Senior Cloud Network Engineer (Automation / IaC)
Tech Stack / Keywords
Firma i stanowisko
We are an AI-native data and technology partner for private capital and healthcare, founded in 2010 and headquartered in Warsaw. We work with leading PE firms, VC funds, and healthcare organizations to build proprietary data infrastructure, deploy AI solutions, and drive AI-native transformation. Our clients manage a cumulative $1.2T+ in assets and our average engagement runs five years. We have restructured our own company around AI, including tools, policies, roles, and delivery models, and are hiring engineers to apply this expertise for others.
Wymagania
- Deep hands-on experience with AWS networking at multi-account scale including VPC design, routing, security groups, Transit Gateway, PrivateLink, IPAM.
- Conceptual understanding of AWS Cloud WAN core network policy documents, segments, tag-based routing, and multi-region topologies with production or migration experience a plus.
- Experience with centralized firewall and traffic inspection using AWS Network Firewall, Palo Alto NGFW (via GWLB), or similar.
- Strong expertise in Terraform and Infrastructure as Code at scale including module design, state management, versioning, and remote backends.
- Ability to perform data-driven network automation by querying VPC Flow Logs in S3 (using Athena, Python, pandas, or equivalent).
- Comfortable with cross-domain tasks such as pull-request reviews, BGP/routing discussions, CI/CD for infrastructure and policy-as-code (OPA, Sentinel, or AWS Config).
- Solid spoken English for technical discussions.
Nice to have:
- Experience with SD-WAN platforms such as Palo Alto Prisma, Cisco Viptela/Meraki, VeloCloud, Aviatrix.
- Knowledge of Direct Connect, BGP, Route 53 hybrid DNS, PrivateLink at scale, ZScaler client-access integration.
- Relevant AWS certifications: Advanced Networking Specialty or Solutions Architect Professional.
- Familiarity with AWS Control Tower or Landing Zone Accelerator for network account vending.
- Experience with GitOps workflows for infrastructure (Atlantis, ArgoCD, or equivalent).
- Exposure to VPC Lattice and application networking.
- Background in financial services or regulated industries requiring segmentation, audit trails, and change control compliance.
Obowiązki
- Drive the active Transit Gateway → AWS Cloud WAN migration involving ~10 segments and phased TGW decommission.
- Lead the centralized firewall programme replacing the NACL model by deriving firewall rules from VPC Flow Logs and managing change control at scale.
- Operate and evolve the hybrid firewall architecture: AWS Network Firewall with NGFWs via Gateway Load Balancers.
- Build and maintain a Terraform module library for network provisioning consumed via GitHub / GitHub Enterprise.
- Own IP address management via AWS IPAM at 400+ account scale and support account-vending workflows.
- Support DNS (Route 53 + inbound resolvers to Active Directory) and Direct Connect with high availability targets.
- Act as the primary technical bridge between Platform Engineering and Networking, translating requirements into IaC.
Benefity
- Fully paid licenses for AI stack tools like Cursor, Claude Pro.
- Remote-first work with no unnecessary meetings, Jira bloat, or micromanagement.
- Direct impact by working closely with CEO, CTO, VPs, and VC/PE General Partners.
- Work alongside elite engineers shipping systems influencing real investment decisions.
Inne informacje
Informujemy, że administratorem danych jest Sunscrapers Sp. z o. o. z siedzibą w Warszawie, ul. Tadeusza Czackiego 15/17. Masz prawo do żądania dostępu do swoich danych osobowych, ich sprostowania, usunięcia lub ograniczenia przetwarzania, prawa do wniesienia sprzeciwu wobec przetwarzania oraz prawa do przenoszenia danych i wniesienia skargi do organu nadzorczego. Dane przetwarzane będą w celu rekrutacji. Podanie danych obowiązkowych jest konieczne, a odmowa może skutkować brakiem możliwości przeprowadzenia procesu rekrutacji. Zgoda na przetwarzanie danych może być wycofana w dowolnym momencie. Spółka posiada procedurę zgłoszeń wewnętrznych zgodną z Ustawą o ochronie sygnalistów z dnia 14 czerwca 2024 r.
Vecten
Pracodawca