{"id":1299300,"url":"https://alion.io/job/kinective-senior-cloud-network-engineer","title":"Senior Cloud Network Engineer","company":{"id":3178430,"name":"Kinective","domain":"kinective.io","url":"https://alion.io/company/kinective-io","size_band":"501-1000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Paylocity","truth_index":null},"role":"Networking","role_family":"Networking","seniority":"senior","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Golden, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":90000,"max_usd":197000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":223},"experience_years_min":5,"visa_sponsorship":true,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"BGP","optional":false},{"name":"CI/CD","optional":false},{"name":"DNS","optional":false},{"name":"Docker","optional":false},{"name":"IAM","optional":false},{"name":"OpenTofu","optional":false},{"name":"OSPF","optional":false},{"name":"PCI DSS","optional":false},{"name":"PowerShell","optional":false},{"name":"Python","optional":false},{"name":"SOC 2","optional":false},{"name":"TCP/IP","optional":false},{"name":"Tcpdump","optional":false},{"name":"Terraform","optional":false},{"name":"Threat Modeling","optional":false},{"name":"VPN","optional":false},{"name":"Wireshark","optional":false},{"name":"ChatGPT","optional":true},{"name":"Claude","optional":true},{"name":"Copilot","optional":true},{"name":"Cursor","optional":true},{"name":"Datadog","optional":true},{"name":"Dynatrace","optional":true},{"name":"GitHub Actions","optional":true},{"name":"Grafana","optional":true},{"name":"Kubernetes","optional":true},{"name":"Nagios","optional":true},{"name":"Service Mesh","optional":true},{"name":"Zero Trust","optional":true}],"status":"live","first_seen_at":"2026-09-08T18:31:45Z","employer_posted_date":"2026-09-26","last_verified_at":"2026-09-26T14:37:23Z","board_verified":false,"closed_at":null,"days_open":20,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":20},"description":"Description\nLead the Way to Intelligent Banking with Us!\nYou might not think about what happens behind the scenes when you check your bank balance or deposit a check from your phone, but we do. Every day.\nKinective empowers banks and credit unions to move beyond keeping up with technology to shaping the future of banking. Our platform seamlessly connects the right tools, delivers real-time data, and drives smarter operations for more than 4,000 financial institutions nationwide. We are a fast-growing team built on individual ownership, company-wide collaboration, and setting industry-leading standards. Here, new ideas are encouraged, candid feedback is welcomed, and your growth truly matters as much as the company’s. At Kinective, we are leading the way to intelligent banking together and enjoying the journey along the way.\nWhy This Role Matters\nEvery role at Kinective exists to move the needle for our clients, partners, and the financial institutions we serve. We are looking for a Senior Cloud Network Engineer at Kinective to own and evolve the networking backbone that powers our products and connects us to our customers. This is a product-facing role - not internal IT. You will design, build, and operate the cloud and customer-facing network infrastructure that directly impacts product reliability, security posture, and compliance standing.\nYou will work primarily across AWS with supporting Azure environments, manage VPN tunnel infrastructure for client connectivity, and play an active role in SOC 2 and PCI DSS audit readiness and evidence collection. This role requires someone who thinks in systems, communicates clearly across engineering, security, and customer teams, and takes ownership end-to-end. Everything we build is delivered as code - no click-ops in production.\nWhat you’ll own\nCloud & Product Networking\nDesign and operate network architectures across AWS (primary) and Azure, including VPCs, VNets, and Transit Gateways\nEnforce strict network segmentation between production and non-production environments - separate VPCs/VNets, distinct routing domains, and explicit deny-by-default posture\nManage routing, peering, and segmentation across multi-cloud environments to support product SLAs and security boundaries\nMaintain and optimize network performance, availability, and observability across cloud regions\nCollaborate with platform and infrastructure engineering teams to integrate networking into CI/CD pipelines and IaC workflows\nClient VPN & Secure Connectivity\nDesign, provision, and maintain IPsec and SSL/TLS VPN tunnels connecting product environments to enterprise clients\nOwn the full lifecycle of client tunnel onboarding - from technical scoping through cutover and steady-state support\nServe as the primary technical point of contact during client network onboarding and connectivity incidents; lead customer-facing troubleshooting calls and produce written RCAs when client connectivity is impaired\nTroubleshoot and resolve tunnel stability, latency, and routing issues in coordination with client network teams - including packet capture and side-by-side config review\nMaintain documentation for all client connectivity configurations, including IP schemas, tunnel parameters, and escalation paths\nSecurity & Compliance\nSupport SOC 2 (Type II) and PCI DSS audit cycles - collecting network evidence, remediating findings, and responding to auditor requests\nImplement and enforce network controls aligned to SOC 2 Common Criteria and PCI DSS network segmentation and firewall requirements\nConduct periodic firewall rule reviews, NACLs/security group audits, and access