The Cloud Network Engineer designs and operates the cloud network foundation as the company migrates to the cloud, exits data center capacity, and rebuilds its disaster recovery posture. This role owns cloud network architecture, the transit layer, hybrid connectivity such as Direct Connect and VPN, cloud DNS, segmentation, firewalls, and the multi-region network model that DR depends on. The engineer plans and executes network cutovers across migration waves, delivers configuration through Terraform, and manages colocation and carrier connectivity including circuit diversity. This is a hands-on role spanning both legacy enterprise networking and modern cloud network architecture, and serves as escalation for network incidents.
- Design and operate VPC architecture, address space allocation, and routing across a multi-account AWS environment.
- Build and run the transit layer using Transit Gateway or Cloud WAN.
- Design and operate hybrid connectivity, including Direct Connect and site-to-site VPN.
- Build and operate connectivity between AWS partitions and to secondary cloud platforms.
- Own cloud DNS, including Route 53, resolver rules, and hybrid name resolution.
- Support trading partner and vendor connectivity, including EDI and clearinghouse tunnels.
- Implement network segmentation separating regulated workloads, under security-approved policy.
- Configure and operate cloud firewalls, inspection paths, egress controls, and load balancing.
- Design the multi-region network model supporting disaster recovery, and validate failover through testing.
- Design and manage colocation and carrier connectivity, including circuit diversity and provider management.
- Plan and execute network cutovers during migration waves, including rollback.
- Deliver network configuration through Terraform.
- Build network monitoring and capacity visibility. Feed network telemetry to security operations.
- Maintain topology documentation and serve as escalation for network incidents.
- Strong routing fundamentals, including BGP in hybrid environments.
- Firewall and network security policy experience.
- Experience supporting production cutovers under change control.
- Troubleshooting across TCP/IP, DNS, load balancers, and routing.
- Colocation and carrier circuit experience: cross connects, diverse path design, provider management.
Required Work Experience:
- 8+ years related work experience in networking
- 4+ years managing hybrid cloud/on-premises network infrastructure
Required Education:
- Related Bachelor's degree required or additional related work experience
Preferred Experience:
- Healthcare payer experience, including partner and EDI connectivity.
- AWS GovCloud networking, including cross-partition routing and DNS.
- Networking across two or more major cloud platforms, including connectivity between them. Which platform was primary does not matter.
- Terraform or equivalent infrastructure as code.
- Data center migration, exit, or secondary site standup experience.
- Palo Alto or Fortinet firewalls in cloud.
- AWS Advanced Networking Specialty, CCNP, or CCIE.