Brak wyników spełniających kryteria wyszukiwania.
Senior Cloud Network Engineer (Automation / IaC)
Full-time B2B | Remote EU / Poland | Financial Services Context
We are an AI-native data and technology partner for private capital and healthcare. Founded in 2010 and headquartered in Warsaw, we work with leading PE firms, VC funds, and healthcare organizations to build proprietary data infrastructure, deploy AI solutions, and drive AI-native transformation.
Our clients manage a cumulative $1.2T+ in assets. Our average engagement runs five years. Our NPS sits above 80. We don't need to claim credibility – we can show it.
We've also done to ourselves what we now do for clients. We've restructured our own company around AI – tools, policies, roles, delivery models. This isn't a pitch. It's a playbook we've already run, and we're hiring the engineers who will run it for others.
The Opportunity
A leading global alternative asset management firm is looking for a Senior Cloud Network Engineer to own cloud networking at scale – across ~300 AWS accounts and thousands of VPCs, spanning multiple regions. This is a hands-on role at the boundary between Platform Engineering and Networking: the person who translates network requirements into infrastructure code, drives active migration programmes, and builds the reusable patterns every engineering team provisions their networks against.
The team already has strong network engineers and strong DevOps engineers. What's missing is the person who bridges the two – deep enough in AWS networking to hold their own with the Head of Networking, and fluent enough in Terraform and IaC to make that knowledge repeatable.
The environment is AWS-first with no on-premises data centres. You'll work with AWS Cloud WAN (an active TGW → Cloud WAN migration is in flight), AWS Network Firewall, and a centralized firewall programme replacing the legacy NACL model. You won't be designing networks in Visio – you'll be writing Terraform and deriving firewall rules from VPC Flow Log analysis.
What You'll Own
Drive the active Transit Gateway → AWS Cloud WAN migration – ~10 segments, tag-based segmentation, phased TGW decommission; already in flight and needs an engineer who can own it to completion
Lead the centralized firewall programme replacing the NACL model – policing cross-account traffic, analysing VPC Flow Logs in S3 to derive firewall rules, and managing change control at scale
Operate and evolve the hybrid firewall architecture: AWS Network Firewall for east-west traffic alongside NGFWs via Gateway Load Balancers; understand and maintain the boundary between them
Build and maintain a Terraform module library for network provisioning (VPC layouts, routing, firewall policies, Cloud WAN policies) consumed across the org via GitHub / GitHub Enterprise
Own IP address management via AWS IPAM at 400+ account scale, supporting account-vending workflows
Support DNS (Route 53 + inbound resolvers to Active Directory) and Direct Connect (NY primary, Virginia POP failover, four-nines target)
Act as the primary technical bridge between Platform Engineering and Networking – turning routing requirements, security standards, and network architecture into IaC both sides can operate and trust
Requirements
Deep, hands-on AWS networking at multi-account scale: VPC design, routing, security groups, Transit Gateway, PrivateLink, IPAM
Conceptual understanding of AWS Cloud WAN – core network policy documents, segments, tag-based routing, multi-region/multi-account topologies; hands-on production or migration experience a plus
Centralized firewall & traffic inspection – stateful/stateless rule groups, east-west inspection, centralized policy management; AWS Network Firewall, Palo Alto NGFW (via GWLB), or comparable vendors all count equally
Strong Terraform / IaC at scale – module design, state management, plan/apply, versioning, remote backends (real depth, not just consuming modules) – via GitHub / GitHub Enterprise
Data-driven network automation – ability to query VPC Flow Logs in S3 (Athena, Python/pandas, or equivalent) and translate traffic patterns into firewall rule changes; this is where purely traditional network engineers fall short
Cross-domain fluency – comfortable with pull-request reviews and BGP/routing discussions in the same week; familiarity with CI/CD for infrastructure and policy-as-code (OPA, Sentinel, or AWS Config); change-management discipline for high-blast-radius changes
Solid spoken English for peer-level technical discussion with the client
Nice to Have
SD-WAN experience – Palo Alto Prisma SD-WAN is a plus; equivalent platforms (Cisco Viptela/Meraki, VeloCloud, Aviatrix) are equally welcome3
Direct Connect / BGP, Route 53 hybrid DNS, PrivateLink at scale, ZScaler client-access integration
AWS certifications: Advanced Networking Specialty or Solutions Architect Professional
AWS Control Tower or Landing Zone Accelerator for network account vending
GitOps workflows for infrastructure (Atlantis, ArgoCD, or equivalent)
Exposure to VPC Lattice / application networking (the client has evaluated it and may revisit)
Background in financial services or regulated industries where segmentation, audit trails, and change control are compliance requirements, not preferences
Benefits
Unrestricted AI Stack & Premium Gear: Fully paid licenses for Cursor, Claude Pro, etc.
Total Autonomy (Remote-First): No filler meetings, no Jira bloat, no micromanagement. You own the workflow. We care about shipped systems in production, not logged hours.
Direct Impact: You’ll work face-to-face with our CEO, CTO & VPs and VC/PE General Partners.
Frontier Engineering Culture: Build alongside elite engineers who are shipping systems that drive real investment decisions. Backed by continuous growth and a strong knowledge-sharing culture ().
Sounds like a perfect place for you? Don’t hesitate to click apply and submit your application today!
Zainteresowany ofertą?
Aplikuj już teraz!