Senior Cloud Network Engineer

KINECTIVE

Golden (CO)

On-site

USD 160,000 - 180,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Health coverage
401(k) plan
Flexible PTO
Holidays and parental leave
Wellness resources

Job summary

Kinective is seeking a Senior Cloud Network Engineer to own the networking backbone for our product suite, primarily on AWS with Azure support. You will design, build, and operate cloud network infrastructure, ensure security posture, and maintain compliance readiness across SOC 2 and PCI DSS.

You’ll work across client connectivity, CI/CD integration, and IaC pipelines, collaborating with security, product, and customer teams.

Qualifications

  • Bachelor’s degree in computer science, software engineering, or related field, or equivalent practical experience.
  • 5+ years hands-on network engineering in cloud-native or hybrid environments.
  • Deep expertise with AWS networking (VPC, Transit Gateway, Route 53, SGs, NACLs, Network Firewall).
  • Cloud security & connectivity — IAM roles/policies, SSM, GuardDuty, Security Hub.
  • Working knowledge of Azure networking (VNet, Azure Firewall, NSGs).
  • Proven experience designing and operating IPsec/IKEv2 and SSL VPN tunnels for enterprise clients.
  • Solid understanding of BGP and OSPF in multi-cloud/hybrid contexts.
  • Experience with SOC 2 and PCI DSS network controls and audit evidence.
  • Experience authoring reusable OpenTofu or Terraform modules.
  • Strong TCP/IP fundamentals and packet-level troubleshooting.

Responsibilities

  • Design and operate network architectures across AWS (primary) and Azure.
  • Enforce strict network segmentation between production and non-production environments.
  • Manage routing, peering, and segmentation across multi-cloud environments.
  • Maintain and optimize network performance, availability, and observability.
  • Integrate networking into CI/CD pipelines and IaC workflows.
  • Design, provision, and maintain IPsec and SSL VPN tunnels for client environments.
  • Lead client onboarding and troubleshoot connectivity incidents; produce RCAs.
  • Maintain documentation of network configurations, including IP schemas and tunnel parameters.
  • Support SOC 2 and PCI DSS audit cycles with evidence collection.
  • Create and maintain OpenTofu/Terraform modules; peer-reviewed PRs.
  • Participate in on-call rotation and post-incident reviews.
  • Mentor junior engineers and contribute to architectural standards.

Skills

AWS networking
VPN engineering
BGP/OSPF
IaC (Terraform/OpenTofu)
TCP/IP fundamentals
Packet capture
Cloud tooling (CLI, Python, Docker)
Cross-cloud (AWS/Azure)
Communication
CI/CD integration
Kubernetes networking
Observability tooling
AI tool familiarity

Education

Bachelor’s degree in CS/SE or equivalent

Tools

Terraform/OpenTofu
Docker
Kubernetes
Datadog/Grafana
GitHub Actions

Job description

Description
Lead the Way to Intelligent Banking with Us!

You might not think about what happens behind the scenes when you check your bank balance or deposit a check from your phone, but we do. Every day.

Kinective empowers banks and credit unions to move beyond keeping up with technology to shaping the future of banking. Our platform seamlessly connects the right tools, delivers real-time data, and drives smarter operations for more than 4,000 financial institutions nationwide. We are a fast-growing team built on individual ownership, company-wide collaboration, and setting industry-leading standards. Here, new ideas are encouraged, candid feedback is welcomed, and your growth truly matters as much as the company’s. At Kinective, we are leading the way to intelligent banking together and enjoying the journey along the way.

Why This Role Matters

Every role at Kinective exists to move the needle for our clients, partners, and the financial institutions we serve. We are looking for a Senior Cloud Network Engineer at Kinective to own and evolve the networking backbone that powers our products and connects us to our customers. This is a product-facing role — not internal IT. You will design, build, and operate the cloud and customer-facing network infrastructure that directly impacts product reliability, security posture, and compliance standing.

You will work primarily across AWS with supporting Azure environments, manage VPN tunnel infrastructure for client connectivity, and play an active role in SOC 2 and PCI DSS audit readiness and evidence collection. This role requires someone who thinks in systems, communicates clearly across engineering, security, and customer teams, and takes ownership end-to-end. Everything we build is delivered as code — no click-ops in production.

