660,302open jobs
38,440companies
97,349added this week
Browse all
Salary
$29k – $66k per year (Estimated)
Location
In office (Bengaluru)
Seniority
Senior · 12+ years exp
Overview
Company
Impact
Profile match
American Express is a New York financial services company founded in 1850 as an express freight business that became a payments network and card issuer. Unlike the four-party networks it competes with, it issues most of its own cards and operates its own network, which lets it earn merchant discount revenue as well as interest and annual fees, and supports a premium rewards proposition built on travel and lounge access. Its business spans consumer and small business cards, corporate payments, merchant acquiring and travel services, and it is a component of the Dow Jones Industrial Average.

Enterprise Cloud under Global Infrastructure is seeking a highly experienced Senior Multi-Cloud Network Engineer to design, build, secure, automate, and operate enterprise-scale cloud network fabrics across Amazon Web Services (AWS) and Google Cloud Platform (GCP).

The ideal candidate will have deep hands-on experience building complex cloud network architectures across both AWS and GCP, including multi-account/multi-project environments, hybrid connectivity, inter-cloud connectivity, network segmentation, routing, DNS, traffic inspection, and centralized security controls. This role requires strong foundational networking expertise combined with practical knowledge of how AWS and GCP implement networking differently.

The successful candidate will design cloud networks that are secure by design, highly available, scalable, observable, automated, and resilient, applying least privilege, Zero Trust, defense-in-depth, segmentation, and policy-driven infrastructure principles.

What Success Looks Like

  • Design and build enterprise-grade AWS and GCP network fabrics from the ground up.
  • Design networking based on sound engineering principles rather than simply connecting cloud resources.
  • Explain end-to-end packet flows across AWS, GCP, on-premises, and security infrastructure.
  • Design scalable routing and segmentation models across hundreds of cloud accounts/projects and VPCs.
  • Build highly resilient hybrid and multi-cloud connectivity architectures.
  • Implement secure network boundaries without unnecessary operational complexity.
  • Make informed decisions between native AWS, native GCP, and third-party networking capabilities.
  • Automate network infrastructure, build comprehensive observability, and diagnose complex problems at both the architecture and packet level.
  • Balance security, resiliency, scalability, performance, operability, and cost in architecture decisions.

Multi-Cloud Network Architecture & Engineering

  • Design, build, and operate enterprise-scale cloud network fabrics across AWS and GCP.
  • Develop architectures supporting multiple AWS accounts, GCP projects, business units, application environments, regions, and hybrid data centers.
  • Define standardized multi-cloud connectivity patterns covering cloud-to-cloud, cloud-to-data-center, application-to-application, internet ingress/egress, east-west traffic, shared services, private service connectivity, and centralized traffic inspection.
  • Design scalable routing, segmentation, IP addressing, DNS, and connectivity strategies across AWS and GCP.
  • Develop multi-region architectures with appropriate availability, redundancy, failover, route convergence, and disaster recovery characteristics.
  • Evaluate architecture trade-offs across cloud-native networking services based on security, scalability, performance, resiliency, operational complexity, and cost.

AWS Network Fabric

  • Design and engineer AWS networking using Amazon VPC, Transit Gateway, Cloud WAN, Direct Connect, Site-to-Site VPN, Transit Gateway Connect, VPC Peering, PrivateLink/VPC Endpoints, Network Firewall, Firewall Manager, Route 53/Resolver, DNS Firewall, Elastic Load Balancing, Global Accelerator, VPC IPAM, and flow logs.
  • Design network architectures for complex multi-account and multi-region AWS environments, including centralized and distributed connectivity and security models.

GCP Network Fabric

  • Design and engineer GCP networking using Google Cloud VPC, Shared VPC, VPC Network Peering, Network Connectivity Center (NCC), Cloud Router, Cloud Interconnect, Partner Interconnect, HA VPN, Private Service Connect, Private Google Access, Cloud NAT, Cloud DNS, Cloud Load Balancing, Cloud Armor, Firewall Policies, Network Intelligence Center, and VPC Flow Logs.
  • Design network architectures supporting multi-project, multi-region, and Shared VPC environments, with appropriate separation between host projects, service projects, shared services, security controls, and application workloads.

