
Senior Cloud Network Engineer β Automation, IaC
Posted Jul 27

Posted Jul 27
This is a fully remote position, open to applicants in Poland.
β’ Lead the active **Transit Gateway β AWS Cloud WAN migration** β approximately 10 segments, implementing tag-based segmentation, and gradually decommissioning TGW; this project is already in progress and requires an engineer to take ownership until completion.
β’ Spearhead the **centralized firewall program** that replaces the NACL model β overseeing cross-account traffic management, analyzing VPC Flow Logs in S3 to develop firewall rules, and managing large-scale change control.
β’ Manage and enhance the **hybrid firewall architecture**: utilizing AWS Network Firewall for east-west traffic alongside NGFWs through Gateway Load Balancers; ensure a clear understanding and maintenance of the boundary between these systems.
β’ Develop and sustain a **Terraform module library** for network provisioning (including VPC layouts, routing, firewall policies, and Cloud WAN policies) that is utilized across the organization via GitHub / GitHub Enterprise.
β’ Oversee **IP address management via AWS IPAM** on a scale of 400+ accounts, facilitating account-vending workflows.
β’ Provide support for **DNS** (Route 53 and inbound resolvers to Active Directory) and **Direct Connect** (primary in NY, failover in Virginia, targeting four-nines availability).
β’ Serve as the primary technical liaison between Platform Engineering and Networking β translating routing requirements, security standards, and network architecture into Infrastructure as Code (IaC) that both teams can implement and trust.
β’ Extensive, hands-on experience with **AWS networking at a multi-account scale**: including VPC design, routing, security groups, Transit Gateway, PrivateLink, and IPAM.
β’ **Conceptual understanding of AWS Cloud WAN** β including core network policy documents, segments, tag-based routing, and multi-region/multi-account topologies; practical production or migration experience is a plus.
β’ Familiarity with **centralized firewall & traffic inspection** β encompassing stateful/stateless rule groups, east-west traffic inspection, and centralized policy management; experience with AWS Network Firewall, Palo Alto NGFW (via GWLB), or equivalent vendors is acceptable.
β’ Proficient in **Terraform / IaC at scale** β including module design, state management, plan/apply, versioning, and remote backends (with real depth, not merely consuming modules) through GitHub / GitHub Enterprise.
β’ Expertise in **data-driven network automation** β ability to query VPC Flow Logs in S3 (using Athena, Python/pandas, or similar tools) and convert traffic patterns into firewall rule adjustments; this is an area where traditional network engineers may fall short.
β’ **Cross-domain fluency** β comfortable engaging in pull-request reviews and BGP/routing discussions within the same week; familiarity with CI/CD for infrastructure and policy-as-code (such as OPA, Sentinel, or AWS Config); disciplined change management for high-impact modifications.
β’ Strong spoken English skills for effective technical discussions with peers and clients.
β’ Unrestricted AI Stack & Premium Gear: Fully covered licenses for tools such as Cursor, Claude Pro, and more.
β’ Complete Autonomy (Remote-First): No unnecessary meetings, no Jira clutter, no micromanagement. You control your workflow. Our priority is on delivering functioning systems in production, not tracking hours logged.
β’ Direct Impact: Collaborate directly with our CEO, CTO, VPs, and VC/PE General Partners.
β’ Frontier Engineering Culture: Collaborate with top-tier engineers who are developing systems that influence real investment decisions. Supported by ongoing growth and a robust knowledge-sharing culture (check out our YouTube).
Granicus
Upgrade, Inc.
S4 Capital Group
NBCUniversal
Get handpicked remote jobs straight to your inbox weekly.