Enterprise Cloud under Global Infrastructure is seeking a highly experienced Senior Multi-Cloud Network Engineer to design, build, secure, automate, and operate enterprise-scale cloud network fabrics across Amazon Web Services (AWS) and Google Cloud Platform (GCP).
The ideal candidate will have deep hands-on experience building complex cloud network architectures across both AWS and GCP, including multi-account/multi-project environments, hybrid connectivity, inter-cloud connectivity, network segmentation, routing, DNS, traffic inspection, and centralized security controls. This role requires strong foundational networking expertise combined with practical knowledge of how AWS and GCP implement networking differently.
The successful candidate will design cloud networks that are secure by design, highly available, scalable, observable, automated, and resilient, applying least privilege, Zero Trust, defense-in-depth, segmentation, and policy-driven infrastructure principles.
What Success Looks Like
- Design and build enterprise-grade AWS and GCP network fabrics from the ground up.
- Design networking based on sound engineering principles rather than simply connecting cloud resources.
- Explain end-to-end packet flows across AWS, GCP, on-premises, and security infrastructure.
- Design scalable routing and segmentation models across hundreds of cloud accounts/projects and VPCs.
- Build highly resilient hybrid and multi-cloud connectivity architectures.
- Implement secure network boundaries without unnecessary operational complexity.
- Make informed decisions between native AWS, native GCP, and third-party networking capabilities.
- Automate network infrastructure, build comprehensive observability, and diagnose complex problems at both the architecture and packet level.
- Balance security, resiliency, scalability, performance, operability, and cost in architecture decisions.
Multi-Cloud Network Architecture & Engineering
- Design, build, and operate enterprise-scale cloud network fabrics across AWS and GCP.
- Develop architectures supporting multiple AWS accounts, GCP projects, business units, application environments, regions, and hybrid data centers.
- Define standardized multi-cloud connectivity patterns covering cloud-to-cloud, cloud-to-data-center, application-to-application, internet ingress/egress, east-west traffic, shared services, private service connectivity, and centralized traffic inspection.
- Design scalable routing, segmentation, IP addressing, DNS, and connectivity strategies across AWS and GCP.
- Develop multi-region architectures with appropriate availability, redundancy, failover, route convergence, and disaster recovery characteristics.
- Evaluate architecture trade-offs across cloud-native networking services based on security, scalability, performance, resiliency, operational complexity, and cost.
AWS Network Fabric
- Design and engineer AWS networking using Amazon VPC, Transit Gateway, Cloud WAN, Direct Connect, Site-to-Site VPN, Transit Gateway Connect, VPC Peering, PrivateLink/VPC Endpoints, Network Firewall, Firewall Manager, Route 53/Resolver, DNS Firewall, Elastic Load Balancing, Global Accelerator, VPC IPAM, and flow logs.
- Design network architectures for complex multi-account and multi-region AWS environments, including centralized and distributed connectivity and security models.
GCP Network Fabric
- Design and engineer GCP networking using Google Cloud VPC, Shared VPC, VPC Network Peering, Network Connectivity Center (NCC), Cloud Router, Cloud Interconnect, Partner Interconnect, HA VPN, Private Service Connect, Private Google Access, Cloud NAT, Cloud DNS, Cloud Load Balancing, Cloud Armor, Firewall Policies, Network Intelligence Center, and VPC Flow Logs.
- Design network architectures supporting multi-project, multi-region, and Shared VPC environments, with appropriate separation between host projects, service projects, shared services, security controls, and application workloads.
Hybrid & Inter-Cloud Connectivity
- Design highly available connectivity between AWS, GCP, enterprise data centers, colocation facilities, and third-party environments.
- Design and operate architectures utilizing AWS Direct Connect and Google Cloud Interconnect.
- Engineer resilient BGP-based routing across cloud and on-premises environments and VPN-based connectivity for primary, secondary, and contingency use cases.
- Develop secure connectivity patterns between AWS and GCP while avoiding unnecessary internet exposure.
- Understand and mitigate asymmetric routing, overlapping IP space, route propagation, route preference, MTU, NAT, DNS, and stateful security-device challenges.
- Develop routing strategies that prevent unintended transit paths and connectivity between security zones, with clear failure domains and predictable failover behavior.
Cloud Network Security
- Design cloud network architectures using security-by-design and Zero Trust principles.
- Implement segmentation based on application, environment, business function, data classification, and trust boundaries.
- Design centralized and distributed firewall architectures and secure ingress, egress, east-west, and inter-cloud traffic patterns.
- Implement appropriate traffic inspection and security enforcement points; apply least-privilege connectivity and minimize unnecessary network reachability.
- Design private access patterns using AWS PrivateLink/VPC Endpoints, GCP Private Service Connect, and Private Google Access.
- Implement controls using AWS Security Groups, NACLs, Network Firewall; GCP VPC Firewall Rules/Policies, Cloud Armor; DNS security controls; and third-party NGFW technologies where appropriate.
- Partner with cybersecurity teams to translate security standards into enforceable cloud network controls.
- Identify excessive connectivity, unintended routing paths, insecure internet exposure, and weaknesses in segmentation or firewall policies.
