A

Senior Cloud and Network Security Engineer

Arcadian Data

Remote · Full Time

Be the first to apply

Experience
10+ yrs
Salary
Openings
1
Posted
3 days ago
Work mode
Work from home
Education
Bachelor's degree or equivalent
Resume
Required to apply

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

Position Overview

We are looking for a Senior Cloud and Network Security Engineer with a minimum of 10 years of expertise to design, deploy, and maintain secure network infrastructures within Microsoft Azure and hybrid on-premises environments. This position involves architectural design with active engineering roles focused on DNS, VPNs, Azure Private Endpoints, proxies, and firewall management.

Primary Responsibilities

  • Architect secure end-to-end network solutions for Azure and hybrid cloud environments, adhering to enterprise security policies and project goals.
  • Create detailed high- and low-level network designs including diagrams, IP schemes, traffic mappings, and firewall configurations.
  • Define segmentation, routing, access controls, and connections between cloud and on-premises systems.
  • Assess proposed network solutions for security risks and recommend appropriate mitigations.
  • Collaborate with architects, cybersecurity and infrastructure teams, application specialists, and vendors to deliver projects.
  • Manage Azure networking components such as VNets, subnets, peering, route tables, NSGs, and ASGs.
  • Implement and maintain Azure Private Endpoints with DNS configurations and access control.
  • Configure and troubleshoot Azure DNS solutions, including Private DNS Zones and hybrid DNS resolution.
  • Set up and manage VPN solutions and ExpressRoute connections for secure hybrid access.
  • Deploy and oversee Azure Firewall, virtual appliances, NAT Gateway, and application firewalls.
  • Design hub-and-spoke or Virtual WAN Azure architectures with centralized inspections and outbound filtering.
  • Maintain on-premises firewalls, proxies, and secure gateways including rules, NAT, routing, VPNs, and logging.
  • Administer enterprise proxies and secure web gateways covering authentication, filtering, allowlists, and TLS inspection.
  • Ensure secure hybrid connectivity among Azure, corporate networks, third-party services, and remote users.
  • Troubleshoot complex network issues including DNS, routing, asymmetric flows, firewall policies, proxies, certificates, and VPNs.
  • Regularly audit firewall and proxy rules to enforce least-privilege access and remove unnecessary permissions.
  • Monitor network performance and security with enterprise tools and Azure monitoring solutions.
  • Assist in incident investigations and root cause analyses for network security events.
  • Apply changes through formal change control processes with impact evaluation, testing, and rollback strategies.
  • Automate network and security configurations using Infrastructure as Code tools like Terraform, Bicep, PowerShell, or Azure CLI.
  • Maintain thorough documentation including configurations, operational procedures, standards, and project handover materials.
  • Test and verify network resilience and failover mechanisms for critical infrastructure components.

Experience and Technical Qualifications

  • At least 10 years of relevant experience in network engineering, network security, or infrastructure security roles.
  • Deep practical experience designing and implementing Azure networking and security in enterprise settings.
  • Successful deployment of hybrid cloud architectures integrating Azure with on-premises networks.
  • Expertise in DNS, TCP/IP, subnetting, routing protocols including BGP, NAT, IPsec VPNs, and TLS.
  • Hands-on experience configuring Azure Private Endpoints and troubleshooting hybrid private DNS challenges.
  • Proficiency with enterprise firewall platforms such as Palo Alto Networks, Fortinet, Check Point, or Cisco.
  • Experience managing enterprise proxy solutions or secure web gateways including connectivity troubleshooting.
  • Strong knowledge of network segmentation, Zero Trust models, least-privilege strategies, and defense-in-depth methods.
  • Proficient with Infrastructure as Code tools (Terraform, Azure Bicep) for provisioning and managing Azure network and security resources.
  • Experience developing reusable IaC modules, version-controlled configurations, and automated CI/CD deployments.
  • Excellent documentation skills and ability to lead multiple projects technically.
  • Strong problem-solving, communication, and stakeholder engagement abilities.

Educational and Certification Requirements

  • Bachelor's degree in Computer Science, IT, Engineering, or related field; or equivalent professional experience.
  • Mandatory certification: Microsoft Certified: Azure Network Engineer Associate (AZ-700).
  • Preferred certifications: Additional Microsoft Azure architecture or cloud security credentials.
  • Advantageous certifications: CCNP, CCIE, CISSP, or vendor-specific firewall certifications.

Professional Competencies and Soft Skills

  • Strong stakeholder influence to secure buy-in on security architecture decisions.
  • Capability to embed cloud infrastructure and network security best practices into projects and operations.
  • Effective communication of technical concepts and risks to both technical and non-technical personnel.
  • Collaborative approach across cybersecurity, infrastructure, application, and vendor teams.
  • Ownership from design through implementation and support with risk mitigation.
  • Judicious problem-solving balancing security, reliability, cost, and business needs.
  • Constructive challenging of insecure or impractical approaches with pragmatic alternatives.
  • Commitment to mentoring and knowledge sharing within teams.

Additional Desired Experience

  • Supporting secure connectivity for enterprise apps, data platforms, and AI services.
  • Experience working within regulated or large organizations with formal security governance.
  • Integration of network and firewall logs with centralized monitoring and SIEM systems.
  • Designing highly available connectivity solutions and supporting disaster recovery drills.

Minimum education

Bachelor's Degree

How they work

Communication Teamwork & Collaboration Problem Solving Relationship Building Accountability

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help
Broxer