{bc}
linkedin

Senior Cloud & Network Security Engineer

Arcadian Data
Baladiyat ad Dawhah, QAT
Full-time
Mid-Senior
Onsite
Discovered 1 weeks ago
Microsoft Azure networking and securitynetwork security architecturehybrid cloud architectureAzure Virtual NetworksAzure Private Endpoints and Private LinkDNS and hybrid DNS
Free

Job Fit Check

Base Career helps you apply smarter for this job.

?%
Ready to Scan

Key skills for this role

Microsoft Azure networking and securitynetwork security architecturehybrid cloud architecture
Smart Apply

Full Job Posting

Position Summary

Senior engineering role focused on secure network infrastructure across Microsoft Azure and on-premises environments.

The role combines network security architecture with hands-on engineering across multiple projects.

The engineer translates business and technical requirements into secure, reliable, and scalable network designs.

Network Architecture and Delivery

  • Design Azure and hybrid network security architectures aligned with enterprise standards and project requirements.
  • Produce detailed designs, network diagrams, IP addressing plans, traffic flow mappings, and firewall rule matrices.
  • Define segmentation, routing, ingress and egress controls, and secure connectivity.
  • Review solutions, identify risks and dependencies, and recommend controls.
  • Collaborate with architects, cybersecurity, infrastructure, application, and vendor teams.

Azure Networking and Security

  • Configure Azure Virtual Networks, subnets, peering, route tables, Network Security Groups, and Application Security Groups.
  • Implement Azure Private Endpoints and Private Link with DNS configuration and access controls.
  • Configure Azure DNS, Private DNS Zones, Azure DNS Private Resolver, and hybrid DNS resolution.
  • Implement VPN Gateway, site-to-site and point-to-site VPNs, and ExpressRoute where required.
  • Configure Azure Firewall, network virtual appliances, NAT Gateway, and Web Application Firewall services.
  • Design hub-and-spoke or Azure Virtual WAN architectures with centralized inspection and controlled outbound access.

Firewalls, Proxies, and Connectivity

  • Configure, maintain, and troubleshoot on-premises firewalls, including policies, NAT, routing, VPN tunnels, and logging.
  • Manage enterprise proxies and secure web gateways, including authentication, URL filtering, allowlists, and TLS inspection.
  • Establish secure connectivity among Azure workloads, corporate networks, third-party services, and remote users.
  • Investigate DNS, routing, asymmetric traffic, firewall, proxy, certificate, and VPN issues.
  • Review firewall and proxy rules to remove unnecessary access and enforce least-privilege connectivity.

Operations and Governance

  • Monitor network availability, performance, and security with Azure and enterprise monitoring tools.
  • Support incident investigation and root cause analysis for network and security issues.
  • Implement changes through change management with impact assessments, testing, and rollback plans.
  • Automate configurations using Terraform, Bicep, PowerShell, or Azure CLI.
  • Maintain configuration documentation, runbooks, architecture standards, and handover materials.
  • Validate resilience and failover arrangements for critical connectivity and security components.

Required Experience and Technical Skills

  • At least 10 years of relevant network engineering, network security, or infrastructure security experience.
  • Hands-on enterprise Azure networking and security implementation experience.
  • Experience delivering hybrid Azure and on-premises architectures.
  • Expertise in DNS, TCP/IP, subnetting, routing, BGP, NAT, IPsec VPNs, and TLS.
  • Experience with Azure Private Endpoints and hybrid private DNS troubleshooting.
  • Experience with enterprise firewalls, proxies, or secure web gateways.
  • Understanding of network segmentation, Zero Trust, least privilege, and defense in depth.
  • Hands-on Terraform or Azure Bicep experience, including reusable modules, version control, and CI/CD deployment.
  • Ability to produce architecture documentation and own technical delivery across multiple projects.
  • Strong troubleshooting, communication, and stakeholder management skills.

Qualifications and Certifications

  • Bachelor’s degree in computer science, information technology, engineering, or a related discipline, or equivalent professional experience.
  • Microsoft Certified: Azure Network Engineer Associate (AZ-700) certification is required.
  • Additional Microsoft certifications in Azure architecture or cloud security are preferred.
  • CCNP, CCIE, CISSP, or relevant firewall vendor certifications are advantageous.

Professional Competencies and Desirable Experience

Influence teams and stakeholders to adopt secure architecture decisions and recommended controls.

Promote cloud infrastructure and network security best practices.

Communicate technical risks and architectural decisions to technical and non-technical audiences.

Collaborate across cybersecurity, infrastructure, application, and vendor teams.

Own solutions from design through implementation and operational handover.

Mentor colleagues through guidance, design reviews, documentation, and knowledge sharing.

Experience supporting enterprise applications, data platforms, or AI services is desirable.

Experience in regulated industries, centralized SIEM integration, high availability, or disaster recovery is desirable.

Apply for this job in 1 click

Skip the repetitive application forms

Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.

Sarah M.James T.Maya R.

Trusted by over 500,000 job seekers on Base Career

Start Free Today