Hybrid & Inter-Cloud Connectivity

  • Design highly available connectivity between AWS, GCP, enterprise data centers, colocation facilities, and third-party environments.
  • Design and operate architectures utilizing AWS Direct Connect and Google Cloud Interconnect.
  • Engineer resilient BGP-based routing across cloud and on-premises environments and VPN-based connectivity for primary, secondary, and contingency use cases.
  • Develop secure connectivity patterns between AWS and GCP while avoiding unnecessary internet exposure.
  • Understand and mitigate asymmetric routing, overlapping IP space, route propagation, route preference, MTU, NAT, DNS, and stateful security-device challenges.
  • Develop routing strategies that prevent unintended transit paths and connectivity between security zones, with clear failure domains and predictable failover behavior.

Cloud Network Security

  • Design cloud network architectures using security-by-design and Zero Trust principles.
  • Implement segmentation based on application, environment, business function, data classification, and trust boundaries.
  • Design centralized and distributed firewall architectures and secure ingress, egress, east-west, and inter-cloud traffic patterns.
  • Implement appropriate traffic inspection and security enforcement points; apply least-privilege connectivity and minimize unnecessary network reachability.
  • Design private access patterns using AWS PrivateLink/VPC Endpoints, GCP Private Service Connect, and Private Google Access.
  • Implement controls using AWS Security Groups, NACLs, Network Firewall; GCP VPC Firewall Rules/Policies, Cloud Armor; DNS security controls; and third-party NGFW technologies where appropriate.
  • Partner with cybersecurity teams to translate security standards into enforceable cloud network controls.
  • Identify excessive connectivity, unintended routing paths, insecure internet exposure, and weaknesses in segmentation or firewall policies.
  • Incorporate logging, monitoring, detection, and auditability into network architecture from the outset.

Routing, DNS & IP Address Management

  • Demonstrate expert-level understanding of TCP/IP, IPv4/IPv6, BGP, DNS, NAT, CIDR/subnetting, route summarization, route propagation, route preference, ECMP, and stateful/stateless filtering.
  • Develop enterprise-scale IP Address Management (IPAM) strategies spanning AWS, GCP, and on-premises environments.
  • Prevent and remediate overlapping address-space issues across cloud environments.
  • Design hybrid DNS architectures spanning AWS Route 53, GCP Cloud DNS, and enterprise DNS infrastructure.
  • Understand provider-specific routing behavior and diagnose complex routing issues across cloud boundaries.

Infrastructure as Code & Automation

  • Build and manage cloud networking using Infrastructure as Code (IaC) rather than manual configuration.
  • Develop reusable networking modules and patterns using Terraform, AWS CloudFormation/CDK, Google Cloud Infrastructure Manager or equivalent tooling, Python, and Ansible.
  • Integrate network infrastructure deployments into CI/CD pipelines and implement automated validation, testing, compliance, and policy enforcement.
  • Develop guardrails to prevent insecure or non-standard network configurations.
  • Promote repeatable, version-controlled, auditable deployments and automate routine network operations, configuration validation, route analysis, and compliance checks.

Network Observability & Troubleshooting

  • Establish comprehensive network observability across AWS and GCP using VPC/TGW Flow Logs, CloudWatch, Reachability Analyzer, Network Manager, GCP VPC Flow Logs, Cloud Logging/Monitoring, Network Intelligence Center, and Connectivity Tests.
  • Diagnose complex connectivity problems across cloud, hybrid, and inter-cloud environments.
  • Perform end-to-end packet-flow analysis through routing, NAT, firewalls, load balancers, private endpoints, VPNs, and hybrid connectivity.
  • Troubleshoot BGP advertisements, route propagation, asymmetric routing, DNS resolution, MTU issues, firewall policies, and application connectivity.
  • Lead root-cause analysis for major cloud networking incidents and implement permanent corrective actions.