- Incorporate logging, monitoring, detection, and auditability into network architecture from the outset.
Routing, DNS & IP Address Management
- Demonstrate expert-level understanding of TCP/IP, IPv4/IPv6, BGP, DNS, NAT, CIDR/subnetting, route summarization, route propagation, route preference, ECMP, and stateful/stateless filtering.
- Develop enterprise-scale IP Address Management (IPAM) strategies spanning AWS, GCP, and on-premises environments.
- Prevent and remediate overlapping address-space issues across cloud environments.
- Design hybrid DNS architectures spanning AWS Route 53, GCP Cloud DNS, and enterprise DNS infrastructure.
- Understand provider-specific routing behavior and diagnose complex routing issues across cloud boundaries.
Infrastructure as Code & Automation
- Build and manage cloud networking using Infrastructure as Code (IaC) rather than manual configuration.
- Develop reusable networking modules and patterns using Terraform, AWS CloudFormation/CDK, Google Cloud Infrastructure Manager or equivalent tooling, Python, and Ansible.
- Integrate network infrastructure deployments into CI/CD pipelines and implement automated validation, testing, compliance, and policy enforcement.
- Develop guardrails to prevent insecure or non-standard network configurations.
- Promote repeatable, version-controlled, auditable deployments and automate routine network operations, configuration validation, route analysis, and compliance checks.
Network Observability & Troubleshooting
- Establish comprehensive network observability across AWS and GCP using VPC/TGW Flow Logs, CloudWatch, Reachability Analyzer, Network Manager, GCP VPC Flow Logs, Cloud Logging/Monitoring, Network Intelligence Center, and Connectivity Tests.
- Diagnose complex connectivity problems across cloud, hybrid, and inter-cloud environments.
- Perform end-to-end packet-flow analysis through routing, NAT, firewalls, load balancers, private endpoints, VPNs, and hybrid connectivity.
- Troubleshoot BGP advertisements, route propagation, asymmetric routing, DNS resolution, MTU issues, firewall policies, and application connectivity.
- Lead root-cause analysis for major cloud networking incidents and implement permanent corrective actions.
Technical Leadership
- Serve as a senior technical authority for cloud networking across AWS and GCP.
- Develop cloud network reference architectures, engineering standards, design patterns, and guardrails.
- Conduct architecture and design reviews for new cloud connectivity requirements.
- Provide technical guidance to application, platform, SRE, infrastructure, and cybersecurity teams.
- Challenge architecture proposals where network complexity, security exposure, scalability, or operational risk is unnecessary.
- Mentor engineers and translate complex networking concepts into clear architectural decisions for technical and non-technical stakeholders.
Required Qualifications
- Significant professional experience (10-12+ YOE) in network engineering, including substantial hands-on experience with public cloud networking.
- Demonstrated experience designing and implementing enterprise-scale AWS and GCP network architectures.
- Deep practical knowledge (7-8+ YOE) of TCP/IP, BGP, DNS, NAT, routing, VPN, firewalls, load balancing, and network segmentation.
- Strong hands-on AWS experience (4-5+ YOE) with VPC, Transit Gateway, Direct Connect, PrivateLink, Route 53, VPN, and AWS Network Firewall.
- Strong hands-on GCP experience (4-5+ YOE) with VPC, Shared VPC, Network Connectivity Center, Cloud Router, Cloud Interconnect, HA VPN, Private Service Connect, Cloud DNS, and Firewall Policies.
- Experience designing hybrid connectivity between public cloud environments and enterprise data centers, and secure connectivity between cloud providers.
- Strong understanding of cloud network security architecture, segmentation, firewalling, traffic inspection, private connectivity, and secure ingress/egress patterns.
- Strong Infrastructure as Code experience (3-4+ YOE), preferably using Terraform, with CI/CD and automated deployment practices.
- Advanced troubleshooting skills with the ability to trace application traffic across multiple network and security layers.
- Ability to communicate complex cloud network architecture to engineers, architects, cybersecurity teams, and senior technology stakeholders.
Preferred Qualifications
- Experience building large-scale AWS multi-account environments and GCP multi-project/Shared VPC environments.
- Experience with AWS Transit Gateway, AWS Cloud WAN, and GCP Network Connectivity Center at enterprise scale.
- Experience integrating AWS Direct Connect and Google Cloud Interconnect with enterprise WAN environments.
- Experience designing multi-cloud connectivity using SD-WAN or cloud networking platforms.
- Experience with Palo Alto Networks, Fortinet, Cisco, Check Point, Aviatrix, or equivalent technologies.
- Experience with enterprise IPAM/DNS platforms and regulated, security-sensitive, or compliance-driven cloud environments.
- Familiarity with Zero Trust, NIST, CIS Benchmarks, AWS Well-Architected Framework, and Google Cloud Architecture Framework.
- Relevant certifications such as AWS Certified Advanced Networking - Specialty, AWS Solutions Architect - Professional, Google Cloud Professional Cloud Network Engineer, Google Cloud Professional Cloud Architect, AWS Security - Specialty, CCNP/CCIE, or CISSP are advantageous.