control assessments\nCollaborate with the security team on threat modeling, vulnerability remediation, and incident response for network-layer events\nMaintain network diagrams and data flow documentation required for compliance scoping\nOperations & Engineering Excellence\nAll network infrastructure changes are delivered as code - no console changes in production. Author and maintain reusable OpenTofu / Terraform modules for VPCs, VNets, TGW attachments, VPN tunnels, firewall rules, and routing policy. Every change lands via peer-reviewed PR\nTrack work, changes, and incidents in JIRA; contribute to clear ticket hygiene and change-management workflows\nBuild and maintain monitoring, alerting, and runbooks for network health across environments\nParticipate in on-call rotation for network-layer incidents; lead post-incident reviews for network events\nMentor junior engineers and contribute to architectural decisions and standards\nRequirements\nNecessary Qualifications & Competencies\nBachelor’s degree in computer science, software engineering, or a related field, or equivalent practical experience.\n5+ years of hands-on network engineering experience in cloud-native or hybrid environments\nDeep expertise with AWS networking (VPC, Transit Gateway, Route 53, Security Groups, NACLs, Network Firewall)\nCloud security & connectivity - hands-on with AWS IAM (roles, policies, identity federation), SSM (Systems Manager, Session Manager, Parameter Store), GuardDuty, and Security Hub\nWorking knowledge of Azure networking (VNet, Azure Firewall, NSGs) - we recognize deep expertise in both clouds is rare; strong AWS with willingness to grow in Azure (or vice versa) is acceptable\nProven experience designing and operating IPsec/IKEv2 and SSL VPN tunnels with enterprise clients\nSolid understanding of BGP, OSPF, and routing policy in multi-cloud and hybrid contexts\nHands-on experience with compliance programs - SOC 2 and/or PCI DSS - specifically network controls and audit evidence\nExperience authoring reusable OpenTofu or Terraform modules, not just consuming them\nStrong TCP/IP fundamentals: subnetting, DNS, TLS, NAT, load balancing\nHands-on packet-level troubleshooting - Wireshark, tcpdump, mtr, iperf, dig\nProficiency with AWS CLI, Azure CLI, Python, Bash/PowerShell, and Docker for automation, tooling, and troubleshooting\nStrong written and verbal communication skills - comfortable running technical calls with customer network engineers\nPreferred Skills\nWorking understanding of modern AI tooling and hands-on experience with coding assistants (e.g., GitHub Copilot, Cursor, Claude, ChatGPT) to accelerate module authoring, troubleshooting, and documentation\nExperience with network observability tooling (e.g., VPC Flow Logs, Azure NSG Flow Logs, Datadog, Grafana, Dynatrace)\nFamiliarity with Nagios or similar network monitoring platforms\nFamiliarity with zero trust network architecture (ZTNA) principles and implementation\nFamiliarity with Cisco Meraki and IPS/IDS platforms\nDDoS protection and WAF experience - AWS Shield/WAF or Azure Front Door/WAF\nHybrid DNS design across Route 53, Azure Private DNS, and on-prem resolvers\nExposure to Kubernetes networking (CNI, ingress controllers, service mesh) in multi-cloud deployments\nFinancial-services or regulated-industry background\nRelevant certifications: AWS Advanced Networking Specialty, Azure Network Engineer Associate, CCNP, or equivalent\nExperience working within a CI/CD-driven infrastructure model (Harness, GitHub Actions, or similar)\nPay, Benefits & Total Rewards\n$160,000-$180,000 with 10% bonus potential\nThe salary range listed reflects the minimum and maximum for this role. Individual compensation is based on experience, qualifications, job-related skills, location, and internal equity, and most offers are not made at the top of the range.\nBase pay is one part of Kinective’s Total Rewards package. Depending on the role, employees may also be eligible for bonuses, commissions, or equity. All employees have access to a competitive benefits package designed to support health, well-being, and financial security, including:\nComprehensive health coverage (medical, dental, vision, prescriptions, life & disability)\nFlexible PTO, 11 company holidays, and generous parental and caregiver leave\nAn immediately vested 401(k) with company contributions\nWellness resources and professional development opportunities\nIf you’ve made it this far, we’d love to hear from you. Click Apply to start the conversation, even if you’re not sure you check every box. Learn more about Kinective at www.kinective.io.\nPlease note that this role does not currently offer sponsorship opportunities. Open to Colorado residents only.","description_format":"text","description_chars":8329,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":true},"security_clearance":false,"languages":[]},"benefits":["Equity","Professional development"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Financial Services"],"lifecycle":[{"event":"open","at":"2026-09-26T10:47:25Z"}],"liveness":{"score":71,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.788,"p_room":0.9,"age_days":19,"expected_fill_days":40,"reasons":["conf:39","velocity","win:mid"],"computed_at":"2026-09-28T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/kinective-senior-cloud-network-engineer","json_url":"https://alion.io/job/kinective-senior-cloud-network-engineer.json","meta":{"generated_at":"2026-09-29T03:39:48Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3408,"day_limit":5000,"remaining_today":1592,"minute_limit":60,"resets_at":"2026-09-30T00:00:00Z"}}}