Technical Leadership

  • Serve as a senior technical authority for cloud networking across AWS and GCP.
  • Develop cloud network reference architectures, engineering standards, design patterns, and guardrails.
  • Conduct architecture and design reviews for new cloud connectivity requirements.
  • Provide technical guidance to application, platform, SRE, infrastructure, and cybersecurity teams.
  • Challenge architecture proposals where network complexity, security exposure, scalability, or operational risk is unnecessary.
  • Mentor engineers and translate complex networking concepts into clear architectural decisions for technical and non-technical stakeholders.

Required Qualifications

  • Significant professional experience (10-12+ YOE) in network engineering, including substantial hands-on experience with public cloud networking.
  • Demonstrated experience designing and implementing enterprise-scale AWS and GCP network architectures.
  • Deep practical knowledge (7-8+ YOE) of TCP/IP, BGP, DNS, NAT, routing, VPN, firewalls, load balancing, and network segmentation.
  • Strong hands-on AWS experience (4-5+ YOE) with VPC, Transit Gateway, Direct Connect, PrivateLink, Route 53, VPN, and AWS Network Firewall.
  • Strong hands-on GCP experience (4-5+ YOE) with VPC, Shared VPC, Network Connectivity Center, Cloud Router, Cloud Interconnect, HA VPN, Private Service Connect, Cloud DNS, and Firewall Policies.
  • Experience designing hybrid connectivity between public cloud environments and enterprise data centers, and secure connectivity between cloud providers.
  • Strong understanding of cloud network security architecture, segmentation, firewalling, traffic inspection, private connectivity, and secure ingress/egress patterns.
  • Strong Infrastructure as Code experience (3-4+ YOE), preferably using Terraform, with CI/CD and automated deployment practices.
  • Advanced troubleshooting skills with the ability to trace application traffic across multiple network and security layers.
  • Ability to communicate complex cloud network architecture to engineers, architects, cybersecurity teams, and senior technology stakeholders.

