Senior Cloud & Network Security Engineer
Arcadian Data — Qatar · Posted ~2 hours ago
🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.
Log in to add to target listDescription
Senior Cloud and Network Security Engineer (Azure)
Position Summary
We are seeking a Senior Cloud and Network Security Engineer with at least 10 years of relevant experience to design, implement, and maintain secure network infrastructure across Microsoft Azure and on-premises environments.
This role combines network security architecture with hands-on engineering, with particular responsibility for DNS, VPN connectivity, Azure Private Endpoints, proxies, and on-premises firewalls.
The successful candidate will support multiple projects, translating business and technical requirements into secure, reliable, and scalable network designs.
Key Responsibilities
Network Architecture and Project Delivery
- Design end-to-end network security architectures for Azure and hybrid environments, ensuring alignment with enterprise security standards and project requirements.
- Develop high-level and low-level designs, network diagrams, IP addressing plans, traffic flow mappings, and firewall rule matrices.
- Define network segmentation, routing, ingress and egress controls, and secure connectivity between applications, cloud services, and on-premises systems.
- Review proposed solutions, identify network security risks and dependencies, and recommend appropriate controls.
- Work with solution architects, cybersecurity teams, infrastructure engineers, application teams, and vendors throughout project delivery.
Azure Networking and Security
- Configure and manage Azure Virtual Networks, subnets, peering, route tables, Network Security Groups, and Application Security Groups.
- Implement Azure Private Endpoints and Private Link, including associated DNS configuration and access controls.
- Configure and troubleshoot Azure DNS, Private DNS Zones, Azure DNS Private Resolver, and hybrid DNS resolution.
- Implement and maintain site-to-site and point-to-site VPNs, Azure VPN Gateway, and ExpressRoute connectivity where required.
- Configure Azure Firewall, network virtual appliances, NAT Gateway, and application protection services such as Web Application Firewall.
- Design and maintain hub-and-spoke or Azure Virtual WAN architectures, including centralized inspection and controlled outbound access.
On-Premises Firewalls, Proxies, and Hybrid Connectivity
- Configure, maintain, and troubleshoot on-premises firewalls, including security policies, NAT rules, routing, VPN tunnels, and logging.
- Manage enterprise proxies and secure web gateways, including authentication, URL filtering, allowlists, and TLS inspection requirements.
- Establish secure connectivity between Azure workloads, corporate networks, third-party services, and remote users.
- Investigate connectivity issues involving DNS, routing, asymmetric traffic flows, firewall policies, proxies, certificates, and VPN tunnels.
- Review firewall and proxy rules regularly to remove unnecessary access and enforce least-privilege connectivity.
Operations, Governance, and Documentation
- Monitor network availability, performance, and security using Azure and enterprise monitoring tools.
- Support incident investigation and root cause analysis for network and security-related issues.
- Implement changes through established change management processes, including impact assessments, testing, and rollback plans.
- Automate repeatable configurations using Terraform, Bicep, PowerShell, or Azure CLI.
- Maintain configuration documentation, operational runbooks, architecture standards, and support handover materials.
- Validate resilience and failover arrangements for critical network connectivity and security components.
Required Experience and Technical Skills
- Minimum 10 years of experience in network engineering, network security, infrastructure security, or closely related roles.
- Substantial hands-on experience designing and implementing Microsoft Azure networking and security solutions in enterprise environments.
- Proven delivery of hybrid architectures connecting Azure with on-premises networks.
- Strong practical expertise in DNS, TCP/IP, subnetting, routing, BGP, NAT, IPsec VPNs, and TLS.
- Demonstrated experience configuring Azure Private Endpoints and resolving hybrid private DNS issues.
- Hands-on experience with enterprise firewalls from vendors such as Palo Alto Networks, Fortinet, Check Point, or Cisco.
- Experience managing enterprise proxies or secure web gateways and troubleshooting application connectivity through these services.
- Strong understanding of network segmentation, Zero Trust principles, least-privilege access, and defense in depth.
- Infrastructure as Code (IaC): Hands-on experience using Terraform or Azure Bicep to provision and manage Azure networking and security infrastructure, including virtual networks, subnets, route tables, security groups, firewalls, VPN gateways, Private Endpoints, and DNS configurations.
- Experience developing reusable IaC modules, managing configurations in version control, and deploying changes through CI/CD pipelines.
- Ability to produce clear architecture documentation and take ownership of technical delivery across multiple projects.
- Strong troubleshooting, communication, and stakeholder management skills.
Qualifications and Certifications
- Bachelor’s degree in computer science, information technology, engineering, or a related discipline, or equivalent professional experience.
- Required: Microsoft Certified: Azure Network Engineer Associate (AZ-700).
- Preferred: Additional relevant Microsoft certifications in Azure architecture or cloud security.
- Advantageous: Professional-level networking or security certifications, such as CCNP, CCIE, CISSP, or relevant firewall vendor certifications.
Soft Skills and Professional Competencies
- Influencing and stakeholder engagement: Ability to influence technical teams, project managers, and business stakeholders to adopt secure architecture decisions and implement recommended controls.
- Driving best practices: Ability to establish, promote, and embed cloud infrastructure and network security best practices into project delivery and day-to-day operations.
- Communication: Clearly explain technical risks, architectural decisions, and recommendations to both technical and non-technical audiences.
- Collaboration: Work effectively across cybersecurity, infrastructure, application, and vendor teams to resolve dependencies and deliver solutions.
- Ownership and accountability: Take responsibility for solutions from design through implementation and operational handover, proactively addressing risks and issues.
- Problem-solving and judgment: Apply structured troubleshooting and sound judgment to balance security, reliability, cost, and business requirements.
- Constructive challenge: Confidently challenge insecure or unsustainable approaches and propose practical alternatives.
- Mentoring and knowledge sharing: Support colleagues through technical guidance, design reviews, documentation, and knowledge-sharing sessions.
Desirable Experience
- Supporting secure connectivity for enterprise applications, data platforms, and AI services.
- Working in regulated industries or large organizations with formal security governance.
- Integrating network and firewall logs with centralized monitoring and SIEM platforms.
- Designing highly available connectivity and supporting disaster recovery exercises.
We have 137,743 jobs that might be an even better fit for you
DontApply's real value goes far beyond a single job link or company name. Just upload your resume — in under a minute we'll analyze all 137,743 jobs and tell you exactly which ones you should apply to right now.
Upload My Resume