Senior Infrastructure Engineer; Cloud Networking & Automation AWS cloud WAN, AWS Networki
Listed on 2026-06-04
-
IT/Tech
Cloud Computing, Systems Engineer
With over 20 years of experience, our global network of passionate technologists and pioneering craftsmen deliver cutting-edge technology and game-changing consulting to companies on the brink of transformation. Since 2001, we have grown from a Java company into a full-service digital consulting company with 4500+ professionals working on a worldwide ambition.
We are organized in complementary chapters – teams with a tremendous amount of knowledge and experience within a particular field, such as Agile, Dev Ops, Data and AI, Cloud, Software Technology, Functional Programming, Low Code, and Microsoft.
We help the world’s top 250 companies and category leaders overcome digital challenges, embrace innovation, adopt new technology, and implement new business models. In addition to high-quality consulting, we also provide offshoring and nearshoring services.
For more details please visit
Job Title:
Senior Infrastructure Engineer (Cloud Networking & Automation) with AWS cloud WAN, AWS Networking and Terraform Experience (10+ Year experience required)
Location:
United states, remote
Job Description :
-
You aren’t just managing a network; you are building a "Destination Platform" for 3,000+ developers. Our goal is to move from "weeks to provision an account" to "minutes to go live." You will architect the global nervous system of a Greenfield AWS environment built for Mission Critical workloads, ensuring that high-security networking is a seamless, automated experience for every development team.
The "Lane":Your Responsibilities
- Architect Global Connectivity: Lead the design and implementation of our global backbone using AWS Cloud WAN (or Transit Gateway for legacy/unsupported regions) to create a unified, multi-region architecture.
- Automate Everything: Use Terraform Enterprise to build "Golden Networking Modules." Developers shouldn't have to learn BGP or VPC Peering—they should "shop" for a pre-configured, secure network stack from our portal.
- Mission Critical Security: Partner with Frey to map NIST 800-53 r5 controls to our network. You will implement centralized egress/ingress points using AWS Network Firewall and WAF
, ensuring no "Public S3" or unlogged traffic ever reaches production. - Self-Service SDN: Build the automation that allows a Slack Agent to trigger the creation of a cross-account, multi-region network environment with zero manual intervention.
- High Availability & DR: Implement AWS ARC (Application Recovery Controller) to ensure our network can handle regional failovers with a single "push of a button."
- Advanced AWS Networking: Mastery of VPC, Transit Gateway (TGW), AWS RAM, and AWS Private Link
. While we know Cloud WAN is rare, you should have the foundational SDN knowledge to master it quickly. - Security First: Hands-on experience with AWS Network Firewall
, Route 53 Resolver DNS Firewall
, and Shield
. You understand how to centralize security without creating bottlenecks. - Infrastructure as Code: Expert-level Terraform skills. You don't just write scripts; you build reusable, tested modules that other teams consume.
- The "Generalist" Plus: While networking is your focus, you are comfortable in a Serverless/Fargate environment. We are a platform team, not an ops team; we don't manage Kubernetes, we manage services.
- Compliance Mindset: Experience working in regulated environments (Fin Tech, Gov Cloud, etc.) where NIST
, SOC2
, or FedRAMP standards are the baseline.
- No Task-Lists: We don't have 100 JIRA tickets waiting for you. You need to be a Builder who can identify a problem (like complex egress routing) and fix it before it blocks a developer.
- Direct & Transparent: We value the "New York" style of communication—be direct, be opinionated, and don't mince words. If a design won't scale, say so.
- The "Events App" Sprint: Our first internal customer is the Dream force Events App
. You'll need to deliver a networking MVP by March/April that is "secure by default" but flexible enough for a high-speed launch.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).