| Job Description: |
Skills: Digital: Terraform~Google Cloud Network and Connectivity Experience Required: 6-8
Top 3 Required Skills: 1. Cloud Network Engineer 2. Terraform Knowledge 3. CI/CD pipeline
Design, implement, secure, and operate cloud networking (VPC/VNet, hybrid connectivity, routing, firewalls, private access, load balancing) with a strong focus on Infrastructure as Code (IaC) using Terraform. Ensure high availability, compliance, observability, and cost efficiency across environments (Dev → Prod).
Core Responsibilities: 1) Cloud Network Architecture & Design- Design VPC/VNet topologies: CIDR planning, subnets, route tables, NAT/IGW/ER/Direct Connect, DNS (public/private). Define hybrid connectivity: Site‑to‑Site VPN, ExpressRoute/Direct Connect, Transit architectures, SD‑WAN integration. Architect resilient and secure network paths (multi‑AZ/region, hub‑and‑spoke, segmentation/micro‑segmentation). Produce HLD/LLD, network diagrams, decision logs, and reference patterns aligned to enterprise standards.
2) Implementation & Configuration (Azure / AWS)- Build and configure: Azure: VNets, Subnets, NSGs, UDRs, Azure Firewall, Application Gateway/WAF, Private Endpoints, Route Server. AWS: VPCs, Subnets, Route Tables, IGW/NAT, Security Groups/NACLs, ALB/NLB, Transit Gateway, PrivateLink. (GCP as applicable: VPCs, firewall rules, Cloud Router, Cloud NAT, load balancing) Implement DNS (Azure DNS/Route 53/Cloud DNS), IPAM hygiene, and name resolution across hybrid.
3) Security & Compliance by Design- Enforce least privilege and network segmentation, zero‑trust patterns, and WAF/DDoS protections. Implement private access patterns (Private Link/Private Endpoints/Service Endpoints) to avoid public exposure. Partner with security/GRC for threat modeling, control mapping, evidence collection, and remediation.
4) Operations, Monitoring & Troubleshooting- Enable observability: VPC Flow Logs / NSG Flow Logs, Network Watcher, CloudWatch/CloudTrail, Log Analytics; build dashboards and alerts. Troubleshoot latency, packet loss, asymmetric routing, MTU/MSS, and TLS/WAF issues. Participate in incident, problem, and change management with clear runbooks and post‑incident reviews.
5) Infrastructure as Code (Terraform‑First)- Author and maintain Terraform modules for reusable network patterns (VPC/VNet, TGW, firewalls, private endpoints). Implement environment promotion via workspaces or pipelines; parameterize with tfvars. Enforce state management (remote backend, state locking), versioning, code reviews, and policy as code (Sentinel/OPA). Integrate Terraform in CI/CD pipelines (Azure DevOps/GitHub Actions/GitLab/Jenkins) with plan/apply gates and approvals. |