Preferred Qualifications

  • Experience building large-scale AWS multi-account environments and GCP multi-project/Shared VPC environments.
  • Experience with AWS Transit Gateway, AWS Cloud WAN, and GCP Network Connectivity Center at enterprise scale.
  • Experience integrating AWS Direct Connect and Google Cloud Interconnect with enterprise WAN environments.
  • Experience designing multi-cloud connectivity using SD-WAN or cloud networking platforms.
  • Experience with Palo Alto Networks, Fortinet, Cisco, Check Point, Aviatrix, or equivalent technologies.
  • Experience with enterprise IPAM/DNS platforms and regulated, security-sensitive, or compliance-driven cloud environments.
  • Familiarity with Zero Trust, NIST, CIS Benchmarks, AWS Well-Architected Framework, and Google Cloud Architecture Framework.
  • Relevant certifications such as AWS Certified Advanced Networking - Specialty, AWS Solutions Architect - Professional, Google Cloud Professional Cloud Network Engineer, Google Cloud Professional Cloud Architect, AWS Security - Specialty, CCNP/CCIE, or CISSP are advantageous.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
660,302 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Bengaluru
Cloud Engineer III 9 hours ago
$76k – $160k per year (Estimated) • Remote/Hybrid • Full-Time • 3+ years exp • Bachelor's Degree • Cleveland
AI/ML
AWS Bedrock
Amazon SageMaker
DevOps
Terraform
Puppet
Ansible
GCP
Chef
Azure
AWS
Apply
$77k – $156k per year (Estimated) • Remote/Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • Belfast
Python
JavaScript
Ruby
PowerShell
C#
C++
Node JS
Bash
Groovy
DevOps
GCP
Prometheus
CI/CD
Windows Server
Jenkins
AWS
Kubernetes
Ubuntu
Grafana
Shift-Left
GitLab
Amazon CloudWatch
Cybersecurity
Shift-Left Security
Management
Agile
Apply
$119k – $150k per year • Equity • In office • Full-Time • 5+ years exp • Boston
Python
JavaScript
Python
Flask
SQLAlchemy
FastAPI
Django
AI/ML
Copilot
Cursor
Claude Code
Frontend
Vue.js
Svelte
React.js
DevOps
Rest API
GitLab CI
CI/CD
Jenkins
AWS
Docker
Kubernetes
Apply
AI Engineer 9 hours ago
$122k – $195k per year • Equity • In office • Full-Time • 4+ years exp • Bachelor's Degree • Cambridge
Python
JavaScript
TypeScript
SQL
Node JS
Scala
Databases
Delta Lake
AI/ML
MLFlow
Embeddings
Function Calling
LLM
RAG
LLMOps
Human-in-the-Loop
LLM Guardrails
Agentic Workflows
Tool Use
Frontend
Vue.js
Svelte
GraphQL
Angular
React.js
DevOps
CI/CD
Vector
Apply
$42k – $97k per year (Estimated) • Remote • Full-Time • Vélizy-Villacoublay
DevOps
Ansible
Management
Agile
Scrum
Kanban
Apply
$109k – $234k per year (Estimated) • In office • 7+ years exp • Atlanta
Databases
Amazon Redshift
AI/ML
Copilot
ChatGPT
Replit
Mobile
Lottie
Design
Blender
Figma
Adobe After Effects
Cinema 4D
Rive
Apply
$83k – $191k per year (Estimated) • In office • New York
SQL
SAS
Apply
$125k – $225k per year (Estimated) • In office • 7+ years exp • Phoenix
AI/ML
Model Context Protocol
AI Agents
LLM Guardrails
DevOps
Terraform
GCP
OpenTofu
Kong
Azure
CI/CD
AWS
Kubernetes
Service Mesh
Amazon EKS
Google GKE
Azure AKS
FinOps
IAM
API Gateway
Cybersecurity
Zero Trust
Defense in Depth
Least Privilege
Apply
$110k – $218k per year (Estimated) • In office • 4+ years exp • Bachelor's Degree • New York
Python
Go
JavaScript
Databases
Redis
Cassandra
Couchbase
AI/ML
Prompt Engineering
LLM
OCR
Frontend
Next.js
React.js
DevOps
gRPC
OpenShift
Consul
Envoy
Jenkins
Docker
Kubernetes
Service Mesh
Management
Agile
Apply
$69k – $152k per year (Estimated) • In office • 1+ year exp • Bachelor's Degree • Phoenix
Python
Java
SQL
Management
Agile
Scrum
Apply
$20k – $54k per year (Estimated) • In office • Full-Time • 3+ years exp • Bengaluru
Python
Java
PowerShell
DevOps
Terraform
Ansible
Azure DevOps
GitHub Actions
GitLab CI
Azure
CI/CD
Jenkins
AWS
QA
Pytest
Apply
$36k – $81k per year (Estimated) • In office • Full-Time • 8+ years exp • Bengaluru
Python
Java
C#
AI/ML
Copilot
Cursor
Claude
DevOps
Terraform
Ansible
CI/CD
Docker
Platform Engineering
GitHub
Apply
$27k – $63k per year (Estimated) • Remote/Hybrid • Full-Time • 8+ years exp • Bachelor's Degree • Bengaluru
JavaScript
TypeScript
SQL
C#
C++
C#
ASP.NET Core
Databases
PostgreSQL
Redis
RabbitMQ
Apache Kafka
OpenSearch
Frontend
Angular
DevOps
Self-Healing
Apply
$48k – $98k per year (Estimated) • Remote • Full-Time • 15+ years exp • Bengaluru
Go
Java
C#
Databases
Apache Kafka
Mobile
Push Notifications
DevOps
gRPC
GCP
Azure
AWS
Apply
SDE 3 8 hours ago
$25k – $57k per year (Estimated) • In office • 7+ years exp • Bengaluru
Python
JavaScript
Java
Python
Django
Databases
PostgreSQL
Frontend
React.js
DevOps
GCP
CI/CD
Apply
See all jobs
This is one of many
660,302 more open roles from verified company boards, updated every day.