issues.
  • Analyze flows and logs to identify issues and security concerns.
  • Implement Zero Trust architectures and micro-segmentation.
  • Support IaC automation of Azure network infrastructure.

Skills

Azure Networking
Azure Firewall
Palo Alto Firewall
VNet Design
UDR & NSG
Private Endpoints
Hybrid Connectivity
Network Security
Zero Trust
IaC (Terraform)

Education

Bachelors in Network Engineering

Tools

Azure Firewall
Palo Alto Firewall
ExpressRoute
Azure VNets

Job description

Sigma Defense is seeking an Azure Network Engineer with deep Microsoft Azure expertise, rather than a general cloud administrator who has occasionally configured networking.

This individual should be comfortable taking ownership of complex connectivity problems involving multiple networks, security boundaries, routing paths, firewalls, and cloud environments. The ideal candidate understands how traffic should move through an Azure architecture and can design secure solutions that provide required connectivity without unnecessarily expanding the network attack surface.

Equal Opportunity Employer/Veterans/Disabled: Sigma Defense Systems is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status and will not be discriminated against on the basis of disability.

Requirements
  • 5+ Years of relevant experience.
  • Professional experience designing, implementing, and supporting Microsoft Azure networking environments.
  • Strong understanding of TCP/IP, routing, subnetting, DNS, NAT, VPNs, firewalls, and network segmentation.
  • Hands-on experience configuring and troubleshooting Azure Firewall and Palo Alto Firewall.
  • Experience designing and managing Azure VNets, subnets, NSGs, route tables, and User Defined Routes.
  • Experience implementing connectivity between multiple Azure VNets and environments.
  • Experience troubleshooting complex network-routing and firewall issues.
  • Understanding of hub-and-spoke network architectures and centralized network-security models.
  • Experience with Azure Private Link and Private Endpoints.
  • Understanding of hybrid cloud connectivity and integration between Azure and external networks.
  • Ability to analyze network traffic, logs, and flow information to diagnose connectivity and security issues.
  • Experience designing or supporting Azure Government environments.
  • Experience supporting cloud infrastructure within a Department of Defense (DoD) or other highly regulated environment.
  • Advanced experience with Azure Firewall Premium and Azure Firewall Policy.
  • Experience with Azure Virtual WAN (vWAN), ExpressRoute, and Azure VPN Gateway.
  • Experience with third-party Network Virtual Appliances and next-generation firewall technologies within Azure.
  • Experience with Palo Alto Networks, Fortinet, Cisco, or similar enterprise firewall platforms.
  • Experience implementing Zero Trust network architectures and micro-segmentation.
  • Experience with Azure Network Watcher, Azure Monitor, Log Analytics, Azure DNS, and Private DNS Zones.
  • Experience automating Azure networking through Terraform, Bicep, PowerShell, Azure CLI, or other IaC technologies.
  • Familiarity with DoD cybersecurity requirements, RMF, NIST SP 800-53, and STIGs.
  • Must be a U.S. citizen.
Mandatory Certifications:
  • CompTIA Security+
  • Microsoft AZ104
Computer Programs/Software:
  • Palo Alto Firewall
  • Azure Firewall
  • Microsoft Azure Cloud Infrastructure
Personnel Clearance Level:
  • Candidate must possess or have the ability to obtain an active TS/SCI security clearance.
  • Clearance may be sponsored for the right candidate.
Education Requirements:
  • Bachelor's degree from an accredited college or university in a Network Engineering or related field of study.
Essential Job Duties (not all-inclusive):
  • Design, implement, configure, and maintain network infrastructure within Microsoft Azure.
  • Serve as a technical subject-matter resource for Azure networking, routing, connectivity, and firewall technologies.
  • Design and manage Azure Virtual Networks (VNets), subnets, route tables, User Defined Routes (UDRs), Network Security Groups (NSGs), and Application Security Groups (ASGs).
  • Configure, maintain, and troubleshoot Azure Firewall, Palo Alto Firewall, and associated firewall policies and rule collections.
  • Develop and maintain firewall rules governing traffic between applications, networks, environments, and security boundaries.
  • Design secure network segmentation strategies to control east-west and north-south traffic.
  • Engineer secure connectivity between multiple Azure environments, subscriptions, VNets, and external networks.
  • Configure and support VNet peering, hub-and-spoke architectures, VPN connectivity, private endpoints, Private Link, and other Azure connectivity technologies.
  • Support hybrid connectivity using ExpressRoute and site-to-site VPNs.
  • Design routing solutions involving firewalls, network virtual appliances, shared services, and multiple security boundaries.
  • Troubleshoot network connectivity, routing, DNS, firewall, latency, and application communication issues.
  • Analyze network flows and firewall logs to identify connectivity problems and potential security issues.
  • Implement network controls supporting Zero Trust architectures and micro-segmentation.
  • Support automation of Azure network infrastructure using Infrastructure as Code technologies.
  • Collaborate with cloud architects, infrastructure developers, cybersecurity engineers, application teams, and system administrators.

Salary Range: $110,000 - $153,000 annually.

Benefits
  • Dental and Vision Insurance
  • Medical Insurance to Include HSA, FSA, and DFSA Plans
  • Life and AD&D coverage
  • Employee Assistance Program (EAP)
  • 401(k) Plan with Company Matching Contributions
  • 160 Hours of Paid Time Off (PTO)
  • 12 (Floating) Holidays
  • Educational Assistance
  • Highly Competitive Salary
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

1755 - Azure Network Engineer
1755 - Azure Network Engineer

Sigma Defense Systems • City of Rome (NY)

On-site
USD 110,000 - 153,000
Dental and Vision Insurance
Medical Insurance with HSA/FSA/DFSA
Life and AD&D coverage
+6
1755 - Azure Network Engineer
1755 - Azure Network Engineer

Sigma Defense Systems LLC • City of Rome (NY)

On-site
USD 110,000 - 153,000
Dental and Vision Insurance
Medical Insurance with HSA/FSA/DFSA
Life and AD&D coverage
+3
1755 - Azure Network Engineer
1755 - Azure Network Engineer

Sigma-Defense • City of Rome (NY)

On-site
USD 110,000 - 153,000
Dental and Vision Insurance
Medical Insurance with HSA/FSA/DFSA
Life and AD&D coverage
+3
Azure Network Engineer 1
Azure Network Engineer 1

Empire State • City of Albany (NY)

On-site
USD 110,000 - 120,000
Azure SME
Azure SME

Insight Global • Wilmington (DE)

Remote
USD 96,000 - 110,000
Medical, dental, vision insurance
HSA, FSA, DCFSA account options
401(k) with employer matching
+1
Azure Network Engineer 1
Azure Network Engineer 1

Empire State Development • City of Albany (NY)

Hybrid
USD 110,000 - 150,000
Comprehensive Benefits Package.
Staff Cloud Network Engineer
Staff Cloud Network Engineer

Eliassen Group • United States

Remote
USD 83,000 - 124,000
Computer Technician - Azure Network Security
Computer Technician - Azure Network Security

CG Infinity, Inc. • Houston (TX)

On-site
USD 85,000 - 115,000
Senior Azure Engineer
Senior Azure Engineer

Arena Technical Resources, LLC (ATR) • Fort Belvoir (VA)

On-site
USD 176,800 - 187,200
Senior Network Engineer - Azure Cloud
Senior Network Engineer - Azure Cloud

Slipstream Life Sciences • Hampton (NJ)

Hybrid
USD 152,000 - 227,000
Remote Fridays (hybrid)
Own equipment and remote workspace
Independent contractor engagement