What you’ll own
Cloud & Product Networking
  • Design and operate network architectures across AWS (primary) and Azure, including VPCs, VNets, and Transit Gateways
  • Enforce strict network segmentation between production and non-production environments — separate VPCs/VNets, distinct routing domains, and explicit deny-by-default posture
  • Manage routing, peering, and segmentation across multi-cloud environments to support product SLAs and security boundaries
  • Maintain and optimize network performance, availability, and observability across cloud regions
  • Collaborate with platform and infrastructure engineering teams to integrate networking into CI/CD pipelines and IaC workflows
Client VPN & Secure Connectivity
  • Design, provision, and maintain IPsec and SSL/TLS VPN tunnels connecting product environments to enterprise clients
  • Own the full lifecycle of client tunnel onboarding — from technical scoping through cutover and steady-state support
  • Serve as the primary technical point of contact during client network onboarding and connectivity incidents; lead customer-facing troubleshooting calls and produce written RCAs when client connectivity is impaired
  • Troubleshoot and resolve tunnel stability, latency, and routing issues in coordination with client network teams — including packet capture and side-by-side config review
  • Maintain documentation for all client connectivity configurations, including IP schemas, tunnel parameters, and escalation paths
Security & Compliance
  • Support SOC 2 (Type II) and PCI DSS audit cycles — collecting network evidence, remediating findings, and responding to auditor requests
  • Implement and enforce network controls aligned to SOC 2 Common Criteria and PCI DSS network segmentation and firewall requirements
  • Conduct periodic firewall rule reviews, NACLs/security group audits, and access control assessments
  • Collaborate with the security team on threat modeling, vulnerability remediation, and incident response for network-layer events
  • Maintain network diagrams and data flow documentation required for compliance scoping
Operations & Engineering Excellence
  • All network infrastructure changes are delivered as code — no console changes in production. Author and maintain reusable OpenTofu / Terraform modules for VPCs, VNets, TGW attachments, VPN tunnels, firewall rules, and routing policy. Every change lands via peer-reviewed PR
  • Track work, changes, and incidents in JIRA; contribute to clear ticket hygiene and change-management workflows
  • Build and maintain monitoring, alerting, and runbooks for network health across environments
  • Participate in on-call rotation for network-layer incidents; lead post-incident reviews for network events
  • Mentor junior engineers and contribute to architectural decisions and standards
Requirements
Necessary Qualifications & Competencies
  • Bachelor’s degree in computer science, software engineering, or a related field, or equivalent practical experience.
  • 5+ years of hands-on network engineering experience in cloud-native or hybrid environments
  • Deep expertise with AWS networking (VPC, Transit Gateway, Route 53, Security Groups, NACLs, Network Firewall)
  • Cloud security & connectivity — hands-on with AWS IAM (roles, policies, identity federation), SSM (Systems Manager, Session Manager, Parameter Store), GuardDuty, and Security Hub
  • Working knowledge of Azure networking (VNet, Azure Firewall, NSGs) — we recognize deep expertise in both clouds is rare; strong AWS with willingness to grow in Azure (or vice versa) is acceptable
  • Proven experience designing and operating IPsec/IKEv2 and SSL VPN tunnels with enterprise clients
  • Solid understanding of BGP, OSPF, and routing policy in multi-cloud and hybrid contexts
  • Hands-on experience with compliance programs — SOC 2 and/or PCI DSS — specifically network controls and audit evidence
  • Experience authoring reusable OpenTofu or Terraform modules, not just consuming them
  • Strong TCP/IP fundamentals: subnetting, DNS, TLS, NAT, load balancing
  • Hands-on packet-level troubleshooting — Wireshark, tcpdump, mtr, iperf, dig
  • Proficiency with AWS CLI, Azure CLI, Python, Bash/PowerShell, and Docker for automation, tooling, and troubleshooting
  • Strong written and verbal communication skills — comfortable running technical calls with customer network engineers
Preferred Skills
  • Working understanding of modern AI tooling and hands-on experience with coding assistants (e.g., GitHub Copilot, Cursor, Claude, ChatGPT) to accelerate module authoring, troubleshooting, and documentation
  • Experience with network observability tooling (e.g., VPC Flow Logs, Azure NSG Flow Logs, Datadog, Grafana, Dynatrace)
  • Familiarity with Nagios or similar network monitoring platforms
  • Familiarity with zero trust network architecture (ZTNA) principles and implementation
  • Familiarity with Cisco Meraki and IPS/IDS platforms
  • DDoS protection and WAF experience — AWS Shield/WAF or Azure Front Door/WAF
  • Hybrid DNS design across Route 53, Azure Private DNS, and on-prem resolvers
  • Exposure to Kubernetes networking (CNI, ingress controllers, service mesh) in multi-cloud deployments
  • Financial-services or regulated-industry background
  • Relevant certifications: AWS Advanced Networking Specialty, Azure Network Engineer Associate, CCNP, or equivalent
  • Experience working within a CI/CD-driven infrastructure model (Harness, GitHub Actions, or similar)
Pay, Benefits & Total Rewards

$160,000–$180,000 with 10% bonus potential

The salary range listed reflects the minimum and maximum for this role. Individual compensation is based on experience, qualifications, job-related skills, location, and internal equity, and most offers are not made at the top of the range.

Base pay is one part of Kinective’s Total Rewards package. Depending on the role, employees may also be eligible for bonuses, commissions, or equity. All employees have access to a competitive benefits package designed to support health, well-being, and financial security, including:

  • Comprehensive health coverage (medical, dental, vision, prescriptions, life & disability)
  • Flexible PTO, 11 company holidays, and generous parental and caregiver leave
  • An immediately vested 401(k) with company contributions
  • Wellness resources and professional development opportunities

Please note that this role does not currently offer sponsorship opportunities. Open to Colorado residents only.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager, Information Technology
Manager, Information Technology

KINECTIVE • Gilbert (AZ)

On-site
USD 115,000 - 135,000
Comprehensive health coverage
401(k) with company contributions
Generous leave and holidays
+1
Manager, Information Technology
Manager, Information Technology

Socket.dev • Gilbert (AZ)

On-site
USD 115,000 - 135,000
Health coverage
Flexible PTO
11 company holidays
+3
Senior Cloud Network Engineer (Remote)
Senior Cloud Network Engineer (Remote)

Myriad360 • New York (NY)

On-site
USD 150,000 - 160,000
Unlimited Paid Time Off (PTO)
Company-funded 401k contributions
Zero-cost employer-covered health insurance
+2
Senior Software Support Specialist
Senior Software Support Specialist

Kinective • Gilbert (AZ), Northern (KY)

Hybrid
USD 65,000 - 90,000
Generous PTO
Medical, dental, vision
Pet insurance
Senior Manager, Client Success
Senior Manager, Client Success

Kinective • Gilbert (AZ)

On-site
USD 105,000 - 125,000
Comprehensive health coverage
Flexible PTO
11 company holidays
+3
Project Manager
Project Manager

Kinective • Gilbert (AZ), Northern (KY)

Hybrid
USD 60,000 - 85,000
Health coverage
Flexible PTO
Company holidays
+3
Senior Network Development Engineer New Denver, CO (Hybrid)
Senior Network Development Engineer New Denver, CO (Hybrid)

Simplesense Inc. • Denver (CO), Northern (KY)

On-site
USD 155,000 - 195,000
Equity
Medical insurance
Life insurance
+5
Cloud Network Engineer
Cloud Network Engineer

Meduit | Driving Revenue Cycle Performance • Charlotte (NC)

On-site
USD 95,000 - 115,000
Medical, dental, and vision insurance
HSA and FSA available
401(k) with company match
+2
Security Automation Engineer, 18-month Term
Security Automation Engineer, 18-month Term

BlackCube Labs • United States

Hybrid
USD 100,000 - 130,000
Flexible vacation and Kinaxis Days
Physical and mental well-being programs
Mentorship programs
Modern Workplace Solutions Engineer
Modern Workplace Solutions Engineer

Rkon Inc • Chicago (IL)

On-site
USD 145,000 - 185,000
Health insurance
Flexible time off
401(k) plan